A Logo

Feel free to include my content in your page via my
RSS feed

Help Irongeek.com pay for
bandwidth and research equipment:

Subscribestar or Patreon

Search Irongeek.com:

Affiliates:
Irongeek Button
Social-engineer-training Button

Help Irongeek.com pay for bandwidth and research equipment:

paypalpixle


On the Nose: Bypassing Huawei's Fingerprint authentication by exploiting the TrustZone - Nick Stephens Derbycon 2018 (Hacking Illustrated Series InfoSec Tutorial Videos)

On the Nose: Bypassing Huawei's Fingerprint authentication by exploiting the TrustZone
Nick Stephens
Derbycon 2018

After hundreds of vulnerabilities disclosed and countless roots of smartphones the landscape of privilege separation is changing on your mobile device. No longer is kernel compromise the end of the road for attackers attempting to find all the dark secrets stored on your smartphone. Now we have TrustZone, a technology introduced by ARM which provides the "Secure World". This "Secure World" is separated from the Android kernel which exists in the "Normal World". Many of the most sensitive operations on your phone are now managed by the TrustZone. These include DRM, fingerprint authentication, and secure file storage, leaving a malicious kernel unable to meddle with them. This talk will demonstrate that despite the enhanced security architecture, a persistent attacker can still prevail. By chaining a number of memory corruption vulnerabilities the author will show how a lowly untrusted app on a Huawei device can compromise the kernel, followed by a trusted app, and eventually the TrustZone kernel itself. Using this access the author will show how the fingerprint trusted module can be patched to accept any fingerprint or even any nose. A demo with nose unlocking will be included.

Nick is a member of the Shellphish CTF team and employed by Raytheon CSI as a vulnerability researcher. Nick has published papers on automated bug finding and exploitation as well Android security, and competed in the DARPA Cyber Grand Challenge with team Shellphish.

N/A

Back to Derbycon 2018 video list

15 most recent posts on Irongeek.com:


If you would like to republish one of the articles from this site on your webpage or print journal please contact IronGeek.

Copyright 2020, IronGeek
Louisville / Kentuckiana Information Security Enthusiast