Video summary
The Embedded Systems Village at DEF CON 34 focuses on the critical intersection between hardware and software, aiming to teach attendees how to navigate the entire vulnerability research process for various devices. The event covers a wide range of embedded systems, from everyday items like dog shock collers and routers to specialized military-grade equipment such as thermal cameras and IP surveillance units. A significant portion of the experience is dedicated to Capture The Flag (CTF) challenges where participants can physically interact with rare hardware, including cameras sourced directly from China that were originally being deployed before being intercepted for the event. This hands-on approach allows security researchers to analyze real-world devices that are often difficult to obtain, fostering a deeper understanding of the unique challenges and opportunities within the embedded systems domain.
For those new to the field or lacking prior experience with terminals and Linux, the village offers structured 101 labs designed to guide users through firmware analysis step-by-step without requiring deep command-line knowledge. These self-paced sessions teach essential skills such as extracting firmware from devices, analyzing its contents, and identifying communication protocols like UART and JTAG. Additionally, workshops are available on specific topics including Bluetooth vulnerabilities and glitching attacks, often facilitated by partners like Hextree. The glitching demonstrations illustrate how electromagnetic pulses can be used to flip bits in memory or force hardware resets, potentially bypassing authentication mechanisms or opening locked devices like hotel safes, highlighting the unpredictable yet exploitable nature of hardware vulnerabilities.
The event emphasizes a community-driven learning environment where individuals can start with zero knowledge and leave with practical skills, eventually returning to participate in advanced CTF competitions. To encourage responsible research, the organizers have placed a $500 bounty on legally obtained Flock cameras, inviting attendees to bring these specific devices for immediate analysis by the team. This initiative underscores the event's commitment to providing access to rare hardware while maintaining strict legal standards regarding product acquisition. Ultimately, the Embedded Systems Village serves as a comprehensive resource for aspiring security professionals, offering a pathway from basic education to advanced research through collaboration with various security firms and open community support.
Read the full video transcript
Yo, Defcon, here we are at Embedded
Systems. Okay, there's a lot going on
here. I've got Darren here, aka Baby
Bell. Uh, talk to me, man. What do we
got? I I see I see a lot of people over
here on a CTF. I see people digging
around on actual equipment. Like, give
me the rundown, man.
>> Yeah, for sure. So at Embedded Systems
Village, what we really try to um really
try to hone in on is the intersection
between hardware and software. So you
get a lot of villages where you focus on
the hardware component um and and uh and
the software component, but we're trying
to do the entire process in which that
when you're doing vulnerability research
and vulnerability assessments or you're
just doing your own research on these
devices is like, okay, sweet. How do I
pull that firmware off of the device?
How do I analyze? and uh gain a buzz on
uh one of the challenges here. Actually,
>> what do we have? Just let's just go for
the audio we got going. You know what?
Looks like what we have here is a a a
shot caller.
>> Yeah. So, this is one of our CTF
challenges. So, that way you know what
that segus us into uh one of the things
that we do here. Um as part of the CTF
that we have here, um it is the theme
that we have here. You see, we see a
couple of our big cameras that we have
here. So, we have a camera here uh from
a military camera from China. We have a
military camera. Oh.
>> Oh my god. Are you okay?
>> Yeah, I'm good.
>> No, it's good. This is all part of the
CTF. We have a naval uh flur camera uh
from the military that uh the US
military still uses. We have an older uh
military camera which is has thermal and
all that. You can actually even see the
thermal over there. We'll take a little
bit of a wave over there that you can
kind of play with. And so these are some
of the devices that we have here.
Embedded systems is a very large
umbrella. We cover everything from dog
shock collars to military cameras to
routers um to IP cameras. Um so it's a
very large um sort of domain. We even
have Bluetooth um challenges as well and
workshops that we have around here.
Speaking of workshops, if you are new to
embedded systems um and you've never
touched any embedded systems device
before, you've never touched a terminal,
you don't even know what Linux is,
that's totally fine. We've got things
for you here as um we do have the 101
labs going on um over in the corner over
there. And that's where you can see the
firmware analysis. It's like, okay, I
have the firmware off of the device,
which is basically the software that the
device uses to run its hardware
components. And so it's like, okay, I
have this now, now what? What do I do?
Where's the next step? So, we teach you
step by step. It's all like uh uh
selfpace. So, it's all step by step. You
don't need to know any of the commands.
It's all copy and paste. Uh each lab
takes about 10 minutes. But then we also
have another lab for that hardware
component. It's like okay, how do we get
to that firmware and be able to analyze
that? And so we we are able to take a
look at that and it's like okay, how do
we find UART and do serial? And we
explain what UART is and how important
it is to um looking and doing research
on embedded systems. And then uh we do
have a glitching challenge or a
glitching workshop being put on by our
friends at hextree also here. Um
amazing. They have amazing content. If
you want to learn more outside of
Defcon, highly suggest taking a look at
their content at hextree.io. They are
fantastic. We also have a couple other
friends that help make this place uh
possible. And so we have a BLE workshop
over there as well as Kujo with a matter
um workshop. And so that kind of does a
little bit of everything. So, we do have
a couple other like cool little things
that we do um here at ESV. Let's take a
look.
