ycliper

Популярное

Музыка Кино и Анимация Автомобили Животные Спорт Путешествия Игры Юмор

Интересные видео

2025 Сериалы Трейлеры Новости Как сделать Видеоуроки Diy своими руками

Топ запросов

смотреть а4 schoolboy runaway турецкий сериал смотреть мультфильмы эдисон
Скачать

BlueHat IL 2018 – Oran Avraham - eMMC Hacking, Or: How I Fixed Long-Dead Galaxy S3 Phones

Автор: Microsoft Israel R&D Center

Загружено: 2018-02-01

Просмотров: 1302

Описание: A few years ago Samsung Galaxy S3 devices started dying all around the world (a phenomenon known as "Galaxy S3 Sudden Death"). The faulty hardware was pinpointed to its eMMC chip (made by Samsung). This incident led to the belief that there's a microcontroller in it, and sparked a journey that began in finding a method to obtain the firmware, up until gaining generic code execution ability on every Samsung eMMC chip.

As this was done originally to fix Samsung S3 devices by software-only means, it was not enough. The bootloader inside every S3 (sboot) won't happily run your precious eMMC fixing code. Thus, a vulnerability had to be found. This talk uncovers two vulnerabilities in sboot which led to code execution. But how to talk with an eMMC chip, which is already dead? Well, technically yes, but apparently there's some hidden recovery mode that can be triggered by a power reset to the chip, and the phone's life is spared.

In newer eMMC chips, the firmware is slightly different, as due it its size it must be stored partially on the external NAND, with an overlay mechanism. This talk discusses the process of reversing such firmware, presents a simple Python utility to experiment with Samsung eMMC chips, and further discusses some possible applications, such as low-level NAND forensics, information hiding, and ultimately, installing a rootkit on the eMMC firmware itself.

Speaker Bio:
Oran Avraham is an Israeli Independent Researcher. He is excited about embedded device hacking and the security of such devices. Oran previously worked on openiBoot, an open-source alternative boot-loader to Apple's iBoot for iOS devices. He was mainly responsible for re-implementing the iPhone's Flash Translation Layer (FTL) in order to achieve filesystem I/O ability in openiBoot and Linux. He also found some of the vulnerabilities used to gain code execution on the iPhone's baseband, namely AT+XLOG and AT+FNS vulnerabilities used in "ultrasn0w" unlock utility. In his spare time, Oran is a CTF player. He is one of the founding members of Pasten CTF team. Oran currently works for Medigate.

Не удается загрузить Youtube-плеер. Проверьте блокировку Youtube в вашей сети.
Повторяем попытку...
BlueHat IL 2018 – Oran Avraham - eMMC Hacking, Or: How I Fixed Long-Dead Galaxy S3 Phones

Поделиться в:

Доступные форматы для скачивания:

Скачать видео

  • Информация по загрузке:

Скачать аудио

Похожие видео

BlueHat IL - Avi Lumelsky, Gal Elbaz - 0.0.0.0 Day: Exploiting Localhost APIs From The Browser

BlueHat IL - Avi Lumelsky, Gal Elbaz - 0.0.0.0 Day: Exploiting Localhost APIs From The Browser

BlueHat IL 2025 - Omer Nevo - Hack like a robot: Journey into the logic of LLM-based...

BlueHat IL 2025 - Omer Nevo - Hack like a robot: Journey into the logic of LLM-based...

BlueHat IL 2025 - Ori David - Now You See Me, Now You Don’t - Abusing VBS Enclaves to Create...

BlueHat IL 2025 - Ori David - Now You See Me, Now You Don’t - Abusing VBS Enclaves to Create...

BlueHat IL 2025 - Yonatan Zunger - Keynote - What does AI safety and security mean?

BlueHat IL 2025 - Yonatan Zunger - Keynote - What does AI safety and security mean?

6 Random $? Finds from Aliexpress

6 Random $? Finds from Aliexpress

20 КРУТЕЙШИХ ГАДЖЕТОВ С АМАЗОНА, КОТОРЫЕ ВЫ ЗАХОТИТЕ КУПИТЬ

20 КРУТЕЙШИХ ГАДЖЕТОВ С АМАЗОНА, КОТОРЫЕ ВЫ ЗАХОТИТЕ КУПИТЬ

BlueHat IL 2025 - Maor Abutbul - Let's be Authentik: Your identity is Mine

BlueHat IL 2025 - Maor Abutbul - Let's be Authentik: Your identity is Mine

AI ruined bug bounties

AI ruined bug bounties

Creating the World's Most Efficient Drone

Creating the World's Most Efficient Drone

BlueHat IL 2025 - Netanel Ben Simon, Meir Bloya - Boot Camp: A deep dive into windows boot security

BlueHat IL 2025 - Netanel Ben Simon, Meir Bloya - Boot Camp: A deep dive into windows boot security

26 НОВЫХ ТОВАРОВ с АЛИЭКСПРЕСС 2026, Новые ГАДЖЕТЫ От Которых Точно ОФИГЕЕШЬ + КОНКУРС

26 НОВЫХ ТОВАРОВ с АЛИЭКСПРЕСС 2026, Новые ГАДЖЕТЫ От Которых Точно ОФИГЕЕШЬ + КОНКУРС

BlueHat IL 2025 - Christopher Glyer - Keynote - Spy vs. Spy: Ransomware Edition

BlueHat IL 2025 - Christopher Glyer - Keynote - Spy vs. Spy: Ransomware Edition

We're All Addicted To Claude Code

We're All Addicted To Claude Code

BlueHat IL 2025 - Yarden Shafir - Look, Ma—No Privileges! How Windows Gives You Kernel Pointers...

BlueHat IL 2025 - Yarden Shafir - Look, Ma—No Privileges! How Windows Gives You Kernel Pointers...

Doda - Pamiętnik (Official Video)

Doda - Pamiętnik (Official Video)

BlueHat IL 2025 - Arad Cohen - Breaking TLS with LLMs

BlueHat IL 2025 - Arad Cohen - Breaking TLS with LLMs

Движение к цели короткими шагами

Движение к цели короткими шагами

The Trick To Instantly Make Your Game FUN

The Trick To Instantly Make Your Game FUN

How my new pedal is made might surprise you

How my new pedal is made might surprise you

Brett Adcock: Humanoids Run on Neural Net, Autonomous Manufacturing, and $50 Trillion Market #229

Brett Adcock: Humanoids Run on Neural Net, Autonomous Manufacturing, and $50 Trillion Market #229

© 2025 ycliper. Все права защищены.



  • Контакты
  • О нас
  • Политика конфиденциальности



Контакты для правообладателей: [email protected]