
awesome-connected-things-sec — Updated!
قائمة منسقة من الموارد الأمنية لجميع الأشياء المتصلة
🔐 موارد أمان الأشياء المتصلة الرائعة
أبحاث الأمان وتقنيات الاستغلال لأنظمة إنترنت الأشياء والأنظمة المدمجة والصناعية والسيارات.
المحتويات
- هجمات العتاد
- البروتوكولات اللاسلكية
- أمان البرامج الثابتة
- بروتوكولات الشبكة والويب
- أمان السحابة والأنظمة الخلفية
- أمان تطبيقات الهاتف المحمول
- الأنظمة الصناعية والسيارات
- أنظمة الدفع
- الأدوات
- الأمان الدفاعي
- موارد التعلّم
- المعامل ومسابقات CTF
- الأبحاث والمجتمع
- MCP / وكيل الذكاء الاصطناعي
هجمات العتاد
الأساسيات
- دليل عتاد إنترنت الأشياء
- مقدمة في اختراق العتاد - استخراج أول برنامج ثابت لك
- مقدمة في اختراق العتاد
- مجموعات أدوات العتاد لتحليل أمان إنترنت الأشياء
- اختراق العتاد لأجهزة إنترنت الأشياء - الاستغلال الهجومي لإنترنت الأشياء
هجمات الواجهات
UART
- تحديد واجهة UART
- أساسيات الطرفية التسلسلية
- الهندسة العكسية للمنافذ التسلسلية
- مقدمة في الهندسة العكسية المدمجة: اكتشاف UART واستخراج البرامج الثابتة عبر UBoot
- استخدام UART للاتصال بكاميرا IP صينية
- رحلة في اختراق عتاد إنترنت الأشياء: UART
- الوصول إلى البرامج الثابتة واستخراجها عبر UART
- اتصالات UART والتحليل الديناميكي على Linksys e1000
JTAG
- أساسيات اختراق العتاد 101: مقدمة في JTAG
- كيفية العثور على واجهة JTAG
- تحليل JTAG
- اتصالات Bus Pirate JTAG مع OpenOCD
- استخراج البرامج الثابتة من الذاكرة الخارجية عبر JTAG
- دليل المسافر إلى اختراق iPhone Lightning و JTAG
- تصحيح أخطاء متحكمات AVR عبر JTAG
SWD (تصحيح الأخطاء السلكي التسلسلي)
- نظرة عامة على بروتوكول SWD - HardBreak Wiki
- كشف الثغرات: استكشاف سطح هجوم SWD في العتاد
- مقدمة في بروتوكول تصحيح الأخطاء السلكي التسلسلي ARM
- تصحيح الأخطاء السلكي التسلسلي ومعمارية CoreSight
- LibSWD - مكتبة تصحيح الأخطاء السلكي التسلسلي المفتوحة
- معسكر اختراق العتاد والاستغلال - SWD
SPI
- أساسيات اختراق العتاد 101: تحديد واستخراج ذاكرة eMMC الوميضية
- استخراج البرامج الثابتة من الموجّه باستخدام Bus Pirate - SPI
- استخراج الذاكرة الوميضية عبر SPI
- استخراج البرامج الثابتة من الأجهزة المدمجة (SPI NOR Flash)
- كيفية برمجة شريحة موجّه باستخدام مبرمج
- TPM 2.0: استخراج مفاتيح Bitlocker عبر SPI
I2C
- أمان إنترنت الأشياء الجزء 16: سطح هجوم العتاد I2C
- استغلال I2C - HackTricks
- ناقل هجوم حصان طروادة العتادي I2C غير التدخلي (PDF)
- اختراق العتاد: حقن I2C باستخدام Bus Pirate
- حماية بروتوكولات SPI و I2C و I3C
TPM
- مقدمة في TPM (وحدة النظام الأساسي الموثوقة)
- التغلب على أمان وحدة النظام الأساسي الموثوقة في 30 دقيقة
استخراج الذاكرة
eMMC
- بروتوكول eMMC
- RPMB: مكان سري داخل eMMC
- استعادة بيانات eMMC من هاتف ذكي تالف
- أطلق العنان لأجهزة منزلك الذكية: اختراق روبوت المكنسة الكهربائية
- اختراق إنترنت الأشياء العملي: Rapid7 في DEF CON 30
القنوات الجانبية وحقن الأخطاء
الأساسيات
- هجمات القنوات الجانبية - Yifan Lu
- هجمات على تطبيقات الأنظمة الآمنة
- مجموعة الفَزْزَة وتحليل الملفات الثنائية وأمان إنترنت الأشياء
هجمات الإرباك
- هجوم إرباك NAND على Wink Hub
- درس تعليمي حول إرباك الجهد باستخدام Crowbars
- هجوم إرباك الجهد باستخدام iCEstick Glitcher
- إرباك FPGA وهجمات القنوات الجانبية - Samy Kamkar
- هجوم إرباك الطاقة العتادي - rhme2
- المفاتيح في الذاكرة الوميضية - إرباك مفاتيح AES من Arduino
- تنفيذ هجمات الإرباك الكهربائي العملية
- كيفية حقن أخطاء الجهد
- Glitcher الجزء 1 - إرباك الجهد القابل للتكرار على متحكمات STM32 الدقيقة
- إرباك الجهد STM32L05
تحليل الطاقة
متحكمات دقيقة أخرى
- استخراج Amlogic A113X Bootrom
- إعادة قراءة عملية استغلال TrustZone في AMLogic A113X
- الهندسة العكسية لمتحكم دقيق غير معروف
- اختراق البرامج الثابتة للمتحكم الدقيق عبر USB
- هناك ثقب في SoC الخاص بك: إرباك MediaTek BootROM
هجمات PCIe و DMA
- درس تعليمي عملي حول PCIe للمبتدئين تمامًا على Windows - الجزء 1
- درس تعليمي عملي حول PCIe للمبتدئين تمامًا على Windows - الجزء 2
- هجوم PCIe DMA ضد Jetson Nano المؤمّن (CVE-2022-21819)
البروتوكولات اللاسلكية
أساسيات الترددات الراديوية
- دورة كاملة في الراديو المعرّف بالبرمجيات - Michael Ossmann
- فهم الراديو
- مقدمة في الراديو المعرّف بالبرمجيات
- مقدمة في GNU Radio Companion
- إنشاء مخطط تدفق في GNU Radio Companion
- تحليل الإشارات الراديوية 433MHz
- تسجيل إشارات راديوية محددة
- هجمات إعادة التشغيل باستخدام Raspberry Pi و rpitx
- الهندسة العكسية لإشارة مفتاح سيارة
- GRCON 2021 - Capture the Signal
Bluetooth / BLE
الأساسيات
- أمان Bluetooth الرائع
- هندسة حركة المرور في شبكة Bluetooth Piconet
- خصائص BLE: درس تعليمي للمبتدئين
- مقدمة في Bluetooth Low Energy (PDF)
- دليل دراسة أمان Bluetooth LE
- الهندسة العكسية لأجهزة BLE
- رحلتي نحو الهندسة العكسية لسوار ذكي - Bluetooth-LE RE
تقنيات الاستغلال- Intel Edison as Bluetooth LE Exploit Box
- Reverse Engineering and Exploiting a Smart Massager
- I Hacked MiBand 3
- GATTacking Bluetooth Smart Devices
- Examining the August Smart Lock
- Practical Introduction to BLE GATT Reverse Engineering
- MojoBox - Yet Another Not So Smartlock
- Bluetooth Smartlocks
- Bluetooth Beacon Vulnerability
- Denial of Pleasure: Attacking Unusual BLE Targets with a Flipper Zero
- Grand Theft Auto: A peek of BLE relay attack
- How I Hacked Smart Lights: CVE-2022-47758
Vulnerability Research
- Finding Bugs in Bluetooth
- Sweyntooth Vulnerabilities
- BrakTooth: Causing Havoc on Bluetooth Link Manager
- BLUFFS: Bluetooth Forward and Future Secrecy Attacks (CVE-2023-24023)
- AirDrop Leak - Sniffing BLE Traffic from Apple Devices
- BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution
- BRAKTOOTH: Causing Havoc on Bluetooth Link Manager (PDF)
- Norec Attack: Stripping BLE encryption from Nordic's Library (CVE-2020-15509)
- BlueDucky - HID Injection on Unpatched Android (CVE-2023-45866)
- Microsoft Bluetooth Driver Spoofing - CVE-2024-21306
- Bluetooth Auracast / LE Audio Security Analysis
Conference Talks
- Blue2thprinting: WTF Am I Even Looking At?
- Open Wounds: Last 5 Years Have Left Bluetooth to Bleed
- Sniffing Bluetooth Through My Mask During the Pandemic
Tools - Software
- Bluing - Intelligence Gathering for Bluetooth
- BlueToolkit - Bluetooth Classic Vulnerability Testing
- btproxy
- hcitool and bluez
- Testing with GATT Tool
- crackle - Cracking BLE Encryption
- bettercap
- GATTacker
- BTLEjack - BLE Swiss Army Knife
- DEDSEC Bluetooth Exploit
- BrakTooth ESP32 PoC
- SweynTooth BLE Attacks
- ESP32 Bluetooth Classic Sniffer
- Bluetooth Hacking Collection
Tools - Hardware
Tools
Hacking Bluetooth Coffee Machines
- Hacking Bluetooth to Brew Coffee from GitHub Actions - Part 1
- Hacking Bluetooth to Brew Coffee from GitHub Actions - Part 2
- Hacking Bluetooth to Brew Coffee from GitHub Actions - Part 3
Zigbee / Z-Wave
Fundamentals
Exploitation
- Hacking IoT Devices with Attify Zigbee Framework
- Zigator: Analyzing Security of Zigbee-Enabled Smart Homes
- Security Analysis of Zigbee with Zigator and GNU Radio
- Low-Cost ZigBee Selective Jamming
Tools - Software
Tools - Hardware
LoRa / LoRaWAN
- LoRaWAN Security Overview - Tektelic
- Security Vulnerabilities in LoRaWAN
- Low Powered and High Risk: Attacks on LoRaWAN Devices
- LAF - LoRaWAN Auditing Framework
- ChirpOTLE - LoRaWAN Security Framework
Fundamentals
Exploitation
- Millions of Devices Using LoRaWAN Exposed - SecurityWeek
- Do You Blindly Trust LoRaWAN Networks? - IOActive
- LoRaWAN Encryption Keys Easy to Crack - Threatpost
- LoPT: LoRa Penetration Testing Tool (PDF)
Tools
Matter / Thread
Fundamentals
- Matter Standard - CSA-IoT
- Matter Protocol Wikipedia
- Matter Protocol Complete Guide 2025
- How to Secure Smart Home Devices with Matter
- Smart Home Device Solutions for Matter - DigiCert
Security Research
- Security Vulnerabilities and Attack Scenarios in Smart Home with Matter
- Trust Matters: Uncovering Vulnerabilities in Matter Protocol - Nozomi
- Matter over Thread Security
- State-of-the-Art Review on IoT Wireless PAN Protocol Security
- Matter Smart Home - Krasamo
- Threadbare: Practical Attacks on Thread Networks (Black Hat USA 2024)
- Matter Specification 1.3 - Connectivity Standards Alliance
- Thread Group Security Analysis
Cellular (GSM/LTE/5G)
- Awesome Cellular Hacking
- Introduction to GSM Security
- Breaking LTE on Layer Two
- 5Ghoul - 5G NR Attacks and Fuzzing
- Exploiting CSN.1 Bugs in MediaTek Basebands
- SIM Hijacking
- SigPloit - Telecom Signaling Exploitation Framework
- LTE Sniffer
- 5G NR Jamming, Spoofing and Sniffing
- LTrack: Stealthy Tracking of Mobile Phones in LTE
- Open5GS - Open Source 5G/4G Core
- SCAT - Signaling Collection and Analysis Tool for Cellular
Fundamentals
- GSM Security Part 2
- What is Base Transceiver Station
- Introduction to SS7 Signaling
- SS7 Network Architecture
- Introduction to SIGTRAN
Exploitation
- How to Build Your Own Rogue GSM BTS
- GSM Vulnerabilities with USRP B200
- Security Testing 4G (LTE) Networks
- Case Study of SS7/SIGTRAN Assessment
Tools
NFC/RFID
- Awesome RFID/NFC Security Talks
- RFID Discord Group
- SoK: Security of EMV Contactless Payment Systems
- NFC Relay Attack on Tesla Model Y
DECT (Digital Enhanced Cordless Telecommunications)
- Real Time Interception of DECT Cordless Telephone
- Eavesdropping on Unencrypted DECT Voice Traffic
- Decoding DECT Voice Traffic: In-depth Explanation
Wi-Fi
Protocol Vulnerabilities
- Framing Frames: Bypassing Wi-Fi Encryption by Manipulating Transmit Queues
- Man-in-the-Middle Attacks without Rogue AP: When WPAs Meet ICMP Redirects
- WPAxFuzz: Sniffing Out Vulnerabilities in Wi-Fi Implementations
- Untangling the Knot: Breaking Access Control in Home Wireless Mesh Networks
Exploitation
- Over The Air: Exploiting Broadcom's Wi-Fi Stack (Part 1)
- Over The Air: Exploiting Broadcom's Wi-Fi Stack (Part 2)
- Over The Air: Exploiting The Wi-Fi Stack on Apple Devices
- Reverse-engineering Broadcom wireless chipsets
- Exploiting Qualcomm WLAN and Modem Over the Air
- Windows Wi-Fi Driver RCE Vulnerability - CVE-2024-30078
- When a Wi-Fi SSID Gives You Root on an MT02 Repeater - Part 1
- When a Wi-Fi SSID Gives You Root on an MT02 Repeater - Part 2
Reverse Engineering WiFi
- Reverse Engineering WiFi on RISC-V BL602
- Unveiling secrets of the ESP32: creating an open-source MAC Layer
- Unveiling secrets of the ESP32: reverse engineering RX
USB
UWB (Ultra-Wideband)
TETRA
- All cops are broadcasting: TETRA under scrutiny
- TETRA:BURST - Five Vulnerabilities in TETRA Standard (Midnight Blue)
- TETRA:BURST 2:ELECTRIC BOOGALOO - End-to-End Encryption Broken (BlackHat USA 2025)
- TETRA Decoder - Open Source TETRA Receiver
- Practical TETRA Sniffing with SDR
Firmware Security
Fundamentals
- Introduction to Firmware Analysis - OWASP
- OWASP Firmware Security Testing Methodology
- IoT Security Verification Standard (ISVS)
- Reversing 101
- Hands-on Firmware Extraction, Exploration, and Emulation
Extraction
- Router Analysis Part 1: UART Discovery and SPI Flash Extraction
- Hardware Hacking Tutorial: Dumping and Reversing Firmware
- Firmware Samples - firmware.center
- BasicFUN Series: Hardware Analysis / SPI Flash Extraction
- BasicFUN Series: Reverse Engineering Firmware / Reflashing SPI Flash
- Retrofitting encrypted firmware is a Bad Idea
Static Analysis Tools
- EMBA - Embedded Linux Firmware Analyzer
- FACT - Firmware Analysis and Comparison Tool
- Binwalk v3
- Firmwalker
- fwanalyzer
- fwhunt-scan - UEFI Firmware Analysis
- ByteSweep
- BINSEC
- unblob - Extraction Framework
- Checksec.sh
- Firmware Modification Kit
Dynamic Analysis and Emulation
- Firmadyne - Automated Firmware Emulation
- FirmAE - Firmware Analysis and Emulation
- QEMU
- PANDA - Architecture-Neutral Dynamic Analysis
- Avatar2 - Dynamic Firmware Analysis
- Renode - Embedded Systems Emulator
- Unicorn Engine - CPU Emulator
- Qiling Framework
- HALucinator
- FirmWire - Baseband Firmware Emulation
- SymQEMU
- S2E - Selective Symbolic Execution
- Bochs - x86 Emulator
- SAME70 Emulator
- Emulate Until You Make it
Emulation Tutorials- محاكاة البرامج الثابتة باستخدام QEMU
- محاكاة البرامج الثابتة لموجهات ARM - Azeria Labs
- محاكاة البرامج الثابتة لإنترنت الأشياء بسهولة
- تحليل ومحاكاة ثنائيات إنترنت الأشياء الجزء 1
- التنقيح المتقاطع لـ ARM/MIPS باستخدام QEMU
- QEMU + Buildroot 101
- محاكاة ثغرات البرامج الثابتة واصطيادها باستخدام Qiling
- Qiling ومحاكاة الثنائيات لفك التغليف التلقائي
- تنقيح D-Link: محاكاة البرامج الثابتة واختراق العتاد
- إطار محاكاة تكيفي لإنترنت الأشياء متعدد المعماريات
- محاكاة البرامج الثابتة التلقائية من خلال استنتاج المعرفة الموجه بالصلاحية
- محاكاة معمارية RH850 باستخدام Unicorn Engine
- Icicle: محاكي معاد تصميمه لاختبار البرامج الثابتة بالصندوق الرمادي
- التحديات والمزالق أثناء محاكاة ستة موجهات منزلية آيسلندية حالية
- محاكاتي تذهب إلى القمر... حتى العلم المزيف
- كيفية محاكاة مكتبات Android الأصلية باستخدام Qiling
أمان تحديثات OTA
الأساسيات
- أمان البرامج الثابتة لإنترنت الأشياء وآليات التحديث
- تنفيذ تحديثات OTA لأجهزة إنترنت الأشياء
- سلاسل إقلاع OTA الآمنة والتحقق من البرامج الثابتة
- مفتاح أمان البرامج الثابتة في أجهزة إنترنت الأشياء المتصلة
- اعتبارات الأمان لتحديثات OTA - Stack Overflow
نواقل الهجوم
- أهم 10 ثغرات في إنترنت الأشياء - هجمات تحديث OTA
- تحديث أجهزة إنترنت الأشياء 2025: أفضل الممارسات
- مراجعة ثغرات البرامج الثابتة لإنترنت الأشياء وتقنيات التدقيق
أمان أنظمة التشغيل في الوقت الحقيقي (RTOS)
Zephyr RTOS
- Zephyr RTOS على GitHub
- قائمة ثغرات Zephyr
- تقييم NCC Group الأمني لـ Zephyr و MCUboot
- 26 عيبًا في Zephyr و MCUboot
- معالجة الأمان في Zephyr RTOS
- تعزيز الأمان باستخدام Zephyr RTOS
FreeRTOS
- 13 ثغرة في FreeRTOS في مكدس TCP/IP
- استغلال تلف الذاكرة في FreeRTOS - ShmooCon
- تحليل أمان RTOS - USENIX
- ترقيع الثغرات الديناميكي لـ RTOS
- ثغرات AWS FreeRTOS
أدوات الهندسة العكسية
- Ghidra
- IDA Pro
- Radare2
- Cutter - واجهة رسومية لـ Radare2
- Binary Ninja
- GDB
- RetDec - مفكك الترجمة
- Diaphora - مقارنة الثنائيات
- Angr - تحليل الثنائيات
- Frida - الأدوات الديناميكية
- Ret-sync
- OllyDbg
- x64dbg
- Hopper
- Immunity Debugger
- PEiD
- Ghidriff - محرك مقارنة الثنائيات لـ Ghidra
- مفكك الترجمة rev.ng يصبح مفتوح المصدر
- مقدمة إلى Cutter
- pyghidra-mcp: خادم Ghidra MCP بدون واجهة
- Mindshare: استخدام Binary Ninja API لاكتشاف ثغرات الاستخدام بعد التحرير المحتملة
دروس الهندسة العكسية
- الهندسة العكسية والترقيع باستخدام Ghidra
- الهندسة العكسية باستخدام Ghidra: كسر تشفير البرامج الثابتة
- عكس هندسة البرامج الثابتة باستخدام Radare
- عكس هندسة برامج ESP8266 الثابتة
- أتمتة اكتشاف ثغرات الثنائيات باستخدام Ghidra و Semgrep
- إيجاد الأخطاء في موجه Netgear
دروس Ghidra
- فصل المنقح Ghidra
- Ghidra 101: تمييز نص المؤشر
- Ghidra 101: فك تشفير سلاسل المكدس
- توسيع Ghidra الجزء 1: إعداد بيئة تطوير
- توسيع التنين: إضافة ISA إلى Ghidra
- وحدة Ghidra nanoMIPS ISA
- استنتاج نوع الثنائي في Ghidra
- كتابة وحدة معالج Ghidra
المجمعات عبر الإنترنت
استغلال ARM
- دروس ARM من Azeria Labs
- استغلال ARM لإنترنت الأشياء
- موجه ARM الضعيف (DVAR)
- Exploit Education
- دليل لتجميع ARM64 / AArch64 على Linux
- درس تجميع ARMv8 AArch64/ARM64 الكامل للمبتدئين
- دليل المبتدئين لاستغلال ARM
- سلسلة عكس هندسة واستغلال ARM64 (8ksec) - الأجزاء 1-10
- ذاكرة وترحيل AArch64
- نحن مسلحون بـ ARM لا مزيد من ROP هنا
تحليل الثنائيات
الإقلاع الآمن
التطوير
تجاوزات
- اختراق الإقلاع الآمن لـ ESP32
- اختراق ESP32 للأبد: استخراج مفاتيح تشفير الفلاش والإقلاع الآمن
- تجاوز الإقلاع الآمن لـ ESP32 (CVE-2020-13629)
- Amlogic S905 SoC: تجاوز الإقلاع الآمن
- إفشال الإقلاع الآمن بهجمات الروابط الرمزية