>> Let's take a look. So, we uh we did get
to sell this badge. We've been selling
this badge for a little bit. And so,
this is for, as I said, with hextree.io,
they do a glitching lab over there. This
is a cool way of of doing glitching
attacks. And so, this is a mini EMP that
goes off of the end. So, you got a
little electromatic pulse that goes
right there. And so if we have a little
bit of a demo over here where we have a
little bit of a target um in which that
what we're trying to do with a glitching
attack is we're trying to flip a bit
from zero to one. Now you might do this
for any for authentication purposes and
do it in proper timing or you might try
to do a hard reset on a device like
this. Might take me a couple tries to
get the aim right like that. And so then
we get into a reboot process. And so
we've done this on a hotel safe before.
And so what you what might happen is
that it might default to open when it
does a hard factory boot. So in that
instance, the safe might just swing
right open if you do a hard glitch onto
it. So that's why it that attack is
viable um in the hardware access point.
Sometimes you don't know um when you're
doing a glitching attack what the
behavior is going to be that comes out
of it. Right. So, that's kind of the fun
part about glitching, but you can also
be very accurate with the timing. That
gets a little bit more uh intense
because you're really trying to flip
that one bit, right? Um especially if
you're doing like an authentication
process and then you're trying to flip
that bit from zero to one and then say,
"Yeah, I authenticated." And then
continuing on in the boot sequence. Um
so yeah, so that's a little bit in terms
of that. We also um we have
oscilloscopes uh here that can check out
UART. Um, and again, we can we have labs
to teach you the importance of UART and
J-Tech and all those other different
types of uh protocols.
>> Also, I wanted to say too, a lot of this
equipment here, uh, this is pretty rare
stuff.
>> So, these aren't things that your people
are usually able to get their hands on
or to take a crack at, right?
>> Yeah. So, a lot of these a lot of these
devices um that is a great point in
terms of our theme for the CTF this year
is that uh it is hard to find things
hard to find. And so, a lot of these
devices are come straight from China.
And so, there we have like the Chinese
military camera. We have a traffic
camera. We have a we have a a camera
straight from China that fun story was
actually just being installed and then
um was taken right from there and
basically was just passed over and then
shipped over to us. So Lei was like
right from
>> right from about to be deployed and and
and uh sent over and now is in the CTF.
>> It's current like it's current, right?
Just like I mean we were talking about
flot cameras. Obviously that's something
a lot of people are talking about
>> these days.
>> So I'm sure you're going to be getting
your hands on some of those soon if you
Yeah. Yeah.
>> So we're we're definitely working on
that. We're trying to for future events.
Um we we almost got it for this event.
Um we couldn't quite make it uh for this
weekend course.
>> Uh but uh that is something that we are
definitely working on and uh for the
future.
>> I don't even really know what you can
add like you have like everything here.
>> ACTF MITER uh Kujo huge shout outs to
them. from Loudmouse Security. Um, huge
shout outs for bringing content because
embedded systems is a huge topic, but we
want to get that information to people
and we want to teach people how to get
started in embedded systems and it takes
a village to make a village and uh so
we're if anybody's wanting to help in
embedded systems, we're glad to have
you. Make sure to reach out to us. Would
be fantastic to have you guys. um just
reach out to us on like LinkedIn or like
uh any of our social media platforms and
we would be glad to work with you guys
and communicate with you.
>> I think what's really cool is you can
come in here not knowing anything about
any of this and you can walk out um with
some with some skills under your belt
>> and uh getting some inside looks.
>> We've done this village for several
years now and we've had people where
they knew nothing about embedded
systems. They came in, they did the labs
um and then they went home. Next year
they came back and they participated in
the CTF and they did quite well and I
think even uh one or two might have uh
finished on the podium. So it's like it
is a process in which that is a learning
process something that you can get
started on here go home learn more again
with resources like hexre.io and then
just even just getting your hands
>> like go to a thrift store and just get a
router and then do some research onto
that you know and then be able to do
your own uh research onto that and then
come back and then take part in the
CTFs.
>> Awesome man. Yo, Darren, thanks for
showing me around. Is there anything
else you want to um you want to shout
out? Any other projects or anything? Or
should we just be checking you out?
>> One thing you do want to tell people
about is the bounty that we have on the
flock cameras.
>> Oh, yeah.
>> We have a $500 bounty on flock cameras
as long as they're legally obtained. We
cannot take any illegally product or
illegally obtained products, right?
>> Yeah, that is correct.
>> So, it has to be legally obtained like a
deprecated one or something.
>> Okay.
>> We just got an urgent message here,
Darren. Do you want to just deliver that
cuz I don't know if we got you on the
mic. So, we just got an urgent message
here, people. This is serious.
>> This is serious. We got a $500 bounty on
if you can get a flock camera. And if
you can, even if you can bring it here
to us for tomorrow and we can get some
people on on to hacking on that thing.
If you bring it in, $500 bounty here at
Embedded Systems Village. If you have a
flock camera, we would be glad to have
it.
>> We want the flock camera here, man.
>> Everybody wants their hands on it.
Everybody wants their hands on it.
>> Let them play. Let them play.