DEF CON 27 - Xiling Gong - Exploiting Qualcomm WLAN and Modem Over The Air @HackersOnBoard
DEF CON 27 - Xiling Gong - Exploiting Qualcomm WLAN and Modem Over The Air  @HackersOnBoard
Uploaded December 2019 | Updated September 2026, 1 hour ago
In this talk, we will share our research in which we successfully exploit Qualcomm WLAN in FIRMWARE layer, break down the isolation between WLAN and Modem and then fully control the Modem over the air.

Setup the real-time debugger is the key. Without the debugger, it's difficult to inspect the program flow and runtime status. On Qualcomm platform, subsystems are protected by the Secure Boot and unable to be touched externally. We'll introduce the vulnerability we found in Modem to defeat the Secure Boot and elevate privilege into Modem locally so that we can setup the live debugger for baseband.

The Modem and WLAN firmware is quite complex and reverse engineering is a tough work. Thanks to the debugger, we finally figure out the system architecture, the components, the program flow, the data flow, and the attack surfaces of WLAN firmware. We'll share these techniques in detail, along with the zero-days we found on the attack surfaces.

There are multiple mitigations on Qualcomm baseband, including DEP, stack protection, heap cookie, system call constraint, etc. All the details of the exploitation and mitigation bypassing techniques will be given during the presentation.

Starting from Snapdragon 835, WLAN firmware is integrated into the Modem subsystem as an isolated userspace process. We'll discuss these constraints, and then leverage the weakness we found to fully exploit into Modem.
DEF CON 27 - Xiling Gong - Exploiting Qualcomm WLAN and Modem Over The AirBlack Hat USA 2018 - Automating Exploit Generation for Arbitrary Types of Kernel VulnerabilitiesBlack Hat USA 2018 - Another Flip in the RowDEF CON 27 - g richter - Reverse-Engineering 4g Hotspots for Fun Bugs and Net Financial LossBreaking Parser Logic: Take Your Path Normalization off and Pop 0days Out!Black Hat USA 2018 - From Bot to Robot How Abilities and Law Change with PhysicalityDEF CON 27 - Campbell Murray - GSM We Can Hear Everyone NowDEF CON 27 - Jayson Grace - MOSE Using Configuration Management for EvilDEF CON 27 - Jens Muller - Re Whats up Johnny Covert Content Attacks on Email End-to-End EncryptionBlack Hat USA 2018 - Mainframe [z/OS] Reverse Engineering and Exploit DevelopmentDetecting Malicious Cloud Account Behavior A Look at the New Native Platform CapabilitiesDEF CON 27 - Zombie Ant Farm Practical Tips for Playing Hide and Seek with Linux EDRs
HackersOnBoard |

DEF CON 27 - Xiling Gong - Exploiting Qualcomm WLAN and Modem Over The Air

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER