Ferdinand Jarisch
Ferdinand is a security researcher and penetration tester working at Fraunhofer Institute AISEC in Munich, Germany. His main focus lies with automotive security, but he takes a detour every now and then to explore other targets such as NFC and RF communication, exploit development or cracking crypto.
Session
It remains a booming business to sell exploitation of 0-days to governmental law-enforcement agencies, mainly to catch bad guys. Sometimes, however, these capabilities are not-so-lawfully misused against other actors, such as activists.
Building on a report of Amnesty International's Security Lab, we investigate one such misuse that utilized several 0-days in the USB-stack of an Android phone's Linux kernel, connect the dots between device logs, CVE entries and Kernel source code, and create a working and portable exploit for affected Linux Kernels ourselves.