Главная
Study mode:
on
1
Intro
2
PAST RESEARCH
3
IMPORTANT APPLICATIONS
4
DIVIDE AND CONQUER
5
GETTING THE FIRMWARE OUT
6
DATASHEET + MANUALS
7
PERIPHERALS OF INTEREST
8
FINDING THE FUN VECTORS
9
INTERNAL DATABASE
10
FORMAT STRING EXPLOITATION
11
PRIVILEGE ESCALATION
12
UNDERSTANDING THE CALL CHAIN
13
WHAT DATA CAN WE MESS WITH
14
MODIFYING CRITICAL DATA
15
MEDICAL INDUSTRY COMMON PITFALLS
Description:
Explore the process of remotely compromising the BBraun Infusomat pump, a widely used medical device in hospitals worldwide, in this 42-minute conference talk from Ekoparty 2021. Delve into firmware reverse engineering, vulnerability research, and exploitation demonstrations as speakers Douglas McKee and Philippe Laulheret investigate the potential for hackers to manipulate infusion rates and potentially overdose patients. Learn about past research, important applications, firmware extraction techniques, and the analysis of datasheets and manuals. Discover peripherals of interest, identify attack vectors, and understand the exploitation of format string vulnerabilities and privilege escalation methods. Gain insights into the internal database structure, critical data modification, and common pitfalls in the medical industry's approach to security.

Breaking the Security Barrier of a Major Infusion Pump - Douglas McKee & Philippe Laulheret - Ekoparty 2021

Ekoparty Security Conference
Add to list