DEF CON 32 - SBOMs the Hard Way Hacking Bob the Minion - Larry Pesce

  Рет қаралды 131

DEFCONConference

DEFCONConference

Күн бұрын

This presentation delves into the intricate process of generating a Software Bill of Materials (SBOM) for the Bob the Minions WiFi router by Davolink-a device whose firmware isn't publicly available. Traditional SBOM creation methods rely on readily accessible firmware, but Davolink's restricted release policies necessitated an unconventional approach. This talk covers the step-by-step journey of hardware disassembly, firmware extraction via SPI flash and JTAG/SWD interfaces, and the tools and techniques employed. Finally, we'll demonstrate how the recovered firmware is used to generate a comprehensive SBOM, highlighting any security vulnerabilities discovered and reported to the vendor. This session aims to provide attendees with practical insights into overcoming SBOM generation challenges in the IoT domain through hands-on hardware hacking, and leveraging the firmware and SBOMs for vulnerability discovery, as well as security improvement.

Пікірлер
Thumb-turn easy bypass theory..... #BUSTED!!
8:47
The Myth-busting locksmith. @2M Security
Рет қаралды 2,8 М.
"كان عليّ أكل بقايا الطعام قبل هذا اليوم 🥹"
00:40
Holly Wolly Bow Arabic
Рет қаралды 3,9 МЛН
Зу-зу Күлпаш 2. Бригадир.
43:03
ASTANATV Movie
Рет қаралды 758 М.
小天使和小丑太会演了!#小丑#天使#家庭#搞笑
00:25
家庭搞笑日记
Рет қаралды 58 МЛН
Hacking the Hackers: The Art of Compromising C2 Servers with Vangelis Stykas
34:39
DEF CON 32 - Winning the Game of Active Directory - Brandon Colley
43:05