[翻译]VR头戴(HTC Vive)设备内的现实危险
Dangerous Reality Inside of VR headset: HTC Vive
VR头戴(HTC Vive)设备内的现实危险

https://embedi.com/blog/dangerous-reality-inside-of-vr-headset-htc-vive/
Introduction
引言
The subject of VR has become a modern trend bringing the neon visions of the masters of cyberpunk stories and novels closer to reality. So, it comes as no surprise that it has been lost only on very few. With years, VR headsets grew far more affordable than they had been at the start when first models were released to the market. No doubt, in future, VR devices will be as naturally found in any house and flat as desktop PCs now. According to IDC, the shipments of VR headset will reach 67 million devices by 2021.
VR已经逐渐成为一种趋势,它使得故事和小说中的多彩幻觉更现实。所以,正如预期的只有很少的地方没有出现VR。这些年,VR头戴设备相比刚出来时已经便宜很多。无疑,未来VR设备将如PC一样在家庭中常见。根据IDC,VR头戴设备的出货量在2021年将达到6700万。
That is why we decided to look inside a VR headset and find out how a cybercriminal can toy with it, and what harm can be done to a device owner.
因此,我们觉得研究下VR头戴设备内部,并找出网络罪犯如何操作它,它能对设备使用者造成什么伤害。
We researched the following attack scenarios an adversary may use:
Infect a headset and change its location coordinates, which may result in injuries to a user.
Infect a headset and add some spooky visuals, causing psychological traumas and disorders.
Infect a headset and block its screen with an ad banner.
Turn a headset into a link in an infection chain that spreads a virus when connected to other devices.
我们研究对手可能使用的如下攻击:
- 感染一个头戴设备并改变它的位置坐标,对使用者造成伤害。
- 感染一个头戴设备并增加一些让人恐怖的图像,引起心里创伤和混乱。
- 感染一个头戴设备并在屏幕里固定一条广告。
- 将头戴设备加入一个感染链,连接到另一个设备时向其传播蠕虫。
If you find the topic at least half as amusing as we do, welcome to our short review of the HTC Vive security.
如果你觉得这个主题让你感觉有趣,欢迎看看我们对HTC Vive安全性的小研究。
Researching HTC Vive
研究HTC Vive
HTC Vive is one of the most wide spread VR devices on the market. It is also the one that provokes most research interest. Let’s start with analyzing components of the VR system and their functionality. HTC Vive consists of 4 major elements.HTC Vive是市场上最流行的VR设备之一。也是使大多数研究感兴趣的。我们先分析VR系统的组件和它们的功能。HTC Vive由4个主要元素组成。
Headset
头戴设备

The main purposes of the Headset are positional tracking of a user’s head and outputting image to the displays of the VR headset. It is both the most important and curious part of the system. It is equipped with a camera and 32 positional tracking sensors. It is also packed with four connectors:
2xUSB 3.0;
power in;
Jack 3.5
HDMI
头戴设备的主要目的是追踪头的位置和输出图像到VR头戴设备的显示器。这是整个系统最重要和最有趣的步伐。它装备了一个摄像机和32个位置追踪传感器。它还包含4个连接口:
- 2个USB3.0
- 电源输入
- Jack 3.5
- HDMI
Three connectors are occupied right from the start to connect the device to a PC. There is only one USB connector vacant for peripherals devices.
三个连接口在设备连接PC起就被使用。只有一个USB接口为其它外围设备保留。
The headset is the only component that is always connected to a PC while the system is working. By getting in the guts of the headset, we got access to its motherboard and, consequently, all the elements we were interested in.
系统工作时,头戴设备是唯一连接到PC的部分。进入到头戴设备内,我们可以看到它的主板和所有其它有趣的东西。
There are main four components on the Side 1 of the motherboard:
主板的区域一主要有四个组件:

