September 2024
Intermediate to advanced
408 pages
7h 29m
English
Many microcontrollers allow for some sort of partial locking mode, in which a debugger may be attached but code is still protected. On the STM32 family, this corresponds to RDP Level 1, where flash memory is disconnected after the debugger connects. This chapter describes a vulnerability in the STM32F0 series, in which flash memory is disconnected two clock cycles too late. A carefully orchestrated debugger can dump one word per connection.
This vulnerability was first described at Usenix WOOT, near the end of Obermaier and Tatschner (2017).
As we discussed in Chapter 2, STM32’s readout device protection (RDP) feature has three levels. Level 0 is unprotected, while Level 2 is a total JTAG lockout, rejecting all ...
Read now
Unlock full access