Dark Mentor LLC
Dark Mentor LLC
Home
Training
Publications
Blog
Bluetooth Security Timeline
PC/Server Firmware Security Timeline
HCI
Bluetooth reconnaissance with Blue2thprinting
1 day class covering how to use the
Blue2thprinting
software to perform reconnaissance on devices, and understand vulnerabilities they may have.
Xeno Kovah
The ESP32 "backdoor" that wasn't
This post refutes the claim that researchers found a “backdoor” in ESP32 Bluetooth chips. What the researchers highlight (vendor-specific HCI commands to read & write Controller memory) is a common design pattern found in other Bluetooth chips from other vendors as well, such as Broadcom, Cypress, and Texas Instruments. Vendor-specific commands in Bluetooth effectively constitute a “private API”, and a company’s choice to not publicly document their private API does not constitute a “backdoor”.
Xeno Kovah
Bluetooth Low Energy - Full Stack Attack
4 day class covering the full Bluetooth Low Energy (BLE) protocol stack from the bottom (PHY) up to the top (GATT). The core of the class is built around playing with a game application on an Android phone, talking via Bluetooth to an IoT-type piece of hardware, and analyzing the communication between them. The 4th day is focused on assessing a cutomized Ultra-Vulnerable Peripheral firmware, running on Zephyr RTOS, which has had vulnerabilities introduced into it which are representative of vulnerabilities found in the past across many other platforms.
Veronica Kovah
,
Xeno Kovah
Cite
×