DEF CON 27 - Wenxiang Qian - Breaking Google Home: Exploit It with SQLite(Magellan) @HackersOnBoard
DEF CON 27 - Wenxiang Qian - Breaking Google Home: Exploit It with SQLite(Magellan)  @HackersOnBoard
Uploaded December 2019 | Updated September 2026, 9 hours ago
Over the past years, our team has used several new approaches to identify multiple critical vulnerabilities in SQLite and Curl, two of the most widely used basic software libraries. These two sets of vulnerabilities, which we named "Magellan" and "Dias" respectively, affect many devices and software. We exploited these vulnerabilities to break into some of the most popular Internet of things devices, such as Google Home with Chrome. We also exploited them on one of the most widely used Web server (Apache+PHP) and one of the most commonly used developer tool (Git).

In this presentation, we will share how we try to crack the Google Home from both hardware and software aspects, get and analyze the newest firmware, solve the problem, and introduce new methods to discover vulnerabilities in SQLite and Curl through Fuzz and manual auditing. Through these methods, we found "Magellan", a set of three heap buffer overflow and heap data disclosure vulnerabilities in SQLite ( CVE-2018-20346, CVE-2018-20505 CVE-2018-20506 ) We also found "Dias", two remote memory leak and stack buffer overflow vulnerabilities in Curl ( CVE-2018-16890 and CVE-2019-3822 ). Considering the fact that these vulnerabilities affect many systems and software, we have issued a vulnerability alert to notify the vulnerable vendor to fix it.

We will disclose the details of "Magellan" and "Dias" for the first time and highlight some of our new vulnerability exploitation techniques. In the first part, we will introduce the results of our analysis on hardware, how to get the newest firmware from simulating an update request, and attack surface of Google Home. We will show how to use Magellan to complete the remote exploit of Google Home, we will also give a brefing talk about how to use Dias to complete the remote attack on Apache+PHP and Git. Finally, we will summarize our research and provide some security development advice to the basic software library developers.
DEF CON 27 - Wenxiang Qian - Breaking Google Home: Exploit It with SQLite(Magellan)DEF CON 27 - Joe Grand - Behind the Scenes of the DEF CON 27 BadgeDEF CON 27 - Firmware Slap Automating Discovery of Exploitable Vulnerabilities in FirmwareBlack Hat USA 2018 - Threat Modeling in 2018 Attacks, Impacts and Other UpdatesDEF CON 27 - Bernhard Mueller - The Ether Wars Exploits counter-exploits and honeypots on EthereumDEF CON 27 - Omer Yair - Exploiting Windows Exploit Mitigation for ROP ExploitsDEF CON 27 - jiska - Vacuum Cleaning Security Pinky and the Brain EditionHacking the Samsung Galaxy S8 IrisscannerDEF CON 27 - Michael Leibowitz - EDR Is Coming Hide Yo Sh!tBlack Hat USA 2018 - Holding on for Tonight Addiction in InfoSecBlack Hat USA 2018 - Practical Web Cache Poisoning Redefining UnexploitableBlack Hat USA 2018 - Automated Discovery of Deserialization Gadget Chains
HackersOnBoard |

DEF CON 27 - Wenxiang Qian - Breaking Google Home: Exploit It with SQLite(Magellan)

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER