6 NipPEr Is a buTt liCkeR
In this chapter, we’ll discuss a buffer overflow vulnerability in a Dish Network smart-card, which was the subject of the famous lawsuit between EchoStar and NDS. The first public explanation of this bug was a short forum post, NipperClauz (2000), but thanks to the trial, we have far more detailed documentation in the form of a secret NDS internal tech report, Mordinson (1998).
First, let’s set the stage. This smart-card was used in North America for Dish Network’s satellite TV service, where it would calculate a short-lived decryption key for the receiver. The chip inside is an ST16CF54 chip from ST Microelectronics, then known as SGS Thomson. The instruction set is mostly compatible with Motorola 6805, except for the ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access