- اختراق الإقلاع الآمن لـ PS4 - Fail0verflow
- ثغرات Dell BIOS - BIOSDisconnect
- ثغرة U-Boot USB DFU (CVE-2022-2347)
- كسر الإقلاع الآمن على Silicon Labs Gecko
أمان UEFI
- استخدام التنفيذ الرمزي لاكتشاف ثغرات UEFI
- ثغرات UEFI في أجهزة HP Enterprise
- محاكاة واستغلال البرامج الثابتة UEFI
- الجانب المظلم لـ UEFI: تحليل تقني معمق للاستغلال عبر الشرائح
- داخل إثبات مفهوم LogoFAIL: من تجاوز الحد الصحيح إلى تنفيذ تعليمات برمجية عشوائية
- PixieFail: تسع ثغرات في مكدس شبكة IPv6 لـ EDK II من Tianocore
- من أجل العلم! - استخدام خطأ غير مبهر في EDK II
- Hydroph0bia: تجاوز SecureBoot لـ Insyde H2O
- PKfail: مفاتيح منصة غير موثوقة في البرامج الثابتة UEFI (Binarly, 2024)
- LogoFAIL: ثغرات تحليل الصور في برامج ثابتة النظام (Binarly)
- تحليل BlackLotus UEFI Bootkit - ESET
- Bootkitty: أول UEFI Bootkit لـ Linux (ESET, 2024)
- جذور خفية في البرامج الثابتة UEFI: الأساطير والواقع (BlackHat 2024)
- CVE-2024-0762 - متابعة PixieFail تجاوز TPM
هجمات الروابط الرمزية
تحليل البرامج الثابتة للموجهات
- رحلة إلى إنترنت الأشياء: اكتشاف المكونات والمنافذ
- رحلة إلى إنترنت الأشياء: استخراج البرامج الثابتة وتحليلها
- رحلة إلى إنترنت الأشياء: الاتصالات اللاسلكية
- رحلة إلى إنترنت الأشياء: الاتصالات الداخلية
- التحليل الديناميكي لمكونات البرامج الثابتة في أجهزة إنترنت الأشياء
- تحليل البرامج الثابتة RV130X
- فك تشفير البرامج الثابتة لـ TP-Link C210 V2 محملات إقلاع كاميرا سحابية
استغلال الموجهات
- البحث عن ثغرات n-days غير مصادق عليها في موجهات Asus
- إبراز MikroTik في دائرة الضوء
- استغلال عتاد MikroTik RouterOS باستخدام CVE-2023-30799
- الحصول على صلاحيات الجذر في موجهات Xiaomi WiFi
- الطريق إلى الأمان: التنقل في مزالق الموجهات
- ROPing our way to RCE
- ROPing Routers من الصفر: Tenda Ac8v4
- PwnAgent: تنفيذ تعليمات برمجية عن بُعد من جانب WAN بنقرة واحدة في موجهات Netgear RAX
- Puckungfu 2: حقن أوامر آخر من جانب WAN في NETGEAR
- عكس هندسة واكتشاف واستغلال ثغرة في موجه TP-Link - CVE-2024-54887
- استغلال ثغرة يوم الصفر (CVE-2025-9961) في موجه TP-Link AX10
- FiberGateway GR241AG - سلسلة استغلال كاملة
- اختبار الصندوق الأسود لأجهزة إنترنت الأشياء باستخدام الموجه TL-WR902AC
- الحصول على صلاحيات الجذر في TP-Link Tapo C200 Rev.5
سلسلة Netgear
- Netgear Orbi: مقدمة، الوصول إلى UART، الاستطلاع
- Netgear Orbi: أعطال في SOAP-API
- Netgear Orbi: استغلال NDay CVE-2020-27861
- الأنفاس الأخيرة لأخطاء Netgear RAX30 لدينا
سلسلة TP-Link
- ثغرة تجاوز سعة المخزن المؤقت في TP-Link TDDP
- Pwn2Own Tokyo 2020: إفشال TP-Link AC1750
- تنفيذ تعليمات برمجية عن بُعد غير مصادق عليه في كاميرا TP-Link Tapo c200 (CVE-2021-4045)
سلسلة Cisco
- مقارنة ترقيع تحديث البرامج الثابتة لـ Cisco RV110W - الجزء 1
- CVE-2024-20356: كسر حماية جهاز Cisco لتشغيل DOOM
- Flashback Connects - تنفيذ تعليمات برمجية عن بُعد عبر Cisco RV340 SSL VPN
تجاوزات الإقلاع الآمن
- تجاوز الإقلاع الآمن باستخدام حقن الأخطاء
- كسر الإقلاع الآمن على Google Nest Hub (الجيل الثاني)
- الإقلاع نحو الاختراقات: اصطياد أسطح الهجوم عن بُعد في Windows SecureBoot
بروتوكولات الشبكة والويب
MQTT
- مقدمة إلى MQTT
- أساسيات أمان وسيط MQTT
- اختراق إنترنت الأشياء باستخدام MQTT
- أمان إنترنت الأشياء: تنفيذ تعليمات برمجية عن بُعد في بروتوكول MQTT
- IoXY - وسيط اعتراض MQTT
- MQTT-PWN
الأساسيات
الأمان والاستغلال
- هل المنازل الذكية عرضة للاختراق؟
- اختبار اختراق قفل الباب الذكي Sesame
- Servisnet Tessa - استخراج بيانات اعتماد MQTT (Metasploit)
- مسار خدمة غير محاط بعلامات اقتباس في Eclipse Mosquitto
ثغرات CVE المعروفة
- CVE-2020-13849 - ثغرة حجب الخدمة (CVSS 7.5)
- CVE-2023-3028 - مصادقة غير كافية (CVSS 9.8)
- CVE-2021-0229 - استهلاك الموارد (CVSS 5.3)
- CVE-2019-5432 - انهيار بسبب حزمة مشوهة (CVSS 7.5)
الأدوات
- Mosquitto - وسيط MQTT مفتوح المصدر
- HiveMQ
- MQTT Explorer
- MQTT Topic ACL Linter - تحليل ثابت محلي فقط لقواعد ACL لمرشحات مواضيع MQTT غير الصالحة والواسعة والمكررة والمتداخلة؛ لا يتصل بوسيط ولا يحل محل تدقيق أمني.
