YoVDO

Abusing Over-The-Air Client Provisioning

Offered By: Hack In The Box Security Conference via YouTube

Tags

Hack In The Box Security Conference Courses Reverse Engineering Courses Software Security Courses Mobile Security Courses Firmware Analysis Courses

Course Description

Overview

Explore the security vulnerabilities in over-the-air client provisioning for major smartphone brands in this conference talk from the Hack In The Box Security Conference. Discover how attackers can exploit weaknesses in network settings installation processes to compromise user privacy and take control of network traffic. Learn about the attack flows, including live demonstrations, and understand the root causes stemming from outdated mobile client provisioning specifications. Gain insights into the potential risks users face when accepting seemingly legitimate network settings from unknown sources. Examine the ongoing efforts by affected vendors to address these security issues and discuss potential mitigations. Benefit from the expertise of security researchers Slava Makkaveev and Artyom Skrobov as they delve into the intricacies of mobile platform and firmware security.

Syllabus

#HITBGSEC COMMSEC: Abusing Over-The-Air Client Provisioning - Slava Makkaveev and Artyom Skrobov


Taught by

Hack In The Box Security Conference

Related Courses

Siglent SSA3032X Spectrum Analyzer Review and Experiments
Afrotechmods via YouTube
Owning the Smart Home with Logitech Harmony Hub
Security BSides San Francisco via YouTube
Malware Detection and Firmware Analysis Lab
Bill Buchanan OBE via YouTube
Live Breaking into Encrypted 3D Printer Firmware
Hackaday via YouTube
Debugging Electronics - You Can’t Handle the Ground Truth!
Hackaday via YouTube