NexMon

156 posts

NexMon

NexMon

@nexmon_dev

NexMon is a firmware patching framework for the BCM4339 WiFi firmware of Nexus 5 smartphones.

Darmstadt, Germany Joined Ağustos 2016
74 Following754 Followers
LiveOverflow 🔴
LiveOverflow 🔴@LiveOverflow·
Do you know any (large) community-driven reverse engineering projects?
English
44
33
313
0
NexMon retweeted
AirGuard
AirGuard@AirGuardAndroid·
We published a pre-print paper about AirGuard. How does the app work? How does it perform against the iOS tracking detection and what can we learn from the anonymous data shared by the user? arxiv.org/abs/2202.11813
English
0
10
23
0
NexMon retweeted
Jiska
Jiska@naehrdine·
The remaining @acm_wisec tutorials are online: open-sourcing research projects by Milan (@seemoolab), firmware reverse engineering with Ghidra by @ghidraninja, firmware rehosting with avatar2 by @nSinusR and details on a 5G testbed by @gvinevere (@5g_lab & @ComNets_TUD).
Jiska@naehrdine

A new tutorial format at @acm_wisec features practical tools for wireless research. 👩‍💻📱📶 SDR intro by @bastibl, baseband fuzzing by @domenuk, iOS in-process fuzzing by @ttdennis & Bluetooth firmware mods by me. Ping me if you want to join as speaker. sites.nyuad.nyu.edu/wisec21/tutori…

English
0
13
37
0
NexMon retweeted
NexMon
NexMon@nexmon_dev·
Very nice that you finally found the shared memory regions between Wi-Fi and Bluetooth chip. As nexmon just patches the Wi-Fi firmware before loading it, we could try to load a patched Wi-Fi firmware using the Bluetooth chip and then reset the Wi-Fi chip to start it.
Jiska@naehrdine

Code execution on a Broadcom Bluetooth chip leads to code execution within Wi-Fi. This has a couple of interesting implications for utilizing Wi-Fi without @nexmon_dev 📱, Wi-Fi debugging 🐛, and exploitation 💥 More details on CVE-2020-10367 (unpatched): naehrdine.blogspot.com/2021/04/blueto…

English
0
0
6
0
NexMon
NexMon@nexmon_dev·
@jiska___ Oh maybe Samsung has different chips in the european and the international variants.
English
1
0
1
0
NexMon
NexMon@nexmon_dev·
@jiska___ Very nice :-) Would you mind also disabling SELinux O:-)
English
2
0
2
0
NexMon
NexMon@nexmon_dev·
Happy Easter! Today I published our monitor mode and frame injection patches for the BCM4375 Wi-Fi chips installed in Samsung Galaxy S10 and S20 smartphones. I am still looking for access to a Galaxy S21 to analyze its firmware. nexmon.org #nexmon
English
1
7
27
0
NexMon
NexMon@nexmon_dev·
@enovella_ S10 patch is ready just need to find some time to publish it.
English
0
0
1
0
NexMon
NexMon@nexmon_dev·
Who has a Galaxy S21 and could give me access to the BCM4389 WiFi 6e firmware files? And maybe remotely to the device to dump the chip's ROM?
English
4
3
9
0
NexMon
NexMon@nexmon_dev·
@jiska___ Jiska in der Wirtschaft? Schwer vorstellbar ...
Deutsch
1
0
1
0
NexMon retweeted
Jiska
Jiska@naehrdine·
It's online! Bluetooth RCE == Wi-Fi RCE. Say hello to Spectra, the concept of breaking wireless chip separation as they share the same spectrum. #BlackHat #spectra-breaking-separation-between-wireless-chips-20005" target="_blank" rel="nofollow noopener">blackhat.com/us-20/briefing…
Jiska tweet media
English
5
139
349
0
NexMon
NexMon@nexmon_dev·
@naehrdine Nice work does it also work for ARM or also for the D11 ucode (b43 assembly)?
English
1
0
1
0
NexMon retweeted
Jiska
Jiska@naehrdine·
Since people were asking how it works internally, here is Jan's final presentation, which covers the most important aspects why ARM Thumb2 disassembly was problematic and how the binary-only approach works. (9/8) github.com/seemoo-lab/pol…
English
1
2
6
0
Jiska
Jiska@naehrdine·
We just released Polypyus, a binary-only diffing tool programmed by @freebejan that runs independent from Ghidra and IDA and integrates into the workflow of other diffing tools. (1/n) github.com/seemoo-lab/pol…
Jiska tweet media
English
4
90
241
0
Jiska
Jiska@naehrdine·
Jan just released Frankenstein, the Broadcom/Cypress Bluetooth firmware emulator that enables fuzzing and further kinds of debugging. It works within a fully-functional Linux BlueZ stack and features virtual modem input. (1/2) github.com/seemoo-lab/fra…
English
3
112
246
0