Now You See mi: Hacking the Xiaomi C400 Camera

Now You See mi: Hacking the Xiaomi C400 Camera

Researchers exploited weaknesses in Xiaomi’s miIO protocol to bypass authentication, predict cryptographic values, and trigger memory corruption, ultimately achieving remote code execution and a cloud-independent jailbreak on a Xiaomi C400 camera.

Reverse engineering Realtek RTL8761B* Bluetooth chips, to make better Bluetooth security tools & classes

Reverse engineering Realtek RTL8761B* Bluetooth chips, to make better Bluetooth security tools & classes

Bloodied (but not broken) by the ordeal, I achieved my goals and stretch goals. And given that there are no public descriptions of how Realtek Bluetooth chips work, I look forward to sharing hitherto-unknown information about how to navigate and understand these mostly-16-bit-MIPS-code systems. And I’ll discuss how their ROM-“patch”ing firmware update mechanism works, how you can patch it to change its code too, and the security implications thereof.