<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Hacklu on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/hacklu/</link>
    <description>Recent content in Hacklu on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 24 Oct 2018 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/hacklu/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Hack.lu 2018: ARM IoT Firmware Emulation Workshop by Saumil Udayan Shah</title>
      <link>https://insinuator.net/2018/10/hack.lu-2018-arm-iot-firmware-emulation-workshop-by-saumil-udayan-shah/</link>
      <pubDate>Wed, 24 Oct 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/10/hack.lu-2018-arm-iot-firmware-emulation-workshop-by-saumil-udayan-shah/</guid>
      <description>&lt;p&gt;First day at &lt;a href=&#34;https://2018.hack.lu/&#34;&gt;hack.lu&lt;/a&gt;. Three of us kicked the conference off with the ARM IoT Firmware Emulation workshop by &lt;a href=&#34;https://twitter.com/therealsaumil&#34;&gt;Saumil&lt;/a&gt;. The goal of this workshop was not so much to write exploits or to pwn boxes but to learn how to build a beneficial research environment by emulating the hardware of a Linux based IoT device to run its firmware in order to run analysis and tests.&lt;/p&gt;&#xA;&lt;p&gt;First step is to obtain the firmware. This could be done by dumping it directly from the device or by downloading firmware images from the vendor. In order to dump the firmware from the device one has to obtain access to the underlying system which is usually done by finding the serial console on the hardware since this one often exposes an unauthenticated root shell. I think there is enough documentation online on how to identify and connect to a serial console so I won’t cover the details here. It’s also covered in Saumil’s &lt;a href=&#34;https://www.slideshare.net/saumilshah/hacklu-2018-make-arm-shellcode-great-again&#34;&gt;slides&lt;/a&gt; in detail. Having the bootup logs from this console will be helpful later though. While talking about baud rates for the serial console Saumil made a great pun I don’t want to withhold: “Most common is baud rate 115200. If you find a console with baud rate 9600 you are in fact talking to an acoustic coupler. That’s not an IoT device, it rather belongs to a museum.”&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