3 ARM processors;
NXP 11U35F;
2xNordic nRF24LU1P
32 Mb Micron N25Q032A13ESE40E
- 3个ARM处理器:
- NXP 11U35F
- 两个 Nordic nRF24U1P
- 32 Mb Micron N25Q032A13ESE40E
There are several important components of Side 2 as well:
2 ARM processors;
STM32F072R8;
AIT8328;
USB Audio SoC CM108B;
USB-hub SMSC USB5537b
FPGA Lattice ICE40HX8K-CB132
4 Mb Micron MP25P40
32 Mb Micron N25Q032A13ESE40E
区域二也有几个重要组件:
- 两个ARM处理器:
- STM32F072R8
- AIT8328
- USB 声音 SoC CM108B
- USB-hub SMSC USB5537b
- FPGA 阵列ICE40HX8K-CB132
- 4 Mb Micron MP25P40
- 32 Mb Micron N25Q032A13ESE40E

Base stations
基站

The primary purpose of the base stations is to track a user’s position. With a cycle of 60 times per second, they pass a synchronization impulse and then project a laser beam from top to bottom and from left to right of a room. The data is collected by the sensors and processed by the microcontrollers in the headset and controllers to track a user’s position.
基站的主要目的是为了追踪用户的位置。它以每秒60次频率循环传输一个同步脉冲并从上到下从做到右向房间内发射一个激光束。传感器收集数据并交由头戴设备和控制器里的微控制器处理,以追踪用户的位置。
The base stations are equipped with a power in and Jack 3.5 for synchronization. Each station also has a Bluetooth module used for sending notifications about the device being turned into/from the Sleep mode.
基站配有一个电源输入口和一个用于同步的Jack 3.5口。每个基站有个蓝牙模式用于通知设备进入或退出睡眠模式。
Inside the device, there is the NXP 11U37F (ARM Cortex-M0) chip, responsible for the main functionality of the device.
设备内有一个NXP 11U37F (ARM Cortex-M0)芯片,负责设备的主功能。

The interaction between the base station and a PC is close to zero (it is limited only to updating procedures). The headset, in its turn, is communicated with the help of laser beams on the hardware level. If there are any changes made in the way the beams work, the system will become simply inoperable.
基站和PC之间的交互几乎为零(只在更新过程中有交互)。反过来,在硬件层头戴设备基于激光束的帮助进行通信。如果激光束的工作情况有任何变化,系统将变得无法工作。
Controllers
控制器

It is quite obvious that a controller is intended for tracking a user’s hand movements and ensuring you get full VR experience. As for connectors, they are equipped only with microUSB for charging and updating. But what is inside it? Well, there is the NXP 11U37F processor based on Cortex-M0 in there. It maintains primary functionality of a controller. There is also FPGA ICE40HX8K-CB132 there dealing with the sensors responding to laser beams projected by base stations; and a 4 Mb Micron M25P40 chip. At first glance, it is hard to spot the Bluetooth chip, because it is a wall-flower Nordic nRF24LU1P hiding under a metal screen.
很明显,控制器用户追踪用户的手部动作并确保获得完整的VR体验。作为连接器,它只装配了一个microUSB用于控制和更新。它里面有什么?有一个内含Cortex-M0的NXP 11U37F处理器。该处理器保证了处理器的主要功能。还包含一个FPGA ICE40HX8K-CB132用于处理传感器对基站投射的激光束的响应。有一个4 Mb Micron M25P40芯片。乍一看,看不出蓝牙芯片,因为蓝牙芯片是一个伪装很好的隐藏在金属屏之下的Nordic nRF24LU1P。

