3 MD380 Null Pointer, DFU
While it’s brutally effective to exploit a chip vendor’s bootloader in ROM, many device vendors add a second bootloader in flash memory. This is the story, first told in Goodspeed (2016b), of how I dumped a two-way radio’s firmware through a null pointer read vulnerability. It is also the story of how the firmware update cryptography was broken, from Rütten and Goodspeed (2016).
The Tytera MD380 is a handheld radio transceiver that uses either analog FM or Digital Mobile Radio (DMR). DMR provides some of the features of GSM, such as text messaging and timesharing of the repeater tower, without the hassles of SIM cards. Many people purchased the MD380 for use in amateur radio; it was just too tempting to rip out its firmware ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access