17 STM32 FPB Glitch
There are many brilliant attacks to be found in Obermaier, Schink, and Moczek (2020), but my favorite is an escape from RDP Level 1 of the STM32F103 and also one of its clones, the APM32F103 from Geehy. This one involves a lot of moving parts, so gather ’round and pay attention!
First, recall from Chapter 2 that RDP Level 1 disables flash memory when a JTAG debugger is attached, but that the connection is allowed and all SRAM is available to the debugger. Resetting the chip will disconnect the debugger and reconnect flash memory, but it does not erase SRAM.
Second, the STM32 chips can boot from SRAM, ROM, or flash memory depending upon the values sampled on the BOOT0 and BOOT1 pins at startup. Flash has full access to memory, ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access