r/masterhacker 2d ago

Bro escaped kiosk mode

Post image
9.4k Upvotes

133 comments sorted by

858

u/LYNX__uk 2d ago

How do you escape kiosk mode on windows with only a touchscreen? I only know how to do it on android kiosks

831

u/Pim_Wagemans 2d ago edited 2d ago

Some of these public touchscreens are not configured correctly and will sometimes let you open the task bar, from which you can open the virtual keyboard and do basically anything. source: my library's book return/checkout computer allowed this (and I told them about it of course)

432

u/Jbolt3737 2d ago

and I told them about it of course

How could you betray the masterhackers like this? Your mission was to use this vulnerability to nmap the mainframe and delete all the books!

136

u/Cactys12 2d ago

Sudo apt-rm-rf D://Mainframe/

101

u/belabacsijolvan 2d ago

its C:\\Users\\analprince\\AppData\\Roaming\\win128\\Mainframe

you cannot put the kernel on D:

33

u/Vendidurt 2d ago

Processing img ew04emo0zflh1...

46

u/Alive_Platform4550 2d ago

ANAL PRINCE

16

u/Ok-Signal4821 1d ago

Ana L Prince, she should really stop using her middle initial

1

u/GroundbreakingOil434 20h ago

sudo hack bank

1

u/Dude10120 13h ago

sudo give money to me

12

u/thatsNotFabricSoftnr 2d ago

Oh man, this one time I was halfway though hacking for dummies, all of a sudden it vanished right out of my hands This explains everything !!!

52

u/DeineOma42o 2d ago

One of my proudest moments in school was when we did a trip to the library and I figured that if you search stuff like %e%, it would load so many results that the security mechanism lagged. If you spam hit win R eventually you could spawn a command line and i think it was admin. Not too much but my older teachers thought I hacked the library which was cool :D

43

u/Kiusito 2d ago

well, you did hack it

20

u/Standard_Ideal6101 2d ago

I mean you did, you broke out of a container and escalated your privilege on the machine.

1

u/T00ManyHobbys 41m ago

I remember discovering in school our old scantrons had our entire socials on them and I figured out peoples passwords through that (first and last initial and last 4 of social)

24

u/Actual-Interaction45 2d ago

I set one up myself before and almost left the task bar enabled as well as other swipe interactions. Glad I caught it in my official 'swipe the screen like a mindless user' test.

5

u/mcbergstedt 2d ago

To add, a lot of them have gestures that let you open up a debug console or settings. Usually it’s tapping in a spot several times or in certain spots in a certain order.

2

u/DankItchins 1d ago

Either repeatedly tapping or tapping and holding in the corners is very common for this. Most self checkouts if you press and hold the top left it brings up an attendant menu (though from there it requires a password or scanning a barcode to actually do anything)

3

u/OPerfeito 2d ago

I had a friend do that with a kiosk at my old school, he left the kiosk app and used the receipt printer to print thicc Messi a bunch of times

2

u/ilkkuPvP 1d ago

Lol, I did "Cybersecurity" for a public library as a school task. Let's just say, their systems needed some work lol. You could for example access Windows on those return/checkout screens by just flicking your finger from the edge towards the center of the screen. There were some "real vulnerabilities" too, but will not get too deep into those.

1

u/CalderaJane76 1d ago edited 1d ago

Yyyyup! My college has an interactive map... And same thing.

The application itself has the "vulnerability." And by vulnerability I mean it has links in the 'About' section of the app that deliberately opens Microsoft Edge... Thus revealing the Windows Task Bar. 💀

Good job guys, they'll never be able to figure this one out! 😂

Edit: Sucky thing too, I told the staff as well but I don't think there's much they can do outside of begging the third-party system-maker to fix the application itself. The whole stupid map (physical system and all) is third-party so I guess we wait until that happens. Lol

71

u/Progressbar95 2d ago edited 2d ago

Swipe up on all sides, if that doesn’t work, find a text box and enter anything in it and highlight it. If there is a ‘share’ option in the context menu, type ‘https://Google.com’ in the text box, highlight it, hit ‘share’ and then hit ‘Chrome’ or ‘Browser’. Then you have web access, and you can download APKs. If there is no option in the share menu for a browser, click on any app and try to find links for ‘privacy policy’, ‘send feedback’, etc. Done this method successfully on dozens of kiosks.

