DEF CON 27 - Backdooring Hardware Devices By Injecting Malicious Payloads On Microcontrollers

  Переглядів 2,940

HackersOnBoard

HackersOnBoard

День тому

Is targeting microcontrollers worth the effort? Nowadays, they are responsible for controlling a wide range of interesting systems, e.g., physical security systems, car's ECUs, semaphores, elevators, sensors, critical components of industrial systems, some home appliances and even robots.
In this talk, it will be explained how microcontrollers can be backdoored too. After a quick review of basic knowledge about uC, we will dive into three different approaches to achieve payload injection, from basic to advanced techniques. The first method consists on locating the entry point of the firmware and inject our payload there, this is an easy way to execute it at least once. As a second and more complex technique, we will backdoor the EUSART communication injecting a malicious payload at the code routine of that hardware peripheral; we will be able to get the right memory address by inspecting the GIE, PEIE and polling process at the uC interrupt vector. Finally, the third technique allow us to take control of the microcontroller's program flow by manipulating the stack writing memory addresses at the TOS; with this we can execute a payload made with instructions already written in the original program, performing it just like a ROP-chain technique.
Talk by Sheila Ayelen Berta

КОМЕНТАРІ: 3
@florencetown4024
@florencetown4024 22 дні тому
20:00
@Tomaskotomco
@Tomaskotomco 4 роки тому
Def con dudes are always weird
@estebanrojas1322
@estebanrojas1322 4 роки тому
the sacrifice for knowledge
Corel Linux - The (Word)Perfect Operating System
25:40
Michael MJD
Переглядів 127 тис.
Best OS for programming? Mac vs Windows vs Linux debate settled
8:40
Exploit Friday: WCH CH573 Memory Read-out Protection bypass
6:35
Aaron Christophel
Переглядів 4,4 тис.
DEF CON 27 - WillC - Phreaking Elevators
40:00
HackersOnBoard
Переглядів 2,1 тис.
Google Data Center 360° Tour
8:29
Google Cloud Tech
Переглядів 5 млн
DEF CON 27 - Patrick Wardle - Harnessing Weapons of Mac Destruction
48:51
HackersOnBoard
Переглядів 1,1 тис.
Do 10 things that don’t scale - Paul Graham
8:09
Academy of Product Management
Переглядів 20 тис.
❌УШЛА ЭПОХА!🍏
0:37
Demin's Lounge
Переглядів 301 тис.
Лучший Смартфон До 149 Баксов!!!??? itel s24
20:25
РасПаковка ДваПаковка
Переглядів 53 тис.
The power button can never be pressed!!
0:57
Maker Y
Переглядів 36 млн
Компьютерная мышь за 50 рублей
0:28
dizzi
Переглядів 2,2 млн
Why spend $10.000 on a flashlight when these are $200🗿
0:12
NIGHTOPERATOR
Переглядів 17 млн
❌УШЛА ЭПОХА!🍏
0:37
Demin's Lounge
Переглядів 301 тис.