- مكتبة Nmap MQTT
- أفضل سبع أدوات عميل MQTT
التطبيقات- Using IoT MQTT for V2V and Connected Cars
- MQTT Hardware Development Projects
- 100,000 Connected Cars with Kubernetes, Kafka, MQTT, TensorFlow
- Authenticating Devices Using MQTT with Auth0
- Deep Learning UDF for MQTT IoT Anomaly Detection
- Guide to MQTT: Hacking a Doorbell
أبحاث البرمجيات الخبيثة
CoAP
المواصفات والأمان
الأدوات - البرمجيات
- CoAP NSE (Nmap)
- Copper4Cr - CoAP User-Agent for Chrome
- libcoap CLI Tools
- Scapy CoAP Plugin
- Eclipse Californium (Java)
- Peach Fuzzer
الأدوات - العتاد
الأبحاث والدروس التعليمية
mTLS
الأدوات
| الأداة | الاستخدام | الرابط | | ───────────────────────── | ─────────────────────────────────────────────────────────────────────────────────────────────── | ──────────────────────────────────────────────────────────────────────────────────────────────────────── | | mtls-intercept | Reverse proxy that dynamically signs client certs to MITM full mTLS sessions | github.com/fungaren/mtls-intercept | | mitmproxy | Configure client_certs with extracted IoT device cert to impersonate device in mTLS handshake | mitmproxy.org | | SSLsplit | Transparent mTLS proxy - forward extracted device cert to complete mutual handshake with cloud | github.com/droe/sslsplit | | eCapture (eBPF) | Hook OpenSSL/BoringSSL on Linux IoT gateways pre-encrypt - decrypts mTLS + TLS 1.3 + PFS | ecapture.cc | | Wireshark + SSLKEYLOGFILE | Decrypt captured mTLS sessions from IoT gateways using NSS pre-master secret logs | wiki.wireshark.org/TLS | | Frida | Runtime hook SSLContext, TrustManager, KeyManager in Android IoT companion apps | frida.re | | Objection | Android sslpinning disable - strips mTLS pinning in companion apps | github.com/sensepost/objection | | apk-mitm | Statically patches IoT companion APK to disable mTLS cert pinning | github.com/shroudedcode/apk-mitm | | MagiskTrustUserCerts | Moves custom CA to system store on rooted Android POS/kiosk to complete mTLS MITM | github.com/NVISOsecurity/MagiskTrustUserCerts | | frida-multiple-unpinning | Universal Frida script targeting 20+ mTLS/pinning patterns in hardened IoT apps | github.com/httptoolkit/frida-android-unpinning | | NEU-SNS/IoTLS | IMC'21 research repo - SSLKEYLOGFILE files to decrypt MITM'd mTLS connections across 32 devices | github.com/NEU-SNS/IoTLS | | mitmrouter | Linux-based IoT traffic interception router - intercepts device TLS at network level | github.com/nmatt0/mitmrouter |
المدونات والمقالات
- mTLS: When Certificate Authentication is Done Wrong
- mTLS Authentication in IoT: Enhancing Security for Connected Devices
- Hands On IoT MitM Part 1 - AWS IoT MQTT + mTLS Interception
- OWASP MASTG-TECH-0012: Bypassing Certificate Pinning in Android IoT Companion Apps
- Theory to Practice: mTLS in Action Part 1
- Configuring mTLS on Mosquitto MQTT Broker
- AWS IoT Docs: X.509 Client Certificates and Fleet Provisioning
- Azure IoT Hub: mTLS X.509 CA Authentication Concept
الأوراق البحثية
- Evaluation of TLS and mTLS in Internet of Things Systems - MIUN DiVA, 2024
- Atlas: Enabling Cross-Vendor mTLS Authentication for IoT - arXiv 2025
- Lightweight mTLS Authentication for Industrial IoT - PMC/NIH 2023
- Quantum-Enhanced mTLS for IoT Battlefield Networks - IJPSAT
- AI vs. IoT Security: Fingerprinting and Defenses Against TLS Attacks - IEEE Xplore 2025
يوتيوب
- Intercepting IoT Device Traffic with ARP Poisoning + mitmproxy TLS Intercept
- Using Linux to Intercept IoT Device Traffic with mitmrouter
- Mutual TLS - The Backend Engineering Show Deep Dive
- Intercepting SSL/TLS - Fiddler and MITMProxy Decrypt Walkthrough
- Decrypting Kubernetes mTLS Traffic - eCapture, Custom CA, eBPF Methods
- Mastering mTLS: Stop MITM Attacks and Boost API/IoT Security
- Introduction to IoT Penetration Testing Webinar - CyberWarFare Labs
نظرة عامة على بروتوكولات إنترنت الأشياء
- IoT Protocols Overview
- IoT Architecture
- Attacking IoT Devices from Web Perspective
- Awesome Industrial Protocols
أمان السحابة والأنظمة الخلفية
أمان AWS IoT
الأساسيات
- Comprehensive AWS Pentesting Guide - BreachLock
- AWS Pentest Methodology - MorattiSec
- AWS Penetration Testing Methodology - Rootshell
- AWS Penetration Testing Techniques 2025
الأدوات
- CloudFox - Cloud Attack Paths
- S3Scanner - Leaky Bucket Discovery
- Cloudfoxable Labs
- AWS Security Pentesting Resources
- Pacu - AWS Exploitation Framework
- ScoutSuite - Multi-cloud Security Auditing
- Prowler - Cloud Security Assessment
الثغرات الأمنية
Firebase / أخطاء إعداد السحابة
أمان تطبيقات الهواتف المحمولة
أندرويد
- Android App Reverse Engineering 101
- Android Application Pentesting Book
- Android Pentest Video Course - TutorialsPoint
- Android Tamer
- Android Hacker's Handbook
- A first look at Android 14 forensics
- Deobfuscating Android ARM64 strings with Ghidra
- Introduction to Fuzzing Android Native Components
- Hacking Android Games
- Intercepting HTTPS Communication in Flutter
استغلال نواة أندرويد
- Android Kernel Exploitation
- Attacking Android Binder: Analysis and Exploitation of CVE-2023-20938
- Attacking the Android kernel using the Qualcomm TrustZone
- Driving forward in Android drivers
- Analyzing a Modern In-the-wild Android Exploit
- Exploiting Android's Hardened Memory Allocator
- GPUAF - Two ways of Rooting All Qualcomm based Android phones
- The Qualcomm DSP Driver - Unexpectedly Excavating an Exploit
- Qualcomm DSP Kernel Internals
- Binder Fuzzing
مخصص الذاكرة Scudo في أندرويد
- Android: Scudo
- Behind the Shield: Unmasking Scudo's Defenses
- scudo Hardened Allocator - Unofficial Internals Documentation
iOS
- iOS Pentesting Guide
- OWASP Mobile Security Testing Guide
- An iOS hacker tries Android
- Analyzing iOS Kernel Panic Logs
- Blasting Past iOS 18
- Emulating an iPhone in QEMU
- First analysis of Apple's USB Restricted Mode bypass (CVE-2025-24200)
- Exploring UNIX pipes for iOS kernel exploit primitives
الأنظمة الصناعية والسيارات
ICS/SCADA
- ICS Village
- ICS Discord Group
- Controlthings.io Platform
- Applied Cyber Security and the Smart Grid
- Deep Lateral Movement in OT Networks
- Hacking ICS Historians: The Pivot Point from IT to OT
- OPC UA Deep Dive Series - Parts 1-5
- Inside a New OT/IoT Cyberweapon: IOCONTROL
- Attention, High Voltage: Exploring the Attack Surface of the Rockwell Automation PowerMonitor 1000
أمان السيارات
- Awesome Vehicle Security
- Car Hacking Village
- Jeep Hack
- Subaru Head Unit Jailbreak
- Car Hacking Practical Guide 101
- CAN Injection: keyless car theft
- How I Hacked my Car Series - Parts 1-6
- How I Also Hacked my Car
- Extracting Secure Onboard Communication (SecOC) keys from a 2021 Toyota RAV4 Prime
- Recovering an ECU firmware using disassembler and branches
- Automotive Memory Protection Units: Uncovering Hidden Vulnerabilities
- Web Hackers vs The Auto Industry: Critical Vulnerabilities in Cars (Sam Curry, 2023)
- Hacking Kia: Remotely Controlling Cars With Just a License Plate (Sam Curry, 2024)
- Hacking Subaru: Tracking and Controlling Cars via the STARLINK Admin Panel (Sam Curry, 2025)
- Pwn2Own Automotive (ZDI Blog Category - 2024 & 2025 Tokyo)
- Synacktiv Publications - Pwn2Own Automotive Writeups
- Awesome CAN Bus - Curated Resources
شواحن السيارات الكهربائية
- A Detailed Look at Pwn2own Automotive EV Charger Hardware
- Pwn2Own Automotive 2024: Hacking the ChargePoint Home Flex
- Reverse engineering an EV charger
- Pwn2Own Automotive 2024: Autel MaxiCharger Analysis (Computest Sector7)
- SaiFlow Blog - OCPP/EV Charging Protocol Vulnerabilities
أنظمة الدفع
اختراق أجهزة الصراف الآلي
- Introduction to ATM Penetration Testing
- Pwning ATMs for Fun and Profit
- Jackpotting ATMs Redux - Barnaby Jack
- Root Shell on Credit Card Terminal
Payment Village
الأدوات
أدوات العتاد
- Bus Pirate
- Bus Pirate 5: The Swiss ARRRmy Knife of Hardware Hacking
- The Shikra
- Attify Badge
- Flipper Zero
- HackRF
- RTL-SDR
- An In-Depth Look at the ICE-V Wireless FPGA Development Board
متعددة الأغراض
محولات التنقيح- ST-Link
USB
- FaceDancer21
- RfCat
- NullSec Ducky Payloads - مجموعة حمولات Rubber Ducky BadUSB لأنظمة Windows وmacOS وLinux.
Flipper Zero
- NullSec Flipper Suite - مجموعة حمولات Flipper Zero لاختبار اختراق RF وRFID/NFC وBadUSB والأشعة تحت الحمراء واللاسلكي.
- PineFlip - تطبيق مرافق لـ Flipper Zero على Linux مع عكس الشاشة ومدير الملفات وإدارة البرامج الثابتة.
Hak5
- Hak5 Field Kits
- NullSec Pineapple Suite - مجموعة حمولات WiFi Pineapple لـ deauth وevil twin والتقاط handshake واستطلاع الشبكة.
أدوات البرمجيات
أطر الاستغلال
- BlueSploit
- IoTSecFuzz
- PENIOT
- ISF - Industrial Security Framework
- HAL - Hardware Analyzer
- PRET - Printer Exploitation Toolkit
- Expliot Framework
- RouterSploit
- HomePwn
- Firmware Analysis Toolkit (FAT)
- Shambles: The Next-Generation IoT Reverse Engineering Tool
تحليل البرامج الثابتة
أدوات Fuzzing
- The art of Fuzzing: Introduction
- A LibAFL Introductory Workshop
- The Blitz Tutorial Lab on Fuzzing with AFL++
- State of Linux Snapshot Fuzzing
- Fuzzing between the lines in popular barcode software
- Boofuzz
- Syzkaller - Kernel Fuzzer
- parking-game-fuzzer
الأساسيات
Fuzzing الخاص بإنترنت الأشياء
- Fuzzing ICS Protocols
- Fuzzowski - Network Protocol Fuzzer
- FIRM-AFL: High-Throughput IoT Firmware Fuzzing
- Snipuzz: Black-box Fuzzing of IoT Firmware
- Fuzzing IoT Binaries Part 1
- Fuzzing IoT Binaries Part 2
- Awesome Embedded Fuzzing
الأدوات
أنظمة تشغيل اختبار الاختراق
- AttifyOS
- IoT Penetration Testing OS v1
- EmbedOS
- Sigint OS - LTE IMSI Catcher
- Instant GNU Radio OS
- Dragon OS - SDR Software
- Skywave Linux - SDR
- Zephyr RTOS
- Ubuntu LTS
محركات البحث
- Shodan
- Censys
- ZoomEye
- BinaryEdge
- Thingful
- Wigle
- Hunter.io
- BuiltWith
- Recon-ng
- PublicWWW
- FCC ID Database
- CVE PoC Search - ابحث في مستودعات PoC العامة على GitHub حسب معرّف CVE.
