How To Hack Shannon Baseband (from A Phone) by Natalie Silvanovich | hardwear

  Переглядів 1,605

hardwear.io

hardwear.io

День тому

Abstract:
-----------------
Samsung baseband modems provide mobile network functionality to a variety of devices. Project Zero reviewed the Samsung 'Shannon' Exynos 5300 modem used by the Google Pixel 7, discovering and reporting several vulnerabilities. While many of these could only be exploited using a local base-station or compromised mobile network, some could be accessed remotely cross-carrier, requiring only a rooted mobile phone to perform the attack. This presentation will explore fully-remote baseband vulnerabilities.
It will start with an overview of the attack surface of the Exynos 5300 modem, and describe the bugs we found, then explain how to test such vulnerabilities on a remote target using a rooted Samsung phone. This talk will then discuss how to exploit such bugs, as well as ways an attacker could make use of a modem compromise
#shannon #baseband #hardwaresecurity #hardwear_io #hw_ioUSA2023
---------------------------------------------------------------------------------------------------------------------
Website: hardwear.io
Twitter: / hardwear_io
LinkedIn: / hardwear.io-hardwarese...
Facebook: / hardwear.io
0:00 Introduction
0:15 Baseband Hackathon
7:52 P2P Attack Surface
9:28 Dumping baseband
9:51 Analysis
10:59 Crashdumps
12:42 Code review
13:40 Filtering
18:59 QEMU emulator
20:47 CVE-2022-26497
22:30 CVE-2022-29090 (SIP)
23:20 Testing P2P bugs
24:41 Exploitation
25:37 95300 security features
27:15 Shannon heap
28:55 Heap 6
30:23 First Attempt
33:37 Overwrite
35:28 Code exec from heap
36:17 Shellcode
37:45 Now what? (for real)
41:48 Questions

КОМЕНТАРІ: 5
@gowononly6197
@gowononly6197 8 місяців тому
Mimo picks his nose and eats it
@marbleop9881
@marbleop9881 9 місяців тому
could you get a mic that sounds less like Xbox?
@idkasd
@idkasd 9 місяців тому
the sensual neck rubbing at 15:10 made me uncomfortable
@angusyoung8845
@angusyoung8845 9 місяців тому
her voice makes me feel uncomfortable
@stok3si3
@stok3si3 9 місяців тому
Nobody cares
How to Start a Speech
8:47
Conor Neill
Переглядів 19 млн
didn't want to let me in #tiktok
00:20
Анастасия Тарасова
Переглядів 8 млн
Does This Hack Mean You Can Listen To POLICE Radio?
6:39
Ringway Manchester
Переглядів 108 тис.
Meet a 12-year-old hacker and cyber security expert
5:01
CBS Mornings
Переглядів 7 млн
Pwntools ROP Binary Exploitation - DownUnderCTF
55:21
John Hammond
Переглядів 85 тис.
Everything You Need to Know About 5G
6:15
IEEE Spectrum
Переглядів 2,6 млн
Roblox Exploiting - Rate My Avatar
8:15
Citizen
Переглядів 861 тис.
Learning to Hack as a Kid
5:03
TimTom
Переглядів 10 млн
Recon 2023 Natalie Silvanovich How To Hack Shannon Baseband
54:16
Recon Conference
Переглядів 425
Такого вы точно не видели #SonyEricsson #MPF10 #K700
0:19
BenJi Mobile Channel
Переглядів 3,3 млн