DEF CON 32 - SBOMs the Hard Way  Hacking Bob the Minion - Larry Pesce

DEF CON 32 - SBOMs the Hard Way Hacking Bob the Minion - Larry Pesce

Source: YouTube · DEFCONConference · published Oct 16, 2024 · 20:55

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The video documents a security researcher's hardware hacking adventure to extract firmware from a Bob the minion-themed router and create a Software Bill of Materials (SBOM) 0:56.

Key Takeaways:
• SBOMs provide critical software component inventories that help identify vulnerabilities and are becoming mandatory through regulations like the EU Cyber Resiliency Act and US executive orders 4:00
• The D-Link AX1800 Bob router contains significantly more storage (1Gbit flash chip) than advertised (128MB), presenting an immediate discrepancy in manufacturer claims 16:53
• No firmware was available for download from the manufacturer, forcing physical extraction methods including removing the flash chip and using a Raspberry Pi for dumping 11:00
• Analysis revealed security vulnerabilities including default credentials (username: Bob, password: Bob), potential command injection, and scripts connecting to Chinese IPs 19:56

This hardware hacking demonstration highlights the importance of firmware analysis and SBOM creation for identifying hidden security risks in consumer IoT devices.

Sources:

  • 0:56 Introduction to SBOMs and the hacking project
  • 4:00 Regulatory requirements for SBOMs
  • 11:00 Firmware unavailability and extraction challenges
  • 16:53 Hardware analysis revealing actual vs. advertised storage
  • 19:56 Security vulnerabilities discovered in firmware

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

all right let's get started we're running a little late so uh I'm going to try not to talk too fast but I got to make up some time here so uh welcome to uh es bombs the Hardway uh for my adventures in hacking Bob the minion um I am the product security research and Analysis director and services team lead at a fun company called finite State uh and uh we do all sorts of fun stuff with s bombs and a whole bunch of other stuff but I'm not here to talk to you about our product or any of that I'm talking about my adventure with Bob all right so who am I um I am a reformed penetration tester and reformed crossed out uh I left doing penetration testing uh to go do some thought leadership and some other uh Hardware hacking and iot a bunch of stuff and three months into the job my boss came to me …