INFOSEC NIGHT: Intro to Firmware Exploitation


Details
This presentation will cover some basic ideas to exploit firmware. We will be discussing basics of firmware, acquiring firmware, extraction, analysis, and (if time allows) backdooring firmware. Hands-on examples for extraction and analysis will be conducted. Basic concepts, such as Linux file structure and tools, will be covered.
GOAL: Extract and analyze firmware for exploitation/bug hunting.
THINGS TO BRING: Note taking material. If wanting to follow along with the exercise, bring a laptop with your favorite version of Linux installed. Download the following tools ahead of time - Binwalk (https://github.com/ReFirmLabs/binwalk), Firmware Mod Kit (https://github.com/rampageX/firmware-mod-kit/wiki), Firmware Analysis Toolkit (https://github.com/attify/firmware-analysis-toolkit), Firmwalker (https://github.com/craigz28/firmwalker), and qemu (from your distro repository)
SKILL LEVEL: Everyone
PRESENTER: Nyte

INFOSEC NIGHT: Intro to Firmware Exploitation