YoVDO

Emulating Samsung's Baseband for Security Testing

Offered By: Black Hat via YouTube

Tags

Black Hat Courses Reverse Engineering Courses Vulnerability Research Courses

Course Description

Overview

Explore the intricacies of baseband processor security testing in this Black Hat conference talk. Dive into the development of an emulation environment for Samsung's "Shannon" baseband, combining avatar2 and PANDA frameworks to create a flexible platform for vulnerability research. Learn about the challenges of exploring baseband attack surfaces, including over-the-air testing limitations and debugging difficulties. Discover how the speakers address these issues through their custom emulation environment, ShannonEE. Gain insights into reverse engineering techniques, boot modes, memory structures, and fuzzing methodologies specific to baseband processors. Witness practical demonstrations, including a rediscovery of the "Call of Death" vulnerability. Understand the importance of baseband security in modern mobile phones and cellular networks, covering protocols from 2G to 5G. Conclude with a discussion on future work and potential applications of this emulation approach in enhancing mobile device security.

Syllabus

Introduction
About me
Agenda
What is a Baseband
Why Basebands
Samsung Baseband
Baseband Emulator
How did we get here
Crashes
Root
Debugging
Scaling
Reverse Engineering
Boot modes
Samsung kernel
Memory structure
Block diagram
Next step
Choosing a framework
Boot UART
UART debugging
Snapshots
The Problem
PiPanda
PAL
The Banner
Fuzzing
Triforce AFL
Target AFL Tasks
GSM Session Management
Fuzz Single
Demo
Rediscovery
Call of Death
Experimental Setup
Calling Demo
Logcat
Wrap Up
Future Work
Release Schedule
Thank You
Questions


Taught by

Black Hat

Related Courses

Dal Reverse engineering alla stampa 3D
University of Naples Federico II via Federica
Rapid Manufacturing
Indian Institute of Technology Kanpur via Swayam
Generative Design for Industrial Applications
Autodesk via Coursera
Fundamentos de Ciberseguridad: un enfoque práctico
Inter-American Development Bank via edX
Functional And Conceptual Design
Indian Institute of Technology Madras via Swayam