Популярное

Музыка Кино и Анимация Автомобили Животные Спорт Путешествия Игры Юмор

Интересные видео

2025 Сериалы Трейлеры Новости Как сделать Видеоуроки Diy своими руками

Топ запросов

смотреть а4 schoolboy runaway турецкий сериал смотреть мультфильмы эдисон
dTub
Скачать

35C3 - Viva la Vita Vida

Автор: media.ccc.de

Загружено: 2018-12-29

Просмотров: 17910

Описание:

https://media.ccc.de/v/35c3-9364-viva...

Hacking the most secure handheld console

Since its release in 2012, the PlayStation Vita has remained one of the most secure consumer devices on the market. We will describe the defenses and mitigations that it got right as well as insights into how we finally defeated it. The talk will be broken into two segments: software and hardware. First, we will give some background on the proprietary security co-processor we deem F00D, how it works, and what we had to do to reverse an architecture with minimal public information. Next, we will talk about hardware attacks on a real world secure hardware and detail the setup process and the attacks we were able to carry out. This talk assumes no prior knowledge in hardware and a basic background in system software. Focus will be on the methods and techniques we've developed along the way.

How do you hack a device running a full featured, security hardened, and completely proprietary operating system executed on a custom designed SoC? Although the PlayStation Vita did not reach the market success of its contemporaries, it was a surprisingly solid device security-wise. Sony learned from the mistakes of PS3 and PSP and there were (mostly) no "FAIL" moments. It carried exploit mitigations that are standard today but groundbreaking for a "popular" device in 2012: SMAP, kernel ASLR, &gt 2 security domains, and more. Molecule was the first group to run unsigned code on the device as well as the first to hack kernel mode and TrustZone. However, to target the security co-processor (F00D), we need to bring out the big guns. Using a highly customized version of the popular ChipWhisperer hardware, we carried out hardware attacks on the device including fault injection (glitching) and side channel analysis. In a board with twelve layers, dozens of unknown ICs, and hundreds of passives, how do you even begin to attack it without any information? We will start with the basics: a whirlwind tour of the theory behind the attacks. Then we will move to the practical application: mapping out the power domains of a SoC, soldering tips for microscopic points, finding a good trigger signal, finding a glitch target, and searching the right parameters. Finally, if time permits, we will also talk a bit about how to extend our existing setup to perform side channel analysis with a few modifications.

It is unfortunate that the Vita was such a niche device, but we hope this talk will inspire more people to pick it up. The Vita is dead, long live the Vita!

Yifan Lu Davee

https://fahrplan.events.ccc.de/congre...

35C3 -  Viva la Vita Vida

Поделиться в:

Доступные форматы для скачивания:

Скачать видео mp4

  • Информация по загрузке:

Скачать аудио mp3

Похожие видео

39C3 - From Silicon to Darude Sand-storm: breaking famous synthesizer DSPs

39C3 - From Silicon to Darude Sand-storm: breaking famous synthesizer DSPs

39C3 - Hacking washing machines

39C3 - Hacking washing machines

35C3 -  The Ghost in the Machine

35C3 - The Ghost in the Machine

39C3 - AI Agent, AI Spy

39C3 - AI Agent, AI Spy

Фотофон 1985 года: давно потерянный ретротехнический шедевр восстановлен!

Фотофон 1985 года: давно потерянный ретротехнический шедевр восстановлен!

30C3 Console Hacking Wii U Fail0verflow

30C3 Console Hacking Wii U Fail0verflow

39C3 - Escaping Containment: A Security Analysis of FreeBSD Jails

39C3 - Escaping Containment: A Security Analysis of FreeBSD Jails

35C3 -  Modchips of the State

35C3 - Modchips of the State

Why The Cuts In The Capacitor Plates? Here's Why With Circuit Examples!

Why The Cuts In The Capacitor Plates? Here's Why With Circuit Examples!

Sting - Shape of My Heart || Sylwester z Dwójką 2025

Sting - Shape of My Heart || Sylwester z Dwójką 2025

I Made a Clock Only Using

I Made a Clock Only Using "2026"

34C3 -  Console Security - Switch

34C3 - Console Security - Switch

2025 год стал годом, когда искусственный интеллект переступил черту.

2025 год стал годом, когда искусственный интеллект переступил черту.

Sting - Every Breath You Take || Sylwester z Dwójką 2025

Sting - Every Breath You Take || Sylwester z Dwójką 2025

Ignoring All Lithium Battery Safety Warnings.. For Science!

Ignoring All Lithium Battery Safety Warnings.. For Science!

39C3 - How to render cloud FPGAs useless

39C3 - How to render cloud FPGAs useless

35C3 -  The year in post-quantum crypto

35C3 - The year in post-quantum crypto

27c3: Console Hacking 2010 (en)

27c3: Console Hacking 2010 (en)

Hard Starting Since New - Generac Standby Generator

Hard Starting Since New - Generac Standby Generator

Expanding in three dimensions

Expanding in three dimensions

© 2025 dtub. Все права защищены.



  • Контакты
  • О нас
  • Политика конфиденциальности



Контакты для правообладателей: [email protected]