From Printed Circuit Boards to Exploits: Pwning IoT Devices Like a Boss - Damien Cauquil - Hack in Paris - 2018
Hack in Paris via YouTube
Overview
Syllabus
Intro
What this talk is not about
What this talk is about
Existing methodologies
Digital security
Data Extraction
Data Analysis
Wireless Communications
Analogies
Smart Dog
Marvel Soft
Tools
Smart lock
A single tip
Global analysis
PCB design
Connectors
Components
Schematics
Schematic example
Data sheets
Final result
Debug mode
Modulation
Firmware
Debugging
Extracting firmware
OTA
Xcode
Search for strings
Spare data
Outofband data disparity
Target architecture
What architecture is
OS and file system
Linux
Soft device
Get SDK version
Drop binaries
Disassemble
Getting the code
Disassembling the code
Automation
Software
Github
Mobile applications
Details about everything
How do we perform this
Hardware needed
How it works
Mobile application
Lowhanging fruit
Analysis
Security issues
Replay attack
Exploit
Solution
The exploit
The more interesting thing
Reverse engineering
Conclusion
Pro tips
Start from the bottom
Epson D600 scanner
Conclusions
Questions
Taught by
Hack in Paris