@intigriti Another thing that can be done by a malicious sender, is creating multiple transactions without finalizing them. All may pass the amount check, even though their sum may pass it. If all are finalized after, you can spend more than you have
@intigriti I assumed the sender creates the transaction, and gives the recipient the id, and then the receiver finalizes the transaction. In that case, the receiver may get more than expected.
Today I presented my CANCAN research at the #escarUSA2022 conference.
First time talking at a conference! Was a lot of fun :)
CANCAN is an attack on the CAN-FD protocol, encapsulating one message inside another.
Read more on the @CymotiveTech blog:
https://t.co/E17V5zA3bS
@NathanPavlovsky@binitamshah The plugin is useful for easily following data usage in registers (as opposed to stack variables). Registers are used for this extensively in embedded systems, but the plugin can work for any system using registers.
Published my new IDA plugin for all you embedded reversers. Tired of IDAs limited possibilities of following the data flow through registers? Oregami just might change your life :)
Check it out at:
https://t.co/mvjlCl2t2U