SA-RIOT – Security Associate Researcher IoT

1.499,00 

Enrollment Advisory
We encourage you to join this course only if you feel comfortable with the level of material it covers. If you are unsure, we warmly recommend completing the OST2 propaedeutic course first, as it will provide you with the foundations needed to follow along with confidence.

Learn the basics following the book Fuzzing Against the Machine with the labs and custom content!

We offer 24/7 support via our Discord

FAQ:

Lab: 15 days at your pace. -> We have a meter that if you need to put a module in pause it will consume 1/10 of a second. It’s a total of 360 hours. Every module has its own lab.
What if I finish all the time available? Even if quite unlikely we will have packages to refill the lab hours.
– Exam: We will include 1 attempt, there will be separate exam packs for who has bought the course.
Coupons: If you haven’t fill the form https://forms.gle/NPFvnV9FcdR1gKbp8 please do and you will have an extra early bird discount

Follow us on X and Linkedin @fuzzsociety_org to get additional info

 

In stock

SKU: SARIOT Categories: , ,

Description

SA-RIOT - Detailed Curriculum
01
🔍

QEMU+AFL = Vulnerabilities?

1. Is it so easy to find vulnerabilities?

• Downloading and installing AFL++
• Preparing a vulnerable VLC instance
• VLC exploit

2. Full-system fuzzing – introducing TriforceAFL

• Understanding full-system fuzzing concepts
• Installing TriforceAFL
• Setting up the fuzzing environment

3. Final Test

4. Further reading

5. Appendix

02
⚙️

QEMU Primer

1. Adding a new CPU

2. Emulating an embedded firmware

3. Reverse engineering DMA peripherals

4. Emulating UART with Avatar2 for firmware debugging

5. Final Test

03
📱

Baseband Emulation

1. A crash course on mobile phone architecture

• Baseband
• Baseband CPU family
• Application processor and baseband interface
• A talk with Shannon
• A note on GSM/3GPP/LTE protocol specifications

2. Setting up FirmWire for vulnerability validation

• CVE-2020-25279 – emulator fuzzing
• CVE-2020-25279 – OTA exploitation

3. Final Test

04
🖥️

Router Emulation x86

1. OpenWrt on x86

2. Building the firmware

• Testing the firmware in QEMU
• Extracting and preparing the kernel

3. Fuzzing the kernel

4. Post-crash core dump triaging

05
💻

Router Emulation ARM32

1. Emulating the ARM architecture to run an OpenWrt system

2. Installing TriforceAFL for ARM

3. Running TriforceAFL in OpenWrt for ARM

4. Obtaining a crash

5. Final Test

Bonus: Evolving to recent harnesses

1. Using a more recent version of AFL++

2. Harnessing techniques

3. libqemu

4. device trees, nand, nor

06
🍎

iOS14/16 Emulation and Fuzzing of iPhone11

1. A brief history of iOS emulation

2. iOS basics

• What it takes to boot iOS
• Code signatures
• Plist files and entitlements
• Binaries compilation
• IPSW formats and research kernels

3. Setting up an iOS emulator

• Preparing the environment
• Building the emulator
• Boot prepping
• Booting iOS in QEMU

4. Preparing your harness to start fuzzing

5. Triforce's driver mod for iOS

6. Final Test

07
🤖

Android Emulation and Fuzzing

1. Introducing the Android OS and its architecture

• Android system architecture overview
• Understanding the Android stack
• Key components for fuzzing

2. Fuzzing Android libraries with Sloth

• Setting up Sloth framework
• Targeting Android libraries
• Analysis and vulnerability discovery

3. Final Test

🎯
🏆

Certification Exam

🎯 Fuzzing
⚡ Basic Emulation
🔐 Vulnerability hunting

Leave a Reply

Your email address will not be published. Required fields are marked *