{"product_id":"re-verse-2027-bluetooth","title":"RE\/\/verse 2027 Training - Bluetooth Low Energy – Full Stack Attack with Xeno \u0026 Veronica Kovah","description":"\u003cdiv\u003e\n\u003cdiv\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eCONFERENCE\u003c\/strong\u003e:  March 11-13th, 2027\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eTRAINING\u003c\/strong\u003e: March 14th-17th, 2027\u003cstrong\u003e\u003c\/strong\u003e\n\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eLOCATION\u003c\/strong\u003e: \u003ca href=\"https:\/\/www.cariberoyale.com\/\" rel=\"noopener\" target=\"_blank\"\u003eCaribe Royale\u003c\/a\u003e, Orlando, FL (\u003ca href=\"https:\/\/book.passkey.com\/go\/REverse2027\" rel=\"noopener\" target=\"_blank\"\u003ediscounted group rate link\u003c\/a\u003e)\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eNOTE\u003c\/strong\u003e: Conference admission purchased separately.  Conference tickets can be purchased \u003ca href=\"https:\/\/shop.binary.ninja\/products\/re-verse-2027-admission\" target=\"_blank\"\u003ehere\u003c\/a\u003e.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c\/div\u003e\n\u003c\/div\u003e\n\u003cp\u003eIt’s pretty fun to hack things wirelessly! And hey, it turns out there’s literally *billions of Bluetooth Low Energy (BLE) things sold per year, so let’s learn how to hack those!\u003c\/p\u003e\n\u003cp\u003eIn this class you will become an expert in all things BLE! You will be given a guided tour of the entire BLE protocol stack in a bottom up fashion. We will stop to admire and understand vulnerabilities applicable to the different stack levels, whether fundamental protocol-level vulnerabilities, or past implementation vulnerabilities. And we will learn by doing as we proceed through numerous labs at every level where we examine the interactions between a custom Android phone application, and a piece of hardware with custom firmware, which is typical of BLE usage.\u003c\/p\u003e\n\u003ch3\u003eKey Learning Objectives\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCover all the most important Bluetooth Low Energy protocols and profiles at every level of the stack\u003c\/li\u003e\n\u003cli\u003eUnderstand the security model of BLE in depth\u003c\/li\u003e\n\u003cli\u003eUnderstand past work including both protocol and implementation vulnerabilities, and what is and isn’t still relevant to today’s devices\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3 style=\"line-height: 1.38; margin-top: 20pt; margin-bottom: 6pt;\" dir=\"ltr\"\u003ePrerequisites\u003c\/h3\u003e\n\u003cp\u003eStudent must be comfortable reading C code if they want to modify or fix the Ultra Vulnerable Peripheral\u003c\/p\u003e\n\u003ch3 style=\"line-height: 1.38; margin-top: 20pt; margin-bottom: 6pt;\" dir=\"ltr\"\u003eCourse Agenda\u003c\/h3\u003e\n\u003ch4\u003ePhysical Layer (PHY)\u003c\/h4\u003e\n\u003cul class=\"listStyle\"\u003e\n\u003cli\u003eIntroduction\u003c\/li\u003e\n\u003cli\u003eEncoding\/Decoding\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003eLink Layer (LL)\u003c\/h4\u003e\n\u003cul class=\"listStyle\"\u003e\n\u003cli\u003ePacket formats by PHY type\u003c\/li\u003e\n\u003cli\u003eBasic advertisements introduction (ADV_IND)\u003c\/li\u003e\n\u003cli\u003eOther basic advertisements (ADV_DIRECT_IND, ADV_NONCONN_IND, ADV_SCAN_IND)\u003c\/li\u003e\n\u003cli\u003eScanning (SCAN_REQ\/RSP)\u003c\/li\u003e\n\u003cli\u003eConnecting (CONNECT_IND)\u003c\/li\u003e\n\u003cli\u003eLL data\u003c\/li\u003e\n\u003cli\u003eLL control\u003c\/li\u003e\n\u003cli\u003eUnderstanding LL vulnerabilities: Machine-in-the-Middle attacks\u003c\/li\u003e\n\u003cli\u003eUnderstanding LL vulnerabilities: Relay attacks\u003c\/li\u003e\n\u003cli\u003eUnderstanding LL vulnerabilities: “InjectaBLE”\u003c\/li\u003e\n\u003cli\u003eUnderstanding LL vulnerabilities: Privacy attacks\u003c\/li\u003e\n\u003cli\u003eLL memory safety threat model\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003eHost Controller Interface (HCI)\u003c\/h4\u003e\n\u003cul class=\"listStyle\"\u003e\n\u003cli\u003eHCI introduction\u003c\/li\u003e\n\u003cli\u003eHCI transport layer\u003c\/li\u003e\n\u003cli\u003eHCI packet formats\u003c\/li\u003e\n\u003cli\u003eHCI logging\u003c\/li\u003e\n\u003cli\u003eHCI memory safety threat model\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003eLogical Link Control and Adaptation Protocol (L2CAP)\u003c\/h4\u003e\n\u003cul class=\"listStyle\"\u003e\n\u003cli\u003eL2CAP introduction\u003c\/li\u003e\n\u003cli\u003eL2CAP data channel\u003c\/li\u003e\n\u003cli\u003eL2CAP signaling channel\u003c\/li\u003e\n\u003cli\u003eL2CAP memory safety threat model\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003eGeneric Access Profile (GAP)\u003c\/h4\u003e\n\u003cul class=\"listStyle\"\u003e\n\u003cli\u003eGAP introduction\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003eSecurity Manager Protocol (SMP)\u003c\/h4\u003e\n\u003cul class=\"listStyle\"\u003e\n\u003cli\u003eSMP introduction\u003c\/li\u003e\n\u003cli\u003eLegacy pairing\u003c\/li\u003e\n\u003cli\u003eUnderstanding SMP vulnerabilities in the context of Legacy pairing: NiNo\u003c\/li\u003e\n\u003cli\u003eUnderstanding SMP vulnerabilities in the context of Legacy pairing: KNOB\u003c\/li\u003e\n\u003cli\u003eSecure Connections pairing\u003c\/li\u003e\n\u003cli\u003eUnderstanding SMP vulnerabilities in the context of Secure Connections pairing: KNOB\u003c\/li\u003e\n\u003cli\u003eUnderstanding SMP vulnerabilities in the context of Secure Connections pairing: BlueMirror\u003c\/li\u003e\n\u003cli\u003eUnderstanding SMP vulnerabilities in the context of Secure Connections pairing: Invalid Curve Attack\u003c\/li\u003e\n\u003cli\u003eUnderstanding SMP vulnerabilities in the context of Secure Connections pairing: BLURtooth\u003c\/li\u003e\n\u003cli\u003eUnderstanding SMP vulnerabilities in the context of Secure Connections pairing: Method Confusion\u003c\/li\u003e\n\u003cli\u003eLE Security Mode 1\u003c\/li\u003e\n\u003cli\u003eLE Security Mode 2\u003c\/li\u003e\n\u003cli\u003eSMP memory safety threat model\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003eATTribute Protocol (ATT)\u003c\/h4\u003e\n\u003cul class=\"list-style\"\u003e\n\u003cli\u003eATT introduction\u003c\/li\u003e\n\u003cli\u003eATT PDUs\u003c\/li\u003e\n\u003cli\u003eATT handle enumeration\u003c\/li\u003e\n\u003cli\u003eATT memory safety threat model\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003eGeneric ATTribute Profile (GATT)\u003c\/h4\u003e\n\u003cul class=\"list-style\"\u003e\n\u003cli\u003eGATT introduction\u003c\/li\u003e\n\u003cli\u003eVisualizing GATT via packet\u003c\/li\u003e\n\u003cli\u003eVisualizing GATT via MitM tools: GATTacker\u003c\/li\u003e\n\u003cli\u003eUnderstanding GATT vulnerabilities: Access control failures\u003c\/li\u003e\n\u003cli\u003eUnderstanding GATT vulnerabilities: Replay attacks\u003c\/li\u003e\n\u003cli\u003eUnderstanding GATT vulnerabilities: Privacy\u003c\/li\u003e\n\u003cli\u003eGATT memory safety threat model\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch4\u003eApplication-specific vulnerabilities\u003c\/h4\u003e\n\u003cul