Unnamed Reverse Engineering Podcast

007 - Candy Coated


Listen Later

M. Carlton joined us to talk about being part of leading professional reverse engineering team at Senr.io. We discussed her Embedded Systems talk about IoT and in particular Devil's Ivy (Check out the important ROP video to better understand the key concept ). In this particular case, they found that the M300 camera model using GSOAP (SOAP) parse for buffer overflow.

Not only did this issue allow spread quickly as a DOS among the M300 cameras but over 200 other Axis cameras (Hurray for code-reuse) due to using the third party code library.

M. uses several tools in her work:

  • IDA Pro
  • Binwalk
  • Nmap
  • Debuggers like gdb
  • Multimeters and oscilloscopes
  • VMWare

She had some excellent suggestions for improving the odds of NOT getting hacked:

  1. Put a password on any consoles and let it be changeable.
  2. Anticipate issues by performing security reviews.
  3. Be wary of any third party libraries you use. If there are updates to these libraries, prepare to update quickly.
  4. Make sure your systems are field patchable/updateable, securely.
  5. Limit surface area. Limit the ability for others to analyze your system by removing/disabling consoles, UARTs, features, and JTAG interfaces.
  6. Put more gates/obstacles on how easily any found exploits can be used in the system.
  7. Unearth any default credentials used in your system and resolve.

In the worse case, plan in advance for a security breach to expedite deployment.

Have comments or suggestion names for us? Find us on twitter @unnamed_show,  or email us at [email protected].

Music by TeknoAxe (http://www.youtube.com/user/teknoaxe)

...more
View all episodesView all episodes
Download on the App Store

Unnamed Reverse Engineering PodcastBy Jen Costillo and Alvaro Prieto

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

40 ratings


More shows like Unnamed Reverse Engineering Podcast

View all
Hacked by Hacked

Hacked

184 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,001 Listeners

Risky Business by Patrick Gray

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

637 Listeners

The Amp Hour Electronics Podcast by The Amp Hour (Chris Gammell and David L Jones)

The Amp Hour Electronics Podcast

232 Listeners

Embedded by Logical Elegance

Embedded

192 Listeners

Python Bytes by Michael Kennedy and Brian Okken

Python Bytes

214 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,010 Listeners

CoRecursive: Coding Stories by Adam Gordon Bell - Software Developer

CoRecursive: Coding Stories

188 Listeners

Hackaday Podcast by Hackaday

Hackaday Podcast

64 Listeners

2.5 Admins by The Late Night Linux Family

2.5 Admins

99 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

44 Listeners

Oxide and Friends by Oxide Computer Company

Oxide and Friends

59 Listeners

The New Quantum Era - innovation in quantum computing, science and technology by Sebastian Hassinger

The New Quantum Era - innovation in quantum computing, science and technology

40 Listeners

Complex Systems with Patrick McKenzie (patio11) by Patrick McKenzie

Complex Systems with Patrick McKenzie (patio11)

133 Listeners