"Unlocking hidden powers in Xtensa based Qualcomm Wifi chips" Daniel Wegemer

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • number6
    404 Image not found
    • Apr 2019
    • 2172

    #1

    "Unlocking hidden powers in Xtensa based Qualcomm Wifi chips" Daniel Wegemer

    Unlocking hidden powers in Xtensa based Qualcomm Wifi chips

    Daniel Wegemer, Hacker, He/Him

    Demo, Tool

    45

    Wifi chips contain general purpose processors. Even though these are powerful processors, their firmware is closed source and does not allow modifications. This talk explores how the firmware of modern Xtensa based Qualcomm Wifi chips can be modified to allow extending its indented functionality. Such modifications can even be for example leveraged by security researchers to find vulnerabilities in an otherwise closed source Wifi code. During the talk we will also dive into the architecture of Qualcomms Wifi chips as well as the structure of the firmware used withing these chips. We will release a modified version of the Nexmon framework to enable patching of Xtensa based firmware and show all the steps involved to create such patches.





    Security Researcher interested in enabling new features in closed source firmware. Areas of interest are: Wifi, IoT and Automotive.


    Co-author of http://nexmon.org/

    - http://problemkaputt.de/gbatek-dsi-a...r-commands.htm
    - https://nstarke.github.io/firmware/w...re-images.html
    - https://sachin0x18.github.io/posts/d...ng-xtensa-isa/
    - https://nexmon.org
Working...