As it turns out, fuzzing IoT devices is challenging due to extremely constrained resources. We explored Cortex-M TrustZone apps to find bugs. And we found them @IEEESSP#IEEESP2024 Paper: https://t.co/pv7ncsPx1I
Full Chain Baseband Exploits.
Details of the baseband and baseband-to-AP pivot vulnerabilities, exploitable for RCE, chained together at the same time
▶️Part 1: https://t.co/dpuDI33JhF
▶️Part 2:https://t.co/rJajpOgMdZ
▶️Part 3: https://t.co/aZVUj8GY6c
@TaszkSecLabs@kutyacica
The Old, The New and The Bypass - One-click/Open-redirect to own Samsung S22 at Pwn2Own 2022
written by @testanull
https://t.co/cN9EPOMLua
Thanks to @thezdi for reviewing and inputs to the blog post. Greatly appreciate that.
I am happy to announce that "BaseComp: A Comparative Analysis for Integrity Protection in Cellular Baseband Software" is accepted to Usenix Security '23. This work is related to static analysis to find logical bugs in baseband firmware.
I'd like to publicly introduce BinSync, a cross-decompiler collaboration tool and suite. With BinSync, you can finally share reversing data, like Types, across all your favorite decompilers (IDA, Binja, Ghidra, angr) on-the-fly. https://t.co/jjeH1VaBTi. See thread for demos.
* LTESniffer: An Open-source LTE Downlink/Uplink Eavesdropper *
We open-source LTESniffer, accepted at @acm_wisec '23.
LTESniffer supports: Real-time decoding of
+ Downlink traffic from the base station.
+ Uplink traffic from nearby users.
https://t.co/WuQ3PtswUw