Hardwear.io NL 2023 | TEEzz: Fuzzing Trusted Applications On COTS Android Devices - Marcel Busch

  Переглядів 237

hardwear.io

hardwear.io

5 місяців тому

TEEzz is the first TEE-aware fuzzing framework capable of effectively fuzzing TAs in situ on production smartphones, i.e., the TA runs in the encrypted and protected TEE and the fuzzer may only observe interactions with the TA but has no control over the TA’s code or data. Unlike traditional fuzzing techniques, which monitor the execution of a program being fuzzed and view its memory after a crash, TEEzz only requires a limited view of the target. TEEzz overcomes key limitations of TEE fuzzing (e.g., lack of visibility into the executed TAs, proprietary exchange formats, and value dependencies of interactions) by automatically attempting to infer the field types and message dependencies of the TA API through its interactions, designing state- and type-aware fuzzing mutators, and creating an in situ, on-device fuzzer.
We found 13 previously unknown bugs in the latest versions of OPTEE TAs. We also ran TEEzz on popular phones and found 40 unique bugs for which one CVE was assigned so far.
#hw_ioNL2023 #fuzzing #android #TEE
-------------------------------------------------------------------------------------------------------------------------------------------------------
Website: hardwear.io
X : / hardwear_io
LinkedIn: / hardwear.io-hardwarese...
Facebook: / hardwear.io

КОМЕНТАРІ
The FULL Beginner to Pro Roadmap for Android Development in 2023
10:47
Philipp Lackner
Переглядів 223 тис.
Nemo - The Code (LIVE) | Switzerland🇨🇭| Grand Final | Eurovision 2024
03:28
Eurovision Song Contest
Переглядів 13 млн
everyone should test their code this way
8:34
Low Level Learning
Переглядів 76 тис.
API vs. SDK: What's the difference?
9:21
IBM Technology
Переглядів 1,4 млн
Compiler Backdooring For Beginners - Marion Marschalek
54:43
Ringzer0 Training
Переглядів 583
Android App Bug Bounty Secrets
20:14
LiveOverflow
Переглядів 92 тис.
Hacking APIs: Fuzzing 101
13:29
The Cyber Mentor
Переглядів 42 тис.
Troubleshooting Memory Problems in Java Applications
42:37
Java
Переглядів 63 тис.
Теперь это его телефон
0:21
Хорошие Новости
Переглядів 847 тис.
The PA042 SAMSUNG S24 Ultra phone cage turns your phone into a pro camera!
0:24