DEF CON 27 - Backdooring Hardware Devices By Injecting Malicious Payloads On Microcontrollers @HackersOnBoard
DEF CON 27 - Backdooring Hardware Devices By Injecting Malicious Payloads On Microcontrollers  @HackersOnBoard
Uploaded December 2019 | Updated September 2026, 7 hours ago
Is targeting microcontrollers worth the effort? Nowadays, they are responsible for controlling a wide range of interesting systems, e.g., physical security systems, car's ECUs, semaphores, elevators, sensors, critical components of industrial systems, some home appliances and even robots.

In this talk, it will be explained how microcontrollers can be backdoored too. After a quick review of basic knowledge about uC, we will dive into three different approaches to achieve payload injection, from basic to advanced techniques. The first method consists on locating the entry point of the firmware and inject our payload there, this is an easy way to execute it at least once. As a second -and more complex- technique, we will backdoor the EUSART communication injecting a malicious payload at the code routine of that hardware peripheral; we will be able to get the right memory address by inspecting the GIE, PEIE and polling process at the uC interrupt vector. Finally, the third technique allow us to take control of the microcontroller's program flow by manipulating the stack writing memory addresses at the TOS; with this we can execute a payload made with instructions already written in the original program, performing it just like a ROP-chain technique.


Talk by Sheila Ayelen Berta
DEF CON 27 - Backdooring Hardware Devices By Injecting Malicious Payloads On MicrocontrollersDEF CON 27 - Patrick Wardle - Harnessing Weapons of Mac DestructionDEF CON 27 - How You Can Buy ATandT T-Mobile and Sprint Real-Time Location Data on the Black MarketDEF CON 27 - Pedro Cabrera Camara - SDR Against Smart TVs URL and Channel Injection AttacksBlack Hat USA 2018 - Pestilential Protocol How Unsecure HL7 Messages Threaten Patient LivesEdge Side Include Injection Abusing Caching Servers into SSRF and Transparent Session HijackingEfail Breaking S MIME and OpenPGP Email Encryption using Exfiltration ChannelsBlack Hat USA 2018 - Exploitation of a Modern Smartphone BasebandBlack Hat USA 2018 - A Deep Dive into macOS MDM and How it can be CompromisedDEF CON 27 - Douglas McKee - HVACking Understand the Delta Between Security and RealityDEF CON 27 - Kyle Gwinnup - Next Generation Process Emulation with BineeBlockchain Autopsies - Analyzing Ethereum Smart Contract Deaths
HackersOnBoard |

DEF CON 27 - Backdooring Hardware Devices By Injecting Malicious Payloads On Microcontrollers

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER