Willem Melching(@PD0WM) 's Twitter Profileg
Willem Melching

@PD0WM

I take things apart. Sometimes I put them back together. Consulting & Trainings: https://t.co/HDoTb6QsAF

ID:48720751

linkhttp://icanhack.nl calendar_today19-06-2009 14:34:15

113 Tweets

2,6K Followers

541 Following

Lennert(@LennertWo) 's Twitter Profile Photo

In 2022 we found vulnerabilities in dormakaba Saflok hotel locks. Reading one RFID card enables us to forge a pair of cards that open any door in that hotel! Dormakaba is currently working with its customers to fix the 3 million affected locks. wired.com/story/saflok-h…

account_circle
Willem Melching(@PD0WM) 's Twitter Profile Photo

New blog post is out! Extracting the SecOC keys used for securing the CAN Bus on the 2021+ RAV4 Prime. icanhack.nl/blog/secoc-key…

Research started all the way in 2022, but took many evenings of reverse engineering to get code execution.

PoC: github.com/I-CAN-hack/sec…

New blog post is out! Extracting the SecOC keys used for securing the CAN Bus on the 2021+ RAV4 Prime. icanhack.nl/blog/secoc-key… Research started all the way in 2022, but took many evenings of reverse engineering to get code execution. PoC: github.com/I-CAN-hack/sec…
account_circle
Willem Melching(@PD0WM) 's Twitter Profile Photo

I'm releasing the 'automotive' rust crate! It has a fully async CAN adapter and UDS client. This allows building fast scanners or communicating with multiple ECUs in parallel. Both SocketCAN (Linux) and panda (Linux, MacOS, Windows) are supported.

github.com/I-CAN-hack/aut…

I'm releasing the 'automotive' rust crate! It has a fully async CAN adapter and UDS client. This allows building fast scanners or communicating with multiple ECUs in parallel. Both SocketCAN (Linux) and panda (Linux, MacOS, Windows) are supported. github.com/I-CAN-hack/aut…
account_circle
Willem Melching(@PD0WM) 's Twitter Profile Photo

This February I'll be teaching a four day course on Car Hacking. There will be over 20 different hands-on exercises with real ECUs!

Check out some experiences from previous participants: icanhack.nl/training/#expe…

account_circle
ringzerø.training && @ringzer0@infosec.exchange(@_ringzer0) 's Twitter Profile Photo

Did you know Willem Melching isn't just doing an awesome course on car hacking with Ringzer0? He's also doing a workshop on Automative firmware reversing! Learn how to analyze automotive firmware with one of the greatest minds in the space! buff.ly/3uU5F2E

account_circle
Willem Melching(@PD0WM) 's Twitter Profile Photo

Had blast giving my 'Practical Car Hacking' training with participants from Deloitte and RDW! Three days filled with hands-on hacking on real vehicle hardware.

If you're interested in attending one of my trainings or organize one, check out my website icanhack.nl.

Had blast giving my 'Practical Car Hacking' training with participants from Deloitte and RDW! Three days filled with hands-on hacking on real vehicle hardware. If you're interested in attending one of my trainings or organize one, check out my website icanhack.nl.
account_circle
Willem Melching(@PD0WM) 's Twitter Profile Photo

Second day of the training! Today we will be covering more diagnostic protocols and hardware hacking. Lots of actual vehicle hardware to practice on.

Second day of the training! Today we will be covering more diagnostic protocols and hardware hacking. Lots of actual vehicle hardware to practice on.
account_circle
wrongbaud(@wrongbaud) 's Twitter Profile Photo

New Blog Post!

How to Build Your First Hardware Hacking Lab:

voidstarsec.com/hw-hacking-lab…

Happy Friday!

account_circle
quarkslab(@quarkslab) 's Twitter Profile Photo

Breaking the Gecko's Secure Boot
Firmware updates can fix vulns but who fixes the vulns in the update service?
In our new blog post Sami Babigeon and Forgette Benoît show why updating IoT firmware securely is hard, even when using state-of-the-art features.
blog.quarkslab.com/breaking-secur…

Breaking the Gecko's Secure Boot Firmware updates can fix vulns but who fixes the vulns in the update service? In our new blog post Sami Babigeon and @Mad5quirrel show why updating IoT firmware securely is hard, even when using state-of-the-art features. blog.quarkslab.com/breaking-secur…
account_circle
Willem Melching(@PD0WM) 's Twitter Profile Photo

We (Greg Hogan, Robbe Derks and me) managed to score 1st place in the Car Hacking Village CTF and we earned our second DEF CON Black Badge! The last two hours of the CTF were very intense as the other teams almost caught up 😅.

We (@gregjhogan, @robbederks and me) managed to score 1st place in the @CarHackVillage CTF and we earned our second DEF CON Black Badge! The last two hours of the CTF were very intense as the other teams almost caught up 😅. #DEFCON31
account_circle
Willem Melching(@PD0WM) 's Twitter Profile Photo

Exploited a command injection in a DJI RM500 Smart Controller. Full exploit fits in image below. More details in the blog post: icanhack.nl/blog/dji-rm500…

Exploited a command injection in a DJI RM500 Smart Controller. Full exploit fits in image below. More details in the blog post: icanhack.nl/blog/dji-rm500…
account_circle
Willem Melching(@PD0WM) 's Twitter Profile Photo

Having some fun with a Sonos One Gen2 and a PCILeech. Thanks to Synacktiv and blasty for all the great info! synacktiv.com/en/publication… youtube.com/watch?v=Wqcbp9…

Having some fun with a Sonos One Gen2 and a PCILeech. Thanks to @Synacktiv and @bl4sty for all the great info! synacktiv.com/en/publication… youtube.com/watch?v=Wqcbp9…
account_circle