How to analyze automotive ECU architectures (PPC-VLE, TriCore) that IDA, Ghidra, and Binary Ninja don't support out of the box. The IR-as-common-language structure of RE tools, the formula for implementing an architecture plugin, and how non-standard calling conventions poison data-flow analysis, with the fix.
A draft design for blackbox fuzzing of the LS Electric PLC system, built on analysis of the XGT protocol. Covers automated mutation strategy, crash triage, and the monitoring infrastructure for discovering vulnerabilities in industrial control systems.
An in-depth analysis of two vulnerabilities found in Netis MEX605 router firmware v2.00.06: OS command injection via the ping diagnostic tool, and DOM-based XSS in the NTP server configuration.
A command injection vulnerability found in the WPS PIN handling of the E5600 router — authenticated remote code execution via a crafted WPS PIN parameter