Jump to content
Nytro

Hacking Embedded Devices For Fun And Profit

Recommended Posts

Posted

Hacking Embedded Devices For Fun And Profit

Authored by prdelka

These are slides from a talk called Hacking Embedded Devices for Fun and Profit. It uses Sky Broadband as a case study.

HISTORY REPEATS ITSELF...

- Typically run with no privilege separation

- Everything runs as highest user privilege

- SYSTEM / root (uid=0) on all processes

- A single defect could potentially compromise the platform

- Embedded Developers are not Security Conscious

- Commonly write insecure routines

- XSRF / XSS

- Design & Logic bugs (e.g. Directory Traversal)

- Buffer Overflow Defects

- Small number of commonly re-used Libraries

- Devices re-use open-source libraries across platforms

- SNMP

- UPnP

- BusyBox

- TinyHttpd, Micro_Httpd … etc

Download:

http://dl.packetstormsecurity.net/papers/attack/Hacking_Embedded_Devices-HackerFantastic.pdf

Sursa: http://packetstormsecurity.org/files/106684

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...