Extremely excited to announce that I will be speaking at @BlackHatEvents#BHAsia this year, with my talk surrounding exploitation of smartphone Boot ROMs, and what can be achieved on a target by compromising the boot chain! https://t.co/eKHIQILJjY
PSA: If you do fuzzing research, don't even bother trying to beat AFL++. Just start your evaluation when the ensemble of other existing fuzzers has thoroughly plateaued (I.e. 100h+). Go find problems that can't be solved rn. Don't try to get another 1% gain in the first 48h.
@travisgoodspeed I believe this mechanism was also vulnerable to TOCTOU on the original Gameboy, you could display a custom logo if you altered the memory on the cartridge after the first comparison.
Wrote an article about turning a ThinkPad X1 Carbon 6th Gen laptop into a programmable USB device by enabling the xDCI controller 😯
Now I can emulate USB devices from the laptop without external hardware, including via Raw Gadget or even Facedancer 😁
https://t.co/B46Su8Wu9C
CVE-2024-22012 In TBD of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution pr… https://t.co/hR0EJvmP5a
Congratulations to our top hackers who have won our annual year-end bonus awards for 2023! Thank you for your hard work and dedication last year. We are always looking for talented individuals to join us.
Hope to see you next year!!
#JoinUs#YearEndBonus#GratefulHeart#OSRC #OPPO
I loved the exploitation required for this one, however this will always be my greatest bootloader hacking achievement: https://t.co/cnZVGLnA2D https://t.co/Grf3vtUI2E
Also, here is my exploit for the PN553, an NFC chip from a series which was found an insane number of phones at the time of analysis: https://t.co/bP2ZdAv1QG this version purely dumps the BootROM from the chip, and could be adapted to most non-updated PN series chips.
@olemoudi Great points, thanks for summarising! The only thing I would add is that devices are still vulnerable to cold boot attacks (RAM dump on reboot) if you compromise the bootloader, even if it isn't unlocked, so there is still some risk of forensic attacks.
I massively enjoyed doing this talk at both conferences, there was great feedback and met some interesting people! Feel free to give the slides a read!
As the DEF CON media server has uploaded my slides, I can confirm that the talk I am doing tomorrow will be a two parter, with the second part being a secure boot compromise of Exynos-based Samsung smartphonss!