New writeup on finding the abandoned NES emulator features in Animal Crossing and using them to get code execution via memory card: https://t.co/NxibYPyxsz
Despite providing proof of concept exploits and multiple rounds of feedback on patches, Espressif refused to acknowledge the memory corruption bugs as security vulnerabilities and won't be issuing any advisories.
Disclosure is finally up for some vulns in the ESP32 BluFi reference app: https://t.co/OmQVWBdX15 most interesting bug to me is the DH public key calculation buffer overflow.
Checkout the new NanoMIPS plugin/blog post that aided in reverse engineering a Mediatek-based 5G modem image! https://t.co/OwlQmtbFlx #cybersecurity#infosec#tech
Wrote an overview of using the different Ghidra decompiler simplification styles for P-Code analysis, how to trace the decompilation process, and getting around some issues with analyzing stack write operations. Even used a bug in Ghidra to alter the analysis configuration :)
Blog: earlyremoval, in the Conservatory, with the Wrench: Exploring Ghidra’s decompiler internals to make automatic P-Code analysis scripts - https://t.co/cGfRQPvA5Z - by James Chambers
Tool Release: Ghostrings - a collection of Ghidra scripts for recovering string definitions in Go binaries with P-Code analysis - by James Chambers - https://t.co/OFTAxr4JDf - Code - https://t.co/FNicjLx23G
Implemented this in an emulator as well, here's the overall flow. (In the real kiosk the printer would sync video screen captures with the console for the images displayed after reboot.)
I've been reverse engineering Pokemon Snap (N64) to restore the Blockbuster sticker printing kiosk functionality without the kiosk, finally made some good breakthroughs
I only recently found out the 2010 HOPE badge was also a GoodFET, but I did distinctly remember there was some kind of puzzle hidden in the firmware. In keeping with doing this 11 years late, I dumped the firmware with a GreatFET and found some ciphertext and a raw RGB565 image
@Sierraffinity I never finished the UI improvements I wanted before release to make it more usable without recompiling 🐢 I'd like to take another look at finishing that when I have some time for projects (this month hopefully), worst case I'll just release it as is
@MeganPuddin For .map files what I've done before is make an IDAPython script to extract the function names and addresses and then call idc.MakeFunction, idc.MakeName for each of them. I'm not familiar with the .sym format, the tricky part might be figuring out how to parse the function info