ZA·014 Talk 2019

Hashing the $#!+ out of firmware

Event
BSides Cape Town
Region
South Africa
Language
EN

Abstract

Everything is broken... But is it possible that more things are more broken than we though? Probably. But lets look at that. When it comes to embedded devices, we rely largely on the OEM manufacturer to provide firmware and firmware updates. These updates could be issued for a number of reasons: better performance, improved feature set, bug fixes, and security patches. But when you download a firmware update, you generally only have the manufacturer's word that it does what it says, with information sometime being provided in the change-log. But these change logs don't always tell all. This research looks at pulling firmware apart to see whats inside, and comparing firmwares to see what might have changed (between versions), and what might be getting reused (between different devices).