DEF CON 27 - Intro to Embedded Hacking-How you can find a decade old bug in widely deployed devices @HackersOnBoard
DEF CON 27 - Intro to Embedded Hacking-How you can find a decade old bug in widely deployed devices  @HackersOnBoard
Uploaded December 2019 | Updated September 2026, 1 day ago
From small business to large enterprise, VOIP phones can be found on nearly every desk. But how secure are they? What if your phone was spying on every conversation you have?

This talk is an introduction to hardware hacking and as a case study I'll use the [REDACTED] Deskphone, a device frequently deployed in corporate environments. I'll use it to introduce the tools and methodology needed to answer these questions.

During this talk, attendees will get a close up look at the operations of a hardware hacker, including ARM disassembly, firmware extraction using binwalk, micro-soldering to patch an EEPROM and get a root shell over UART, and ultimately uncover an already known decade-old bug that somehow remained unnoticed in the device's firmware.

Beyond the case study I will also address alternative tactics; some did not work, others may have but were not the lowest-hanging fruit. When it comes to hardware hacking, the process is as important as the result; knowing that there are multiple ways to reach the end goal helps researchers remain confident when hurdles arise. After the talk, attendees will have an increased distrust towards always-on devices; however, they will have the background knowledge to investigate the products and systems they encounter daily.

Intro to Embedded Hacking-How you too can find a decade old bug in widely deployed devices. [REDACTED] Deskphones, a case study.
DEF CON 27 - Intro to Embedded Hacking-How you can find a decade old bug in widely deployed devicesBlack Hat USA 2018 - WireGuard Next Generation Secure Network TunnelBlack Hat USA 2018 - A Dive in to Hyper V Architecture & VulnerabilitiesBlack Hat USA 2018 - Its a PHP Unserialization Vulnerability Jim, but Not as We Know ItBlack Hat USA 2018 - Measuring the Speed of the Red Queens Race - Adaption and Evasion in MalwareDEF CON 27 - Mike Spicer - I Know What You Did Last Summer 3 Years of Wireless Monitoring at DEF CONBlack Hat USA 2018 - Compression Oracle Attacks on VPN NetworksBlack Hat USA 2018 - Are You Trading Stocks Securely Exposing Security Flaws in Trading TechnologiesBlack Hat USA 2018 - Stress and Hacking Understanding Cognitive Stress in Tactical Cyber OpsDEF CON 27 - Damien Cauquil - Defeating Bluetooth Low Energy 5 PRNG for Fun and JammingBlack Hat USA 2018 - Qualitative Look at Autonomous Peer Communications Impact on Phishing...Black Hat USA 2018 - Snooping on Cellular Gateways and Their Critical Role in ICS
HackersOnBoard |

DEF CON 27 - Intro to Embedded Hacking-How you can find a decade old bug in widely deployed devices

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER