Hardwear.io NL 2023 | Breaking Secure Boot On The Silicon Labs Gecko Platform - Benoît & Sami

  Переглядів 598

hardwear.io

hardwear.io

День тому

Our investigation led us to examine Silicon Labs' open-source SDK, specifically the Gecko SDK, which boasts a state-of-the-art of secure over-the-air (OTA) update capabilities. While looking at the code that is handling the parsing of the firmware update, we discovered a vulnerability which can be used in combination with a weakness in the update mechanism to gain persistent code execution on the device, bypassing Secure Boot enforcement and firmware signature verification.
Our presentation will begin by delving into the inner workings of OTA firmware upgrades. We will subsequently delve into the specifics of the vulnerability we pinpointed, particularly outlining our discovery process employing fuzzing techniques. To conclude, we will delve further into the realm of exploiting embedded systems. We'll conclude this talk by looking to go deeper inside the exploit world on embeded systems, which mechanism make harder an exploitation and how we can handle this.
Lastly, we will showcase our successful bypass of the Secure Boot mechanism.
#hardwear_io #fuzzing #hw_ioNL2023 #infosec
-------------------------------------------------------------------------------------------------------------------------------------------------------
Website: hardwear.io
X : / hardwear_io
LinkedIn: / hardwear.io-hardwarese...
Facebook: / hardwear.io

КОМЕНТАРІ
Маленькая и средняя фанта
00:56
Multi DO Smile Russian
Переглядів 1,7 млн
What Can You Do with Python? - The 3 Main Applications
11:30
CS Dojo
Переглядів 3,5 млн
Schematic Modeling & The Role of Schematics in an FPGA Core
41:44
Pramod Somashekar
Переглядів 838
10 HomeKit Automations for Motion, Doors, Temp, and More!
10:50
Stephen Robles
Переглядів 10 тис.
Breaking Bitlocker - Bypassing the Windows Disk Encryption
9:11
stacksmashing
Переглядів 833 тис.
10 Coolest Gadgets and Inventions 2024 | You Can Buy Now
8:55
Future Tech
Переглядів 14 тис.
Secure Boot Overview
30:48
Microchip Developer Help
Переглядів 14 тис.
Портативная PS 5 🎮 #ps5 #expressly
0:22
ExpresSLY Shorts
Переглядів 289 тис.
Как установить Windows 10/11?
0:56
Construct PC
Переглядів 1,9 млн
Why spend $10.000 on a flashlight when these are $200🗿
0:12
NIGHTOPERATOR
Переглядів 17 млн
The PA042 SAMSUNG S24 Ultra phone cage turns your phone into a pro camera!
0:24
M4 iPad Pro Impressions: Well This is Awkward
12:51
Marques Brownlee
Переглядів 5 млн
❌УШЛА ЭПОХА!🍏
0:37
Demin's Lounge
Переглядів 303 тис.