Getting started in embedded device research
Have you ever found yourself wondering if the IoT device you're relying on has any additional "features"? Have you ever bought something only to discover it doesn't quite do what you want it to (or is buggy AF)? This talk will be aimed at those interested in reverse engineering (and potentially modifying) embedded device firmware. With no agents in sight, Andy will offer some "tips 'n' tricks" into getting started in the fascinating world of embedded device hacking.
In this presentation, Andy will look at how security researchers approach embedded devices, from obtaining firmware and recovering the kernel and filesystem, to attempting to gain privileged access. Along the way, Andy will illustrate some practical examples of where curiosity for how things work has helped himself and others solve problems, from unshackling devices from the grip of ISPs to repurposing end-of-life equipment that would otherwise be destined for the scrap heap.
Andy is currently a Vulnerability Researcher with CoreTech Security based in Cheltenham. With over 20 years of experience working in various hands-on roles, including IT manager, penetration tester, software engineer and vulnerability researcher, Andy has a fair bit of experience fighting working with technology. He is a firm believer in paying it forward, and would like to share that knowledge with anyone who is interested in learning.