Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Alarm.DISARM - Remotely Exploiting & Disarming Popular Physical Security System from Public Internet

Black Hat via YouTube

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This talk demonstrates two remote code execution vulnerabilities in a Paradox physical security system, tracing the process from firmware and protocol analysis to an ROP chain and shellcode. It shows how the vulnerabilities can be used to remotely access and disarm the alarm system.

Syllabus

Intro
Lab equipment
Step 1 - Firmware updates
Reverse Engineering
Network Protocol
Packet Header
Looking for vulnerabilities - IP150 Login Page
CVE-2020-25189
Solution - ROP Chain
Shellcode [1] - memory dumper
Shellcode [2] - Switch Ports

Taught by

Black Hat

Reviews

Start your review of Alarm.DISARM - Remotely Exploiting & Disarming Popular Physical Security System from Public Internet

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.