简体中文 繁體中文 English 日本語 Deutsch 한국 사람 بالعربية TÜRKÇE português คนไทย Français

Ulanzi Studio

 找回密码
 立即注册
楼主: majunjiea

开放离线模式按钮自定义功能

[复制链接]

66

主题

130

回帖

773

积分

管理员

积分
773
发表于 2025-9-8 12:02:56 | 显示全部楼层
wine 发表于 2025-9-2 22:54
我去 我刚买回来 用了 居然是这样的。我就当个键盘都比你这个好,你开软件收集我们的数据吧?然后再去优 ...

切换喇叭和麦克风的插件是有的,可以到应用市场,下载 Windows快捷工具,里面有 设置麦克风 和 设置音箱 的功能,拖入键盘就可以快捷切换了。

1

主题

4

回帖

41

积分

新手上路

积分
41
发表于 2025-10-9 17:26:08 | 显示全部楼层
wine 发表于 2025-9-7 10:57
那是你想我们需要。我都在这里说不需要软件!我们要离线模式。你说我需要!!!!!!!!我不要这个软件 ...

The device can send nativ key commands because it is registered as a HID. This works completely without any control software if you have a shell access on the device:
  1. #!/bin/sh
  2. HID="/dev/hidg1"
  3. echo "Send Key 'x'..."
  4. echo -ne '\x00\xE9' > "$HID"
  5. sleep 0.1
  6. echo -ne '\x00\x00' > "$HID"
复制代码

  

2

主题

9

回帖

138

积分

注册会员

积分
138
发表于 2025-10-9 22:11:30 | 显示全部楼层
Einstein2150 发表于 2025-10-9 17:26
The device can send nativ key commands because it is registered as a HID. This works completely wi ...

how did you make this device run bash script?

1

主题

4

回帖

41

积分

新手上路

积分
41
发表于 2025-10-10 12:52:54 | 显示全部楼层
aqsz200 发表于 2025-10-9 22:11
how did you make this device run bash script?

There is a vulnerability. I'm root on the device. I wrote 2 mails in 1 week to ULANZI but no reaction ...But the big question is: will it run DOOM?

Yessss!



本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有账号?立即注册

×

2

主题

9

回帖

138

积分

注册会员

积分
138
发表于 2025-10-10 13:35:27 | 显示全部楼层
Einstein2150 发表于 2025-10-10 12:52
There is a vulnerability. I'm root on the device. I wrote 2 mails in 1 week to ULANZI but no react ...

alright... i don't know if the vendor will fix it
if not, can you share how did you get the bash script hacked into the system? i'd like to customised the device a little bit
thanks!

1

主题

4

回帖

41

积分

新手上路

积分
41
发表于 2025-10-10 13:50:31 | 显示全部楼层
aqsz200 发表于 2025-10-10 13:35
alright... i don't know if the vendor will fix it
if not, can you share how did you get the bash  ...

At the moment my answer is: no
There are some really bad comments about my findings here: Reddit


Maybe ULANZI is contacting me here in the forum or by mail but there is still enougt time for them until potentially disclosure by me.

2

主题

9

回帖

138

积分

注册会员

积分
138
发表于 2025-10-10 21:18:30 | 显示全部楼层
Einstein2150 发表于 2025-10-10 13:50
At the moment my answer is: no
There are some really bad comments about my findings here: Reddit

just read the post.

I'll try have a look on the unauthenticated path myself
but i agree that how the auth data the software handled is really bad, just plain text stored locally
您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

手机版|Ulanzi Studio论坛 ( 粤ICP备2024258515号-1 )

GMT+8, 2026-1-20 20:56 , Processed in 0.136070 second(s), 18 queries .

Powered by Discuz! X3.5

© 2001-2025 Discuz! Team.

快速回复 返回顶部 返回列表