Link box
连接盒

Link box is a hub between a desktop and the headset. It has four connectors on one of its sides:
power in;
USB 3.0 for connecting to a desktop;
display port;
HDMI.
连接盒是一侧桌面PC和头戴设备间的hub。它的其中一面有4个接口:
- 电源输入
- 连接桌面PC的USB 3.0
- 显示端口
- HDMI
power out;
HDMI;
USB3.0.
另一侧有三个头戴设备接口:
- 电源输出
- HDMI
- USB 3.0
One can easily find the its Bluetooth chip required for swift and convenient updating of some devices.
很容易发现它需要蓝牙来快速、方便地对一些设备进行更新。
Watchman update and console
Watchman 更新和控制
Having browsed through the SteamVR software folder, we managed to find two helpful programs: lighthouse_console.exe and lighthouse_watchman_update.exe. The first is a console for working with HTC Vive devices; the latter enables updating the headset devices.浏览SteamVR软件的目录,我们发现了两个有用的程序:lighthouse_console.exe和lighthouse_watchman_update.exe。前一个是管理HTC Vive设备的控制台程序;后一个更新头戴设备。
By executing the help command in lighthouse_console, we could see the following commands listed:
在lighthouse_console中执行help命令,获得如下命令列表:
lh> help
associatecontroller Associated the attached controller to the attached puck
axis Toggle VRC axis data dumping
battery Print battery status
button Toggle button data dumping
clear Clear the record buffer and accumulated statistics.
dump Toggle all dumping to the console. You must also turn on the individual { imu, sync, sample } flags.
errors Dump the lighthouse error/status structure.
event Toggle lighthouse aux event dumping
eventmask Select lighthouse aux events to report
isp Enable In-System Programming
haptic [us] Trigger haptic pulse
identifycontroller Trigger haptic pulses on the active serial number to identify it
imu Toggle IMU data packet dumping
imustats Print IMU statistics
period Print sync statistics
dis [<type=auto>] Toggle disambiguation. types={ auto, tdm, framer, synconbeam }
syncd Toggle sw sync detect
pose Toggle static pose solver. Is 'dis' is not active, it will enable it.
poweroff Turn off the active controller
record Toggle event recording. You must also turn on the individual { imu, sync, sample } flags.
serial Select a device to open by serial number substring
sensorcheck Print out hits (and widths) per sensor
save [<filename="lighthouse_console_save.txt">] Save recorded events to a file on disk
sync Toggle sync dumping
sample Toggle sample dumping
trackpadcalibrate Trigger trackpad recalibration on the active controller
uploadconfig [<filename>] Upload the config file to the device
downloadconfig [<filename>] Download the config file
reformatconfig <inputfilename> <outputfilename> Update the config to the latest json format
version Prints the firmware and hardware version on the Watchman board
userdata Get a directory listing of the stored userdata
userdatadownload <name> Download the specified named userdata
userdatadownloadraw <addr> <size> [<filename>] Download and store the user data at specified address
userdatasize Display the size of the user data space (in bytes)
ispdiv <divisor> Set the camera ISP sync signal divisor
quit Quit
lh> help
associatecontroller Associated the attached controller to the attached puck
axis 触发VRC轴数据转储
battery 打印电池状态
button 触发按钮数据转储
clear 清楚记录缓存和累计的统计数据
dump 在控制台中触发所有转储。必须打开individual { imu, sync, sample }标志.
errors 转储lighthouse错误、状态结果
event 触发lighthouse辅助事件转储
eventmask 选择lighthouse辅助事件进行报告
isp 运行系统内程序
haptic [us] 触发触觉增强
identifycontroller 在活跃的串号上触发触觉增强
imu 触发IMU数据包转储
imustats 打印IMU统计信息
period 打印sync统计信息
dis [<type=auto>] 触发解疑. types={ auto, tdm, framer, synconbeam }
syncd 触发sw sync检测
pose Toggle static pose solver. Is 'dis' is not active, it will enable it.
poweroff 关闭活跃控制器
record 触发事件揭露。 必须打开individual { imu, sync, sample } flags.
serial 通过序列号串选择一个设备并打开
sensorcheck 打印每个传感器的hits (和widths)
save [<filename="lighthouse_console_save.txt">]保存记录的事件到磁盘上的一个文件
