CSCG/OpenECSC 2026 ist erfolgreich abgeschlossen! 🎉
Die besten Player aus den Kategorien Junior und Senior werden nun zum Auswahl-Event eingeladen, bei dem das deutsche Team für die ECSC in Bochum bestimmt wird.
Germany will host the European Cybersecurity Challenge (ECSC) 2026 in Bochum. NFITS e.V. will be the main organizer.
~500 participants are expected in October, with finalists competing in up to 45 national teams.
👉https://t.co/Oq5zJbnr28
Confirmed! Neodyme AG (@Neodyme) used a stack based buffer overflow to get a root shell on the Alpine iLX-F511, earning $20,000 USD and 2 Master of Pwn points. #Pwn2Own#P2OAuto
Drones are hot - their security is not.
Here is how removed the NAND, dumped firmware, and reverse-engineered ECC on a consumer drone. Stay tuned for part 2!
https://t.co/QzfcR2HEyC
Another amazing #Pwn2Own in the books! 💪
Our team pulled off some great hacks:
🖨️ HP Printer — $20K / 2 MoP
🏠 Home Assistant — $15K / 3 MoP
🔌 Smart Plug — $20K / 2 MoP
📸 Canon — $10K / 2 MoP
Total: $65K / 9 MoP
So proud of what we achieved together! 🧠⚡
Success! We had a little configuration confusion, but Team Neodyme (@Neodyme) hopped for joy as their exploit of the Amazon Smart Plug was successful. Their attack went over Bluetooth & WiFI, so they used the RF enclosure. They head off to the disclosure room with details. #Pwn2Own
Would you like to participate in the German Hacking Championship next year? 💻🎉Then, your next chance to qualify is this weekend! Have fun at #enowars, an attack-defense CTF hosted by @ENOFLAG.
The Cyber Security Challenge Germany 2025 has started! 🎉
The competition runs from March 1 - 18:00 CET to May 1 - 18:00 CEST.
We're excited to announce that we are inviting the top 6 DACH players in the EARTH category to the @DHM_ctf!
Participate now at: https://t.co/ZZLBE5Rk0Q
Following our #38c3 talk about exploiting security software for privilege escalation, we're excited to kick off a new blog series! 🎊
Check out our first blog post on our journey to 💥 exploit five reputable security products to gain privileges via COM hijacking: https://t.co/5ne5FBggZl
ND people are @ #38c3 in Hamburg, Germany. Be sure to check out our two talks about LPEs in AV/EDR Products (Saturday, 4 PM YELL) and a not yet mitigated Bitlocker Flaw! (Saturday, 7:15 PM HUFF)
@_h0p5 I used the xgecu t56. I first desoldered the chip and later connected fly wires to read and write in circuit. The only downside to the dumper is the software only runs on windows. But people told me it runs via wine too, but haven't tried it.
After a great #Pwn2Own with @Neodyme , I would like to share some insights I gained when working with the AeoTec Smart Home Hub. We did not manage to find any bugs in time but dumping the firmware was a great lesson. So, let’s tell you the story of how I approached this target.
Since we had used a different setup without any administrator account, our official attempt during #Pwn2Own failed. However, @thezdi provided us with a second chance to present our Lexmark exploit and it worked 🖨️🎉
@xnyhps@bl4sty So I wanted to make a different capture and found https://t.co/JG5WEP1a7c . Setting this up via a Pi4 did the trick and it started to boot from the flash drive. Still don't know why. The flash alone did not work.
@xnyhps@bl4sty I also struggled to get it working. I recorded pcaps of the USB connection via a GreatFET to debug what happens. But they looked fine, though they stopped after the first USB packet.
Now I could either reflash the emmc chip or use the nice USB-Boot mode of the custom U-Boot ;), though that required pulling Boot0 Pin high and a weird USB Flash drive config.
After some reversing and looking arround, I noticed the U-Boot version was 2017.11 . A quick search revealed CVE-2020-10648. A verified boot bypass for U-Boot. What was left was crafting a new fit image and using a custom initrd with the init command replaced, by a shell.
Our final SOHO Smashup of Day 2 ends with a partial collision. Neodyme (@Neodyme) used 4 bugs, including a stack-based buffer overflow, in their successful demonstration, but 1 bug had previously been used in the contest. They earn $21,875 and 8.75 Master of Pwn points. #Pwn2Own