
(CORE Security Technologies)In this talk we present how to reverse-engineering Canon Powershot digital cameras and take control of most of them to exploit interesting security threats. We present a novel attack method that allows taking control of a digital camera through a compromised memory card. This is a realistic attack scenario, as using the card in unsecured PCs is a common practice among many users. This attack vector leaves users of digital cameras vulnerable to many threats including privacy invasion and those targeting the camera storage.
To implement the attack we abuse testing functionality of the in-factory code. We will show how to analyze the code running in the camera's CPUs and find the parts relevant to the attack. We further show how to debug an emulated copy of the firmware in QEMU.
In contrast with firmware-modding projects like CHDK, our method doesn't require as much user interaction or firmware modification, and our techniques are mostly model-independent.
Finally, we show same proof-of-concept attacks launched from the camera to PCs
Estamos orgullosos de anunciar la octava edición de la ekoparty security conference.Una vez más, e...
A solo días de la edición 2011 de la ekoparty, varios trainings han sido vendidos completamente, y...
El próximo 26 de Julio de 2011, tendrá lugar la jornada solidaria #1HackParaLosChicos, enterate co...
De la mano de IMMUNITY, empresa líder en el desarrollo de aplicaciones para penetration testing, tr...
Tenemos el placer de anunciar, que el Slogan votado por la gente, para representar a la ekoparty 201...
diseño: GrafikaWeb