|
|
|
|
|
by nick0garvey
1074 days ago
|
|
Most of the attacks I see on Nordic devices are power based attacks, where cutting the power for a brief instant causes protection instructions not to run. This one is entirely different, and attacks the initialization code directly. This code has no restrictions on its ability to access memory, allowing a full dump. Great method. |
|
After managing to connect through glitching, they dump the FW, then turn off APPROTECT, reflash, and have open debug access.
>Our attack setup thus consists out of 1) a transistor connected to the CPU core supply voltage and ground, 2) a dev board to control the glitch timing, and 3) a debug probe to try to access the debug interface.
[1]: https://www.emproof.com/attacking-microcontroller-readout-pr...