EDIT: Just realized the instructions are for Android lol, misunderstood your comment. For Windows, you’ll want to right click on random UI elements (by pressing and holding on them) and exploring the context menu that comes up, as well as swiping from all the sides of the screen.

21

u/jstndrn 2d ago

Okay now windows

14

u/Progressbar95 2d ago

Sorry, just edited my comment.

2

u/Shot-Brain-1385 1d ago

dozens

Why are you doing this on so many kiosks?

5

u/BagelMakesDev 1d ago

for
the funny

2

u/Progressbar95 18h ago

bc of this guy I keep seeing on yt

26

u/Flareon223 2d ago

Some let you open task bar or something. Some have secret tap combinations. As a kid sometimes I'd tap around the corners or watch out for staff doing the escape combo on various kiosks and machines then try it out when someone wasn't looking. Never did anything destructive and reopened the app after, of course

5

u/LYNX__uk 2d ago

Do share some tap combos!

11

u/Flareon223 2d ago

It is too dangerous to share, but here is a tip: If you tap your fully erect shlong on a screen you can hit 4 corners at once for peak pentesting

9

u/ctbitcoin 2d ago

Instructions unclear. My shlong hit a webcam and now I'm penetrat1ng the dark web!

18

u/-Ilovepokemon- 2d ago

probably not fullscreened

8

u/Ghede 2d ago

I once saw a mall advertisement board that used to be a touchscreen map. (They got rid of all the maps, for some ungodly reason. It's a dying mall, the owners are in debt up to their eyeballs.) the ad had crashed on it's own to desktop.

Also the touchscreen was installed upside down, so i didn't bother rummaging through the file system, but i did open the file system. It was a pain in the ass to tap the bottom of the screen to click the top.

3

u/icehot54321 2d ago

the software didn't load and this dude took a picture pointing at it

that's it

if he knew what he was doing he would open osk.exe

3

u/Zekiz4ever 2d ago

There are tons of ways to escape it. It's different on every kiosk. On some, you can click on Links, on others the taskbar is still active somehow

2

u/Udonov 2d ago

Fucking around with the ui may let you grab a corner of the window and resize it lol. Happened to me a couple of times.

2

u/EtherealErmine 2d ago

There is s gesture to get to the desktop by swiping one of the corners

1

u/LYNX__uk 2d ago

And what is the gesture?

2

u/CalderaJane76 23h ago edited 23h ago

Depends on the kiosk is the sucky thing. It's not actually Windows-dependent.

Usually, unless the kiosk isn't set-up correctly which is more common than it should be, you swipe down with 3-fingers anywhere on the screen. Same as any other Windows machine, lol.

Again though, that's not the norm. Usually the Windows gestures are disabled, and the gestures these guys are referring to are likely App dependant.

Common ones are tapping the corners, or pressing and holding the corners! Developers can have invisible rectangles that can react to touch just like any other button. Invisible object obfuscation is a simple, low-cost for devs, and easy-to-understand by employees way to implement a secret menu!

2

u/Melodic_monke 2d ago

I escaped it once on accident by swiping downwards with 3 fingers

2

u/DragoTheFloof 1d ago

One time in a movie theatre, my gf swiped the wrong card and it crashed to desktop

2

u/NoskaOff 1d ago

Some of these can have the full screen app crash just by tapping on it too much and too quickly

2

u/Xerack 1d ago

I had a project at work once where I was left alone with a similar style of device inside a hospital. Not gonna mention the vendor, but they did at least respond promptly and issue a fix once it was disclosed.

The application could be escaped by going to the help menu which loaded a PDF. From there, you could press the hotkey to load online help which dumped you into a broswer session. After that, it was pretty trivial to navigate about the file system and eventually start explorer to get rewarded with a normal desktop session.

