Hands-on IoT firmware extraction and forensics

No ratings

Presented at HITCON 2025 by

Did you ever wanted to hack an IoT device but did not know how to start? Having UART is nice, but does not help in many cases. For a complete analysis of an IoT device, it is required to look at the firmware itself. In most cases this means that the firmware, data or encryption keys need to be extracted from the device memory. Many researchers are hesitant to do that as there is a high risk of destroying the device or leaving it in an inoperable state. In this workshop we will look at different flash memory types (EEPROM, SPI flash, NAND flash, eMMC flash) and how to extract the information from them. We will show that you do not need very expensive hardware to archive your goal and that it is not as complicated as everyone believes. See which tools might be useful for your own lab! Notes Due to limited workshop equipment, Hacking 101 will be limited to 28 participants. Please arrive early and queue in advance. Simultaneous interpretation will not be provided for this session.