{
  "url": "https://pretalx.c3voc.de/camp2023/talk/TQXEN7/",
  "id": 57330,
  "guid": "336838bc-dc14-5985-bb40-3ee424a68537",
  "date": "2023-08-17T10:30:00+02:00",
  "start": "10:30",
  "logo": null,
  "duration": "00:45",
  "room": "Milliways",
  "slug": "camp2023-57330-analyzing_cellular_basebands_with_firmwire",
  "title": "\ud83d\udcf6 Analyzing Cellular Basebands with FirmWire \ud83d\udd0e",
  "subtitle": "",
  "track": "Milliways",
  "type": "Talk",
  "language": "en",
  "abstract": "Last year, we released FirmWire to the public, an open-source baseband analysis platform.\r\nBut what even is a baseband and why do we want to analyze it? Hint: It\u2019s a critical part of your phone and a first point of entry for attacks.\r\n\r\nThis talk will answer your questions and provide a hands-on introduction to our framework.",
  "description": "This talk will discuss cellular basebands and FirmWire, our open-source platform for baseband firmware. The platform allows researchers to emulate, dynamically debug, introspect, and interact with complex baseband firmware, providing insights about its inner workings in real-time.\r\n\r\nFirmWire\u2019s integrated ModKit creates and injects custom tasks into the emulated baseband.\r\nWe leverage the ModKit for full-system fuzzing via AFL++ by creating custom fuzzing tasks interacting with the host, using special hypercalls.\r\nWith this setup, we uncovered several pre-authentication vulnerabilities in the LTE and GSM stacks of Samsung\u2019s Shannon and MediaTek\u2019s MTK baseband implementations, affecting billions of devices.\r\n\r\nFirmWire is the outcome of a more than two-year-long international research collaboration between the University of Florida, Vrije Universiteit Amsterdam, TU Berlin, and Ruhr-University Bochum.",
  "recording_license": "",
  "do_not_record": false,
  "persons": [
    {
      "guid": "d84dd205-d8be-593f-8ce8-5bd4ca179c2d",
      "id": 4314,
      "code": "P9LHMV",
      "public_name": "nsr",
      "avatar": null,
      "biography": "nsr is interested in all sorts of low-level firmware, tinkering, and capture the flag competitions. He developed and maintains avatar2, a framework for analyzing embedded systems firmware. Among others, he used the framework within the FirmWire project for emulating Samsung\u2019s Shannon and MediaTek\u2019s MTK baseband firmware, yielding to the discovery of several critical vulnerabilities.\r\n\r\nIn his day job, nsr is a assistant professor at the University of Birmingham and his research interests cover the (in-)security of embedded systems, as well as binary and microarchitectural exploitation.",
      "answers": []
    },
    {
      "guid": "21a04531-3d7c-5dd9-890f-cacf8d2dc4d1",
      "id": 4313,
      "code": "KL9AUC",
      "public_name": "domenukk",
      "avatar": "https://pretalx.c3voc.de/media/avatars/L6dqH-d3_400x400_tI87tKB.jpg",
      "biography": "Dominik Maier holds a PhD from TU Berlin where he focussed on fuzzing. He is part of the AFLplusplus project, and currently works on connectivity security for the largest smartphone OS.",
      "answers": []
    }
  ],
  "links": [],
  "attachments": [],
  "room_id": "345ca97a-7eb6-459b-bc53-bc2a8bd5c3f1",
  "origin": "pretalx.c3voc.de"
}