38 citations · 114 across the 13 of their papers we have counts for
12 papers · 1 filter
Evil Never Sleeps: When Wireless Malware Stays On After Turning Off iPhones
Jiska Classen, Alexander Heinrich, Robert Reith +1
When an iPhone is turned off, most wireless chips stay on. For instance, upon user-initiated shutdown, the iPhone remains locatable via the Find My network. If the battery runs low…
Very Pwnable Network: Cisco AnyConnect Security Analysis
Gerbert Roitburd, Matthias Ortmann, Matthias Hollick +1
Corporate Virtual Private Networks (VPNs) enable users to work from home or while traveling. At the same time, VPNs are tied to a company's network infrastructure, forcing users to…
Ghost Peak: Practical Distance Reduction Attacks Against HRP UWB Ranging
Patrick Leu, Giovanni Camurati, Alexander Heinrich +5
We present the first over-the-air attack on IEEE 802.15.4z High-Rate Pulse Repetition Frequency (HRP) Ultra-WideBand (UWB) distance measurement systems. Specifically, we demonstrat…
Happy MitM: Fun and Toys in Every Bluetooth Device
Jiska Classen, Matthias Hollick
Bluetooth pairing establishes trust on first use between two devices by creating a shared key. Similar to certificate warnings in TLS, the Bluetooth specification requires warning…
Firmware Insider: Bluetooth Randomness is Mostly Random
Jörn Tillmanns, Jiska Classen, Felix Rohrbach +1
Bluetooth chips must include a Random Number Generator (RNG). This RNG is used internally within cryptographic primitives but also exposed to the operating system for chip-external…
Frankenstein: Advanced Wireless Fuzzing to Exploit New Bluetooth Escalation Targets
Jan Ruge, Jiska Classen, Francesco Gringoli +1
Wireless communication standards and implementations have a troubled history regarding security. Since most implementations and firmwares are closed-source, fuzzing remains one of…