class=\"list-style\"\u003e\n\u003cli\u003eIntroduction\u003c\/li\u003e\n\u003cli\u003eCommand injection\u003c\/li\u003e\n\u003cli\u003eApplication-layer encryption\u003c\/li\u003e\n\u003cli\u003eInsecure firmware updates\u003c\/li\u003e\n\u003cli\u003eApplication-specific MitM\u003c\/li\u003e\n\u003cli\u003eApplication-specific replay attacks\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eHardware\/Software Requirements\u003c\/h3\u003e\n\u003cp\u003eYour own laptop with VMware installed, capable of running an x86-based Ubuntu VM (which will have all the Bluetooth tools and firmware compilation environment pre-installed).\u003c\/p\u003e\n\u003ch3\u003e\n\u003cbr\u003eIncluded Course Materials\u003c\/h3\u003e\n\u003cp\u003eDuring the class the instructors will provide an Android phone, Bluetooth dongle for running a custom firmware, and various other Bluetooth dongles for sniffing and spoofing traffic, and a USB hub for plugging everything in. If you’re paranoid about “BadUSB” attacks, you should bring a laptop that you’re going to wipe afterwards, because we’re going to be plugging in a lot of USB hardware to aid in learning about Bluetooth! If you’d like to buy and provision your own hardware before class to use after class, please reach out at the email listed \u003ca href=\"https:\/\/darkmentor.com\/\"\u003ehere\u003c\/a\u003e.\u003c\/p\u003e\n\u003ch3\u003eTrainers\u003cstrong\u003e\u003c\/strong\u003e\n\u003c\/h3\u003e\n\u003cp\u003e\u003cstrong\u003eVeronica Kovah \u003c\/strong\u003eis a researcher who has created and released multiple over-the-air arbitrary code execution exploits which target Bluetooth chip firmware. She presented these attacks at BlackHat USA 2020. In 2018 she founded the security consultancy Dark Mentor LLC. She has previously worked at companies like Tesla on vehicular security and NSA as an adjunct instructor and Capability Development Specialist developing CNE tools for embedded systems. She is currently using her background in reverse engineering and exploitation to specialize in the security analysis of Bluetooth systems.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eXeno Kovah\u003c\/strong\u003e began leading Windows kernel-mode rootkit detection and defense research projects at MITRE in 2009, before moving into research on BIOS security in 2011. His team’s first public talks started appearing in 2013, which led to a flurry of presentations on BIOS-level vulnerabilities up through 2014. In 2015 he co-founded LegbaCore. And after presenting a firmware worm that could spread between Macs via Apple’s EFI-based BIOS and Thunderbolt Ethernet adapters, he ended up working for Apple. There he worked on securing all the lesser-known firmwares on Macs and peripherals – everything from 3rd party GPUs to SecureBoot for monitors! He worked on the x86-side of the T2 SecureBoot architecture, and his final project was leading the M1 SecureBoot architecture – being directly responsible for designing a system that could provide iOS-level security, while still allowing customer choice to trust arbitrary non-Apple code such as Linux bootloaders. He left Apple in Dec 2020 after the M1 Macs shipped, so he could work full time on OpenSecurityTraining2.\u003c\/p\u003e","brand":"Vector 35","offers":[{"title":"Default Title","offer_id":41626407501882,"sku":null,"price":5100.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/1783\/9513\/files\/xeno-veronica.png?v=1788535384","url":"https:\/\/shop.binary.ninja\/products\/re-verse-2027-bluetooth","provider":"VECTOR 35 ","version":"1.0","type":"link"}