What this course is about
An intensive 2-day advanced course covering firmware reverse engineering and exploitation. You will extract firmware from manufacturer update files, analyze it in Ghidra, reverse engineer security access algorithms, and create custom exploitation tools. This training builds on the fundamentals to deliver deep technical skills in automotive security assessment, from understanding secure boot mechanisms to crafting seed-key bypasses.
Agenda
Day 1: Reverse Engineering
Theory
- Firmware extraction from manufacturer update files
- UDS flashing procedures and update mechanisms
- Fault injection techniques against ECU hardware
- Introduction to Ghidra for automotive firmware analysis
- Common automotive firmware patterns and architectures
- Firmware integrity checks and secure boot mechanisms
Hands-on
- Extracting firmware from OTA update packages
- Loading and analyzing automotive firmware in Ghidra
- Identifying security-critical functions in firmware
- Mapping memory regions and peripheral registers
Day 2: Exploitation
Theory
- Security access (Seed-Key) algorithm internals
- Common weaknesses in automotive authentication
- Advanced fuzzing techniques for diagnostic protocols
- Bypassing firmware integrity and signature verification
- Creating custom automotive security testing tools
Hands-on
- Reverse engineering ECU security access algorithms
- Creating custom seed-key bypass tools
- Building automated UDS fuzzing scripts
- Developing custom flashing and calibration tools