sync 触发sync 转储
sample 触发sample转储
trackpadcalibrate 在活跃控制器上触发控制板再校准
uploadconfig [<filename>] 上传配置文件到设备
downloadconfig [<filename>] 下载配置文件
reformatconfig <inputfilename> <outputfilename> 更新配置到最新的json格式版本,在watchman面板打印固件和硬件版本。
userdata 获取存储用户数据的目录列表
userdatadownload <name> 下载指定名字的用户的数据
userdatadownloadraw <addr> <size> [<filename>] 下载并存储用户数据到特定地址
userdatasize 显示用户数据空间的尺寸(字节单位)
ispdiv <divisor> 设置相机ISP同步信号因子
quit 退出
associatecontroller Associated the attached controller to the attached puck
axis Toggle VRC axis data dumping
battery Print battery status
button Toggle button data dumping
clear Clear the record buffer and accumulated statistics.
dump Toggle all dumping to the console. You must also turn on the individual { imu, sync, sample } flags.
errors Dump the lighthouse error/status structure.
event Toggle lighthouse aux event dumping
eventmask Select lighthouse aux events to report
isp Enable In-System Programming
haptic [us] Trigger haptic pulse
identifycontroller Trigger haptic pulses on the active serial number to identify it
imu Toggle IMU data packet dumping
imustats Print IMU statistics
period Print sync statistics
dis [<type=auto>] Toggle disambiguation. types={ auto, tdm, framer, synconbeam }
syncd Toggle sw sync detect
pose Toggle static pose solver. Is 'dis' is not active, it will enable it.
poweroff Turn off the active controller
record Toggle event recording. You must also turn on the individual { imu, sync, sample } flags.
serial Select a device to open by serial number substring
sensorcheck Print out hits (and widths) per sensor
save [<filename="lighthouse_console_save.txt">] Save recorded events to a file on disk
sync Toggle sync dumping
sample Toggle sample dumping
trackpadcalibrate Trigger trackpad recalibration on the active controller
uploadconfig [<filename>] Upload the config file to the device
downloadconfig [<filename>] Download the config file
reformatconfig <inputfilename> <outputfilename> Update the config to the latest json format
version Prints the firmware and hardware version on the Watchman board
userdata Get a directory listing of the stored userdata
userdatadownload <name> Download the specified named userdata
userdatadownloadraw <addr> <size> [<filename>] Download and store the user data at specified address
userdatasize Display the size of the user data space (in bytes)
ispdiv <divisor> Set the camera ISP sync signal divisor
quit Quit
lh> help
associatecontroller Associated the attached controller to the attached puck
axis 触发VRC轴数据转储
battery 打印电池状态
button 触发按钮数据转储
clear 清楚记录缓存和累计的统计数据
dump 在控制台中触发所有转储。必须打开individual { imu, sync, sample }标志.
errors 转储lighthouse错误、状态结果
event 触发lighthouse辅助事件转储
eventmask 选择lighthouse辅助事件进行报告
isp 运行系统内程序
haptic [us] 触发触觉增强
identifycontroller 在活跃的串号上触发触觉增强
imu 触发IMU数据包转储
imustats 打印IMU统计信息
period 打印sync统计信息
dis [<type=auto>] 触发解疑. types={ auto, tdm, framer, synconbeam }
syncd 触发sw sync检测
pose Toggle static pose solver. Is 'dis' is not active, it will enable it.
poweroff 关闭活跃控制器
record 触发事件揭露。 必须打开individual { imu, sync, sample } flags.
serial 通过序列号串选择一个设备并打开
sensorcheck 打印每个传感器的hits (和widths)
save [<filename="lighthouse_console_save.txt">]保存记录的事件到磁盘上的一个文件
sync 触发sync 转储
sample 触发sample转储
trackpadcalibrate 在活跃控制器上触发控制板再校准
uploadconfig [<filename>] 上传配置文件到设备
downloadconfig [<filename>] 下载配置文件
reformatconfig <inputfilename> <outputfilename> 更新配置到最新的json格式版本,在watchman面板打印固件和硬件版本。
userdata 获取存储用户数据的目录列表
userdatadownload <name> 下载指定名字的用户的数据
userdatadownloadraw <addr> <size> [<filename>] 下载并存储用户数据到特定地址
userdatasize 显示用户数据空间的尺寸(字节单位)
ispdiv <divisor> 设置相机ISP同步信号因子
quit 退出
注意:上传附件及图片大小不得大于30M。
⚠️ 版权声明:
本博客所有内容(含教程、源码、工具)仅供个人技术学习与研究交流使用,严禁商用、倒卖、二次分发及非法用途。
未经作者书面授权,任何组织或个人不得转载、复制或用于其他平台,违者将追究相关责任。
复制成功
