YoVDO

Ground Truth - 18 Vendors, 6000 Firmware Images, 2.7 Million Binaries, and a Flaw in the Linux-MIPS Stack

Offered By: 0xdade via YouTube

Tags

ShmooCon Courses Cybersecurity Courses Reverse Engineering Courses Firmware Analysis Courses Vulnerability Research Courses

Course Description

Overview

Explore a comprehensive analysis of embedded devices, IoT, and home routers in this 53-minute conference talk from ShmooCon 2019. Dive into the findings from an extensive study of over 6000 firmware images from 18 vendors, encompassing 2.7 million binaries. Discover alarming trends in software hardening practices, including regression of features over product lifetimes and inconsistent application of basic protections across major vendors. Learn about the differences in hardening between newer and older architectures, and the surprising decrease in ASLR implementation from 2012 to 2018. Investigate a critical flaw in Linux/MIPS stack support, resulting in a universal DEP bypass and subsequent ASLR bypass. Gain insights from industry experts Parker Thompson, Tim Carstens, and Mudge as they discuss the importance of large empirical studies in assessing overall security trends and their implications for the future of embedded device security.

Syllabus

Ground Truth: [...] and a flaw in the Linux/MIPS stack - Parker Thompson, Mudge, & Tim Carstens


Taught by

0xdade

Related Courses

Dal Reverse engineering alla stampa 3D
University of Naples Federico II via Federica
Rapid Manufacturing
Indian Institute of Technology Kanpur via Swayam
Generative Design for Industrial Applications
Autodesk via Coursera
Fundamentos de Ciberseguridad: un enfoque práctico
Inter-American Development Bank via edX
Functional And Conceptual Design
Indian Institute of Technology Madras via Swayam