Friday, November 14, 2008

Speaking at 25C3

BSLCracker 3.0

At the 25th Chaos Communications Congress in Berlin this December, I'll be presenting some new research in the security of the MSP430's serial bootstrap loader (BSL) as well as a nice little lecture/workshop combo on reverse-engineering the TI EZ430 development tool.

I intend to travel through France and England, returning in late January for S4, Miami. Please email me if you'd like to meet.

Cracking the MSP430 BSL
Day 1 (2008-12-27), 20h30 (8:30 pm) in Saal 3.

The Texas Instruments MSP430 low-power microcontroller is used in many medical, industrial, and consumer devices. When its JTAG fuse is blown, the device's firmware is kept private only a serial bootstrap loader (BSL), certain revisions of which are vulnerable to a side-channel timing analysis attack. This talk continues that from Black Hat USA by describing the speaker's adventures in creating a hardware device for exploiting this vulnerability.

While the previous part focused on the discovery of the timing vulnerability and its origin, this lecture will focus on the exploitation. Topics include a brief review of the vulnerability itself, PCB design and fabrication, the malicious stretching of timing in a bit-banged serial port, observation of timing differences on the order of a microsecond, and the hell of debugging such a device.

Repurposing the TI EZ430U
Lecture: Day 3 (2008-12-29), 12h45 (pm) in Saal 3
Workshop: Not yet scheduled.

USB devices are sometimes composed of little more than a microcontroller and a USB device controller. This lecture describes how to reprogram one such device, greatly expanding its potential.

At only twenty dollars, the Texas Instruments EZ430U is a bargain of an in-circuit debugger for the MSP430 microcontroller. The board itself is composed of little more than an MSP430 and a USB to Serial controller. The board's JTAG fuse is unblown, and full schematics are included in public documentation. This lecture will discuss the use of the EZ430U, not as a debugging tool, but as a development platform in and of itself. Topics will include the writing of replacement firmware, analysis of the default firmware, reprogramming the USB to Serial controller, and potential target applications.

Travis Goodspeed
<travis at>


Taylor Bara said...

Do you want someone to do your homework for you? Get it here!

Jim Rhodes said...

I should learn more about this event. I might meet you there next time. Right?

johnybrown said...

Canon mx492 driver download
Canon tr8520 drivers download
Canon mg3022 driver download
Online Animals Encyclopedia| Animal Facts and Pictures
10 Amazing facts about animals
Are mermaids real?| Is mermaid really exist or not?
Top Most Extinct Animals
Top Most Endangered Animals
10 Amazing facts about animals Video
Pogo games support phone Number +1-888-589-0410
888-589-0410 EA Games Phone Number
888-589-0410 Browser Support
888-589-0410 Printer Helpline
888-589-0410 Tech Services

shopify said...

Get yourself ready for the biggest sale of the year as we provide you a big discount in the Women's Slim Fit Jackets category for the limited time offer so hurry uprush to our online store and get your favorite outfit before it’s too late.

Godrej Pest Control said...

For the best pest control services in Gurgaon and Delhi, you can contact Godrej Pest Control Gurgaon and safeguard your home and office from the attack of various pests. We as a whole expect that your home ought to be sound and safe for your children and family, so we need to do some significant things to keep it safe and clean.

Unknown said...

There are lots of health benefits of ayurvedic massage. Ayurvedic massage helps in reducing stress, blood pressure, softening skin, weight loss, etc.

Godrej Pest Control said...

Omg!! What a fantastic post. The points you have mentioned are awesome. Highly Appreciated.
Last night I had a dream that my house is under a termite attack and i called godrej as they are offering termite control services in gurgaon.

Ramon John said...

The website is looking bit flashy and it catches the visitors eyes. Design is pretty simple and a good user friendly interface.UPHOLSTERY CLEANING Pageland

Godrej Pest Control said...

With its wide array of treatments and team of professional technicians, Godrej Pest Control is the best pest control company in Gurgaon. If you are looking for the best pest control services in Gurgaon for your residential or commercial property then Godrej is the best. Call now for FREE inspection.

vipul said...

Are you looking for best Dubai Tour Package? Well, Epic Trips is one the best tour and travel companies in Delhi and offer best international Dubai tour package at most affordable prices. Contact now

Creatix9 said...

When we say logo design services, we mean whatever services you offer: copywriting, UX/UI design, social media marketing- you name it, and this guide will help you price it!

check more services

digital marketing services
search engine optimization service provider