Our most recent blog peeks behind the scenes of our hardware security research - how custom PCBs & small-scale circuit assembly allows us to explore new attack surfaces. We hope that sharing this enables other people to learn from our tips-and-tricks:
https://t.co/11QrVnBdfi
Glitching has become a critical part of our hardware hacking toolkit. Today we release a new open source tool, FlashBASH, to help automate electrical glitching tests to break into serial consoles! #hardwaresecurity#hardwarehacking
https://t.co/orAKvWSPyF
Our newest team member Kevin shares a useful how-to on adding chip support to Flashrom – a commonly used open source tool for extracting contents from flash memory chips. #embedded#hardwarehacking https://t.co/pSIOnuFBjq
Our final installment of the HW 101 JTAG blog post series is out - we cover how to communicate with a target device via JTAG once the pinout has been identified. OpenOCD & GDB step-by-step on a real system. Take a look! https://t.co/Bcvuana7Qq
In the next installment of our hardware hacking 101 series, we introduce JTAG – while it originates from the world of manufacturing and electronics testing, it has major implications for hardware security today.
https://t.co/FLM0amRRwL
... we're excited that our team will be "sharing the design for this port with DOE, vendors, and other community leaders to jumpstart a discussion on what additional tools are needed to properly equip grid response teams." 3/3
Excerpts about our work as part of a team on @DARPA#RADICS where we are "... developing a forensics port ... for local access to a variety of diagnostic information ..." https://t.co/wKqu0aaUYl 1/3
... using this "authorized users can perform ... memory validation and forensic imaging without compromising vendor IP or a utility’s proprietary information." - a key item which we spent significant design and cryptographic engineering effort on! 2/3
Take a look at #ninjadiff, our newly released an open source binary diffing plugin for BinaryNinja! You can read about how it works and get it via https://t.co/hikqqNnEe7
Submit issues, pull requests, and give us feedback!!!
Great work led by @TheWizard0f0dd
CC @vector35
We often get questions about when a pentest is most helpful & valuable to an organization. We hope this blog is helpful in sharing some of our observations over the years on when & how one can best help an organization.
https://t.co/ZtqKgUDPyu
@uffeux Yes, we do! We're working to be able to make more info public, and will aim to release slides (which include a TPMGenie shoutout for the prior work in I2C!). We would defer to the conference on if they release video.
We recently shared some of our research on #hardware implants for the TPM bus - specifically FPGA decoding/modification on LPC bus TPMs.
Come read a brief overview on what our team shared at #ieee PAINE.
https://t.co/fIVHwlufdZ
@virtualabs@virtualabs take a look at https://t.co/nsD6Bgfix8 and give it a try! Please feel free to submit PRs to that branch with new features/etc and let us know if you have any issues!
@virtualabs Yes, there is an internal py3 branch that has had a lot of work pending release. I'll ask the developer to push it out to a branch for you.
If you're involved in connected devices, IoT, or related fields in the US, knowing what's coming with the new IoT-related law is a must. You can study up quickly before the holiday at https://t.co/mgBvQsQSeR
Check out CVE-2020-13995, found by our team member @cyberingcc! Great work applying some new tooling and lessons from research we developed to find a number of issues within an implementation of the US NITF (overhead imagery format) specification. See https://t.co/N2rcdbaeax
As part of our work using binary instrumentation and static analysis to understand parsers’ de facto file format specifications, @cyberingcc
found parts of the spec which are likely to lead to implementation errors and vulnerabilities.
https://t.co/Rkf1zjq2V5
A well segmented (security) architecture is difficult when designed from the start - and even tougher to do after-the-fact along with an acquisition transaction. Take a look at https://t.co/OTeeVJfkZj - only the tip of the iceberg of work to do. @Reuters@Microsoft@tiktok_us
Check out the great work by our friends at @grimmcyber (Adam Nichols, et al) which expanded on the analysis we did of the DJI Mimo app to look at some of the same issues (and others) in the DJI GO 4 app.
https://t.co/JCiqXIzP2S
https://t.co/VCTejoEqws