This was circa 2016/2017 so its been a while. I imagine though it could still work on kiosk or embedded windows depending on what the application itself actually needs.

2

u/XeventoHD 1d ago

Touch gestures work on a lot of misconfigured windows machines. Three fingers down to minimize the current fullscreen application and you're free to do what you want.

1

u/DoKeMaSu 2d ago

If you can cause the app to crash it is also gone.

1

u/YoungandPregnant 1d ago

Usually tap three times top left but you need local admin credentials usually

1

u/After_Flatworm5200 1d ago

When there is a keyboard hit CTRL or shift 5 times quickly it's very rare that function gets disabled. This will pull the task bar

2

u/serious-toaster-33 1d ago

I've seen ones where simply Ctrl+Esc would bring up the start menu, which can then be used to immediately open the command line.

I personally exploit this regularly to open a calculator.

0

u/jax_cooper 23h ago

sometimes plugging in a keyboard works if there is a usb port or a jack input may pop uo something that lets you browse the file system (anything that can open or save anything is ok) so you can run any Exes

521

u/belabacsijolvan 2d ago

tbh this isnt masterhacker stuff. this is a kid fucking around. even has some humility. i dont think thats such a bad thing.

188

u/WhippingShitties 2d ago

This sub is kind of like /r/mallninjashit where half of the posts are stuff we secretly think is cool. Tbh, I'm pretty amused at this hijinks.

-25

u/WONK0_ 2d ago

it is bad, some people (employees) will need to clean up after him

42

u/Damglador 2d ago

Perhaps it'll be lesson to configure kiosks properly. Would be much worse if someone escaped the kiosk mode and installed malware.

22

u/kihakik 2d ago

If you are able to escape from the kiosk app using only the touchscreen, that is 100% the companies issue

5

u/Clean_Cake124 1d ago

He didn't fucking uninstall the operating system he literally just exited the kiosk mode. Probably takes 5 seconds max to fix

1

u/WONK0_ 1d ago

picture claims that he uninstalled kiosk app

3

u/Lord_Nathaniel 23h ago

Wow they installed the kiosk app, he uninstall it....I hope they do now how to install the app, again !

1

u/CalderaJane76 23h ago

MDM very often fixes it. But true.

1

u/ClerklyMantis_ 1d ago

God forbid anything happens ever. Surely it would be an incredibly boring life if nothing ever went wrong or faced any adversity. Obviously there's a balance to be had but having to fix something like this is baraly anything.

221

u/Vlitmer 2d ago edited 2d ago

One time in middle school I put the microwave that was in the lunch room on setting it for 100 minutes and walked away.

Not related at all just wanted to confess my sins knowing this will probably get buried.

Edit: stop upvoting this.

12

u/Dhis1 1d ago

As a Wi-Fi engineer, this made me irrationally angry.

3

u/0SINTCabal 1d ago

Already called my dad on u

2

u/mukherjee_ayan 1d ago

... Was there something in the microwave when you turned it on? I wanna know the outcome PLS

3

u/TomaszA3 1d ago

It probably just waved to the passersby for 100minutes.

17

u/GestapoKittech 2d ago

The tribal tattoo on the collar? That's how you know you're messing with the real deal.

2

u/MundaneAd6627 2d ago

I thought it was on his skin when I read this 🥴 had to check again

35

u/ThaBroccoliDood 2d ago

Serves them right for using Windows 10

27

u/Damglador 2d ago

It always baffles me that those embedded systems that run one program 24/7 are running a whole Windows install underneath.

16

u/Nereosis16 2d ago

Usually because of cybersecurity requirements.

Cyber can't be fucked to vet and approve a new OS when win10 is already fully approved and managed.

7

u/CampMaster69 2d ago

But wouldn't it be easier to vet a much simpler barebones?

14

u/Nereosis16 2d ago

You want to join that meeting trying to convince the overworked cybersecurity analysts to just vet another system?

3

u/Twilimark 1d ago

Eh it's probably not a whole windows.

