Drones are hot - their security is not.
Here is how removed the NAND, dumped firmware, and reverse-engineered ECC on a consumer drone. Stay tuned for part 2!
https://t.co/QzfcR2HEyC
@boredpentester Tried unicorn from scratch, but I think it would take too much time to get it working. Ended up patching the memory on the printer by doing a trampoline hook, and capturing a snapshot that way. This works surprisingly well until the next external interrupt is supposed to happen.
@boredpentester TLDR: I now have crazy good introspection, but probably should have started looking for bugs earlier instead of writing better tooling for RE.
@boredpentester I have used this bug: https://t.co/PqZa3oPR92 and wrote a framework to hook the serial printing function, can now even do snapshot fuzzing, but didn't find a bug in time.
Excited to present my research @hack_lu while not much new, I learned a ton. Never done AES fault injection before, always nice to have a real-world example to work on.
Check out our new blog post on a research-driven look at software-only DRM. Explore how the Qiling emulation framework can be used to analyze Widevine and how Differential Fault Analysis (DFA) and emulation aid de-obfuscation.
▶️ Read more: https://t.co/v9wyj5eqy0
Success! We had a little configuration confusion, but Team Neodyme (@Neodyme) hopped for joy as their exploit of the Amazon Smart Plug was successful. Their attack went over Bluetooth & WiFI, so they used the RF enclosure. They head off to the disclosure room with details. #Pwn2Own
Confirmed! Team @Neodyme used three bugs to exploit the Amazon Smart plug. In doing so, they earn themselves $20,000 and 2 Master of Pwn points. #Pwn2Own
🖨️ Print victory! Team @Neodyme just hacked the @CanonUSA imageCLASS MF654Cdw at #Pwn2Own. They head off to the disclosure room once more to provide the details of their exploit. #P2OIreland
While our colleagues hack live at #Pwn2Own in Cork, take a look at our newly published last year's writeup on our blog: We compromised a QNAP router to take over a networked Canon printer.
▶️ Read the findings and how we got there: https://t.co/9ykn0eKgCi
This exploit was a lot of teamwork at Neodyme. @D_K_Dev dumped the flash, I built the tooling for reversing and wrote the exploit, @0x4d5aC spotted the bug, and Daniel, Florian, and Justin presented the whole thing on stage! I'm super happy that everything worked out in the end.
Our first confirmation of #Pwn2Own Ireland is in! @Neodyme used a stack based buffer overflow to exploit the HP DeskJet 2855e. They earn $20,000 and 2 Master of Pwn points. #P2OIreland
At #Pwn2Own Ireland 2024, we successfully targeted the SOHO Smashup category. 🖨️
Starting with a QNAP QHora-322 NAS, we pivoted to the Canon imageCLASS MF656Cdw - and ended up with shellcode execution.
Read the full vulnerability deep dive here 👉 https://t.co/Lx8T5mLVaL
From iframes and file reads to full RCE. 🔥
We found an HTML-to-PDF API allowing file reads and SSRF - then chained it into remote code execution via a Chromium 62 WebView exploit.
👉 Read the full write-up here: https://t.co/Qa5Beuuncr
If you're a security researcher and in Germany, consider signing https://t.co/6x5ajjZSxq . Decriminalizing research might not be the top political priority right now, but it's still important!
The Cyber Security Challenge Germany 2025 has started! 🎉
The competition runs from March 1 - 18:00 CET to May 1 - 18:00 CEST.
We're excited to announce that we are inviting the top 6 DACH players in the EARTH category to the @DHM_ctf!
Participate now at: https://t.co/ZZLBE5Rk0Q
Pwndbg 2025.01 is out! It adds official LLDB support including support for macOS and Mach-O binaries, improved performance, enhanced embedded debugging & many more!
Also, want to support us or buy us a coffee? See our GH sponsors: https://t.co/1KVYKgrXMV
https://t.co/oJmymEeSiC
Last year @stacksmashing presented the pico-sniffer, this year Thomas (https://t.co/zWs4hVUCbi) demonstrates a software-only attack that would make breaking Bitlocker even easier!
From startups to large companies, we've seen this setup used by many corporate clients in the wild. Here's why this is so difficult to fix and Microsoft has not changed the exploitable default settings yet:
https://t.co/LgBXyyJJKh
ND people are @ #38c3 in Hamburg, Germany. Be sure to check out our two talks about LPEs in AV/EDR Products (Saturday, 4 PM YELL) and a not yet mitigated Bitlocker Flaw! (Saturday, 7:15 PM HUFF)
@alexjplaskett There are also the community stages, I have already gotten a few insights into the talk "Windows BitLocker: Screwed without a Screwdriver" from my colleague and am excited to see the result!
https://t.co/UqiGiTomEL
💥When security software itself becomes a target! 💥
Learn how we've uncovered critical vulnerabilities in Wazuh, turning a powerful security tool into an unexpected attack vector.
👉 Read more about the findings: https://t.co/aqWvibltbA