الأمن الدفاعي
نمذجة التهديدات
- STRIDE Threat Model Guide - Practical DevSecOps
- OWASP Threat Modeling Process
- STRIDE-based Threat Modeling for IoT Precision Agriculture
إطار STRIDE
- What is STRIDE in Threat Modeling - Security Compass
- Threat Modeling with ATT&CK - MITRE
- What is Threat Modeling - Fortinet
نمذجة التهديدات الخاصة بإنترنت الأشياء
- STRIDE Threat Modeling for IoT Smart Home
- STRIDE Threat Modeling for Smart Solar Energy Systems
- STRIDE Threat Modeling for IoT Healthcare Systems
- STRIDE for IoT Agriculture - IEEE
التطوير الآمن
- Compiler Options Hardening Guide for C and C++
- Linux Hardening Guide
- Docker Security - Step-by-Step Hardening
- How To Secure A Linux Server
الإرشادات والمعايير
- NIST IoT Cybersecurity Framework
- NIST SP 800-213 - IoT Device Cybersecurity Guidance
- NISTIR 8259 - Foundational Cybersecurity Activities for IoT Manufacturers
- ETSI EN 303 645 - Cyber Security for Consumer IoT
- OWASP IoT Top 10 (2018)
- OWASP IoT Project
أدلة التحصين
الاستجابة للحوادث
موارد التعلم
منصات التدريب
أوراق الغش
- Hardware Hacking Cheatsheet
- Nmap Tutorial
- Pentest Hardware Handbook
- THC's favourite Tips, Tricks & Hacks
- Cross Cache Attack CheetSheet
أدلة الثغرات
- OWASP IoT Top 10 2018 Mapping
- Reflecting on OWASP IoT Top 10
- CVE North Stars
- IoT Vulnerabilities with CVE and PoC
- Linux Privilege Escalation
أدلة اختبار الاختراق
- Shodan Pentesting Guide
- Modern Vulnerability Research on Embedded Systems
- Awesome Embedded Systems Vulnerability Research
قنوات YouTube
- Joe Grand
- LiveOverflow
- Binary Adventure
- EEVBlog
- Craig Smith
- IoTSecurity101
- Besim ALTINOK
- Ghidra Ninja
- Cyber Gibbons
- Scanline
- Aaron Christophel
- Valerio Di Giampietro
- Gamozo Labs - Printer Hacking
الكتب
اختراق الأجهزة
- The Hardware Hacking Handbook - Jasper van Woudenberg & Colin O'Flynn (2021)
- Practical Hardware Pentesting - Jean-Georges Valle (2021)
- Practical Hardware Pentesting 2nd Edition (2023)
- Hardware Hacking: Have Fun While Voiding Your Warranty - Joe Grand (2004)
- Hacking the Xbox - Andrew "bunnie" Huang (2013)
- The Hardware Hacker - Andrew "bunnie" Huang (2019)
- The Art of PCB Reverse Engineering - Keng Tiong (2015)
- Manual PCB-RE: The Essentials - Keng Tiong (2021)
- Hardware Security Training, Hands-on! (2023)
- Hardware Security: Challenges and Solutions (2025)
- Mastering Hardware Hacking (2025)
- Ultimate Hardware Hacking Gear Guide
- Microcontroller Exploits (2024)
- Engineering Secure Devices - Dominik Merli (2024)
- Cryptography and Embedded Systems Security - Hou & Breier (2024)
البرامج الثابتة والهندسة العكسية
- The Firmware Handbook - Jack Ganssle (2004)
- Learning Linux Binary Analysis - Ryan O'Neill (2016)
- Fuzzing Against the Machine (2023)
- Rootkits and Bootkits - Matrosov, Rodionov, Bratus (2019)
- Ghidra Software Reverse Engineering 2nd Edition (2025)
- The Ghidra Book 2nd Edition - Nance & Eagle (2026)
- The Definitive Handbook on Reverse Engineering Tools (2025)
- x86 Software Reverse-Engineering, Cracking, and Counter-Measures - Domas & Domas (2024)
- Fuzzing Android - Zawawy, Rodionov et al. (2026)
- From Day Zero to Zero Day - Eugene Lim (2025)
- The Spacecraft Hacker's Handbook - Olchawa & Starcik (2026)
أمن إنترنت الأشياء
- Abusing the Internet of Things - Nitesh Dhanjani (2015)
- IoT Penetration Testing Cookbook - Aaron Guzman & Aditya Gupta (2017)
- Practical IoT Hacking: The Definitive Guide (2021)
- PatrIoT: Practical and Agile Threat Research for IoT (2022)
- The Embedded Linux Security Handbook - St. Onge & Krishnan (2025)
- Securing Smart Things - Massimo Nardone (2026)
اللاسلكي وRF
- Inside Radio: An Attack and Defense Guide - Qing Yang, Lin Huang (2018)
- Hack the Airwaves: Advanced BLE Exploitation (2023)
- Practical SDR - David Clark & Paul Clark (2025)
- The Art of ARM Assembly, Volume 1 - Randall Hyde (2025)
- The Wireless Cookbook - Bill Zimmerman (2026)
الأنظمة المدمجة والجوالة
NFC/RFID
- Near Field Communication (NFC): From Theory to Practice (2012)
- Security Issues in Mobile NFC Devices - Michael Roland (2024)
أمن السيارات
- The Car Hacker's Handbook - Craig Smith (2016)
- Building Secure Automotive IoT Applications - Oka et al. (2024)
- Offensive Automotive Cybersecurity - Nasser & Oka (2025)
الأمن الصناعي والعام
- Gray Hat Hacking 5th Edition (2018)
- Black Hat Python 2nd Edition (2021)
- Attacking Network Protocols - James Forshaw (2017)
- Securing Industrial Control Systems - Rahman et al. (2026)
الأوراق البيضاء والتقارير
سلسلة إنترنت الأشياء
المختبرات وCTFs
التطبيقات القابلة للاستغلال
- DVID - Damn Vulnerable IoT Device
- IoTGoat - Vulnerable OpenWrt Firmware
- BLE CTF
- Microcorruption
- ARM-X CTF
الأجهزة
الصناعي
VoIP
مسابقات CTF
تحديات CTF للأجهزة
تحديات CTF لإنترنت الأشياء
تحديات CTF للأنظمة المدمجة/البرامج الثابتة
تحديات CTF لـ ARM
منصات التعلم المستمر
إعداد المختبر
البحث والمجتمع
البحث التقني
- Dropcam Hacking
- LED Light Hacking
- PS4 Jailbreak Status
- Lenovo Watch X Privacy Issues
- Smart Scale Privacy Issues
- Besder IP Camera Security Analysis
المدونات- Team82 Research
- Voidstarsec
- wrongbaud
- Firmware Analysis
- Exploitee.rs
- Payatu Blog
- Raelize Blog
- JCJC Dev
- W00tsec
- Devttys0
- Embedded Bits
- Keenlab
- Courk.cc
- IoT Security Wiki
- Cybergibbons
- Firