12 PIC18F452 ICSP and HID
Back in 2010, there was a lot of interest in exploiting RFID tags that hold symmetric keys. The cards themselves were reasonably well protected from memory extraction, and keys might be unique to each customer’s installation, so researchers would instead attack the readers. These readers often used commodity microcontrollers and trusted their readout protection to keep the symmetric keys safe.
In this chapter, we’ll cover two such exploits that were used to extract keys from HID iClass readers. Both of them exploit nuances in ICSP, Microchip’s in circuit serial programming standard. The first, published at 27C3 as Meriac (2010), involves erasing a protected page of flash memory over ICSP and replacing it with shellcode ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access