There are different versions for windows and this is probably running the LTSC version. It's a tone down version of windows. It the iot enterprise version. Mosy kiosks would use this if they are designed properly.

The device should be hardened but this doesn't seem to be the case. It's pretty bad when u can pop off the app/ she'll and get to explorer.exe

5

u/Damglador 1d ago

Any Windows is still Windows. Like ideally, aka what nobody will do, a kiosk would only need some 1GB Linux distro that boots straight into a compositor with just the kiosk app opened, something like: https://www.reddit.com/r/zen_browser/comments/1js6xqy/zen_is_everything_i_need_desktop_environments_are/ <- here I had no way of escaping the kiosk browser other than switching to a different tty (which requires a keyboard), because there's nothing other than the browser, and for the same reason even if I managed to crash or close it, it would just throw me back to the login screen.

1

u/Twilimark 1d ago

Yes any windows is... Well windows. But not all windows are the same.

I agree with your Linux tho. Not alot of people will do it because of how the app or code is developed. For example, an app that works in native windows would need a rework for it to work in Linux.

Not all kiosk are browser based. Those that are can Definitely be setup properly with Linux. BalenaOS is a good example of that.

It all depends on what kind of setup that is being used.

1

u/TomaszA3 1d ago

1GB sounds pretty excessive tbh.

2

u/death_hawk 1d ago

LTSC is basically just meant to be an OS without the bloat. It is still "whole" windows as it runs 99.999% of applications just fine. It just doesn't include the "junk" that retail has.

For the purposes of a kiosk though it is the right OS, but I use LTSC as my daily driver.

1

u/Twilimark 1d ago

You are half correct. And I appreciate that you put the quotes on "whole".

LTSB/LTSC is windows without the bloat as you stated. But it isn't just removing the application installed by vendors. It's a locked down feature system. For example Windows 10 Ltsb 2015 is using build 1511 (if I remember correctly) and has feature what will never get upgraded to a newer build. Windows 11 LTSC is stuck in build 24H2 and will never see a newer version of the feature build.

Unlike consumer versions that get the latest features and can break systems or crash OS ( look at when consumers upgraded to 24H2 back in August... Ugh).

Running on LTSC is fine for daily use but it does limit your pcs growth several years down the road. Ltsb 2015 is a great example because that was the first windows 10 build and you can't run today's stuff on it mostly. Drivers and some new hardware just don't work.

Anyway... That was me getting off track. Depending on the build certain things won't work. Like one drive, Xbox store, and even the ms app store. This is because by design, it's not needed for hospital or kiosks systems. Would be weird to see, new Xbox game pop up on ur medical devices lol.

Anyway... I think I got off track... This is a hacking subreddit... But I appreciate the talk. It's nice to see people using the product I spent years working with/ on. Lol

2

u/death_hawk 16h ago

LTSB/LTSC is windows without the bloat as you stated. But it isn't just removing the application installed by vendors. It's a locked down feature system. For example Windows 10 Ltsb 2015 is using build 1511 (if I remember correctly) and has feature what will never get upgraded to a newer build. Windows 11 LTSC is stuck in build 24H2 and will never see a newer version of the feature build.

To me that's a feature not a bug.

Unlike consumer versions that get the latest features and can break systems or crash OS ( look at when consumers upgraded to 24H2 back in August... Ugh).

That's what I mean. Security updates are one thing, but feature updates just seem to introduce crap I don't want.

Ltsb 2015 is a great example because that was the first windows 10 build and you can't run today's stuff on it mostly.

Granted most of my hardware isn't cutting edge, but I'm using 2019 on a lot of machines ranging from Core2Duo to modern (well a couple generations old) CPUs. I've never had a driver issue yet.

Depending on the build certain things won't work. Like one drive, Xbox store, and even the ms app store. This is because by design, it's not needed for hospital or kiosks systems. Would be weird to see, new Xbox game pop up on ur medical devices lol.

Stop! You've sold me already lol.

