37C3 - Finding Vulnerabilities in Internet-Connected Devices

Title:
37C3 - Finding Vulnerabilities in Internet-Connected Devices
Description:

https://media.ccc.de/v/37c3-11919-finding_vulnerabilities_in_internet-connected_devices

A Beginner’s Guide

This introductory session will outline the process of hacking internet-connected devices, with the help of a real world example: Poly telephones and conference speaker systems. We will explain vulnerabilities we identified in them and how they can be leveraged to transform the devices into wiretaps.

In this introductory session we will journey into the field of internet-connected device security. Our talk aims to empower beginners by simplifying the process of hacking such devices.

We'll discuss vulnerabilities we uncovered in Poly telephones and conference speaker systems and describe how we effectively transformed a seemingly innocuous conference speaker into a fully functional wiretap. We'll begin with straightforward findings accessible to beginners and progress to more technical discoveries, so that people with no experience in the field can follow along, too.

By the end of the talk, the attendees will have a foundational understanding of how they can approach hacking such a device and will have learned how the impact of vulnerabilities can be shown and increased by chaining them.

All the vulnerabilities we discovered during our research have been responsibly disclosed to the vendor and will be published in December 2023.

Pascal Zenker
Christoph Wolff

https://events.ccc.de/congress/2023/hub/event/finding_vulnerabilities_in_internet-connected_devices/

#37c3 #Security

more » « less
Video Language:
English
Duration:
47:21
http://www.youtube.com/watch?v=K9mm3YioagI
Format: Youtube
Primary
Original
Added   by C3Subtitles
Format: Youtube
Primary
Original
http://www.youtube.com/watch?v=eDNzZG8p9xM
Format: Youtube
Added   by C3Subtitles
Format: Youtube
http://www.youtube.com/watch?v=PBKrEV0913g
Format: Youtube
Added   by C3Subtitles
Format: Youtube
This video is part of Amara Public.

Subtitles download

Incomplete subtitles (1)