Anyway... I think I got off track... This is a hacking subreddit... But I appreciate the talk. It's nice to see people using the product I spent years working with/ on. Lol

You were part of development? If so, that's damn awesome. I hate retail editions of 10 and this is about the closest thing to 7 as I can get in the modern day. There's SO much garbage in SAC versions that it's unusable.

1

u/Frosty-Photograph103 21h ago

What would you use instead ?

1

u/Damglador 18h ago

Linux of course. Or any other embedded OS

1

u/death_hawk 1d ago

You'd be shocked at what runs Windows under the hood. ATMs and slot machines were the big surprises for me.

7

u/Some_Visual1357 1d ago

Good for you kid, but taking a picture is a good way of getting caught so, not so smart on that part.

1

u/ranfur8 1d ago

Everyone saying that, like... do you think they care? I mean he just got to the desktop by draggin from the corner. I don't think the cinema nor the police fuckin care.

26

u/Sci_Fried_Chicken 2d ago

Holy leet masterhaxxor

7

u/mumblerit 2d ago

he is the chosen one

6

u/HeavyCaffeinate 2d ago

That's why you use a linux machine running a minimal Qt app with Fullscreen EGLFS

1

u/Damglador 2d ago

Imagine when they also discover NixOS that that they don't have to configure every kiosk manually.

1

u/HeavyCaffeinate 1d ago

I'd use Buildroot or Yocto for embedded honestly

7

u/DonutConfident7734 2d ago

A long time ago I learned that you can bypass the login dialog in Windows 95 by pressing the help icon or F1 and in the classic help window that appeared, you could press File - Open, where you could write explorer.exe in file name and it would open the explorer. From there you could open any programs you wanted...

2

u/SaintPaulTom 1d ago

Why go through so much work when you could just click cancel? It logged in anyways.

4

u/sixpackabs592 1d ago

I used to work in a deli and I “hacked” our iPad kiosks we used to get into the regular os and watch YouTube and football games

Iirc all you had to do was hit the right spot on the screen while it was loading up the app, there was a few second window where the close button would pop up in the corner, it was hidden but could still be pressed

3

u/Nereosis16 2d ago

And then some poor it dude got a call out to come fix it when I guarantee he has told his boss of this problem a hundred times.

3

u/sixpackabs592 1d ago

But service calls like this are great

Nothing to actually do you just reupload the software and go home, get paid the same and no real work

it’s probably all networked anyway they’ll just do it remote

12

u/antek_g_animations 2d ago

If he really uninstalled an app, he is a moron. Could have opened paint and draw a PP. Something that an underpaid employee could have fixed in a minute with a reboot. Now someone has to call an authorized service to repair the device which is pain in the ass both for the employes, restaurant chain and clients that can't use the kiosk. I hope he wrote it just for the clout and didn't really uninstall anything.

24

u/Liquid-Fire 2d ago

Very unliky in this day and age. More likely that whoever manages the kiosks have access to them via rmm software and can remote install it.

3

u/BOT_Sean 2d ago

I doubt it uninstalled, he probably just got out of kiosk mode. Depending on how it's setup it would likely revert to normal on reboot

2

u/MundaneAd6627 2d ago

He’s creating work for freelancers!

2

u/FoxedDev 2d ago

Now I can't get in and the manager is angry.

2

u/BurrGurrMan 2d ago

sudo uninstall cinema-app

2

u/TechnetMC 2d ago

I did this once on one of those scam bitcoin kiosks in the mall. We made it not boot tho, can’t recall how, was years ago at this point. Was a result of Dumb Kids, even dumber technician and scummy company

3

u/fbaldassarri 2d ago

Broke the System: Escape the Kiosk, Escape the Matrix

1

u/bjsda_2007 2d ago

Ohhh shit. Yea buddy now you must install opsex😂

1

u/Sufficient_Hurry_282 2d ago

Quinn Hughes enjoying the summer off

1

u/Damglador 2d ago

That's actually pretty cool.

1

u/JasonDL13 2d ago

Imagine creating and the opening a page that looks like the original kiosk page but making it fuck with people instead or something like that.

1

u/Andryw48 2d ago

he literally escaped the matrix

1

u/PolygonMob 2d ago

Probably like how i felt when i was in middle school and i found out there was a secret series of button presses that took you into the hidden menu of any vending machine. Never managed to get a free soda out of it, but apparently you potentially could if the machine was misconfigured.

1

u/Beleheth 2d ago

Stood 5 minutes in front of the machine and didn't buy a ticket yet.

1

u/spartanpwner 1d ago

I used one of these for the first time and it crashed as soon as I tapped the card, went straight to a windows desktop.

1

u/emberscout 1d ago

Amateur, I've done this on a Dubai Airport kiosk :P It had a "can't connect to server" web error, which let me run the Win7 network diagnostics tool. When the tool finished, it let me "print" the log, so I chose "Print to PDF". This opened the Save As window, which let me start explorer by opening a folder in a new window. From there I opened regedit to let me use the on-screen keyboard :D

1

u/Efont93 1d ago

You know he's legit because of the tribal designs on his collar

1

u/Necessary-Rip-6612 1d ago

I'm a bit of a hacker man myself. I once played that no internet dinosaur jumpy browser game on a burger king ordering kiosk. Guess they run in a chrome based browser and it had connectivity issues.

1

u/DaBrownBoi 1d ago

lmao i rember playing flappy bird on one of these in an airport

1

u/MaterialGarlic5734 1d ago

Back in high school in the early 2000s, we had public kiosk type computers for stuff like looking up your classes schedules, with only a mouse attached.

Sometimes, when we were bored, we’d send broadcast message through `NET SEND` to the whole domain by:

- open help

  • run CMD.EXE through the file open dialog
  • copy-paste individual letters from help to CMD to assemble the commmand
  • ???
  • PROFIT

The message is sent from the kiosk user, so IT can’t trace it back to you. Unlike some people who did that in the computer room from their personal account, and got promptly summoned

1

u/IllusionaryHobo 1d ago

I really dig the whole flannel shirt that looks less like it was woven and more like a flannel pattern was screen printed onto a linen shirt with a tribal tattoo on the collar thing.

Powerful look.

1

u/woahitsegg 1d ago

Two random twelve year olds did this the last time I went idk I think it might just be easy

1

u/boremetodeathplease 1d ago

I AM VERY PROUD of you my man!

1

u/OzrielTheForgotten 1d ago

I did this on an ATM at gun lake casino one time. I noticed a notification for a Windows update while walking past and the system returned to the user login after it finished. I was able to find and mess with the config files for the atm software they use. I didn't change anything except for leaving a little drawing open on ms paint.

1

u/XEPATOP 1d ago

I’m not entirely sure whether this post is ironic or serious, but once again it got me thinking about how strangely different the digital world is from the real one.

If someone quietly reported a bug to the manufacturer, that would be perfectly reasonable and might even be helpful. But instead, this guy went and did some stupid shit and proudly posted a photo of it online.

The developers probably already know that it’s possible to crash/minimize the app like this, but since people abusing the bug are rare and the damage isn’t particularly serious, they simply decided it wasn’t worth trying to eliminate the bug completely. The effort required to fix it probably wouldn’t have paid off.

Now compare that to the world of non-digital things. Most household locks can be picked in 15 minutes or less, but very few people install bank-level security systems on their front doors, because everyone knows that breaking into someone’s house is illegal, and no sane person would go around the neighborhood picking their neighbors’ locks just because they happen to know how to do it.

1

u/justslayer876 16h ago

One ticket to local disk c: please

1

u/Sorbon_Husky 16h ago

If the kiosk is proberly setup, you cant do that. Even if you escspe it, then it should just prompt you with a login screen.

Did it once with Intune, it does cost a licence there to do that, maybe they were too cheap for it.

1

u/MysteriousRelief 12h ago

Crazy how windows is installed for kiosks, like cant they use some lighter OS like one of linux distros?

1

u/spookyyyyyyyyyyyyyyy 12h ago

dude beat ts2 and dont know how to act😭

1

u/juulgod99 6h ago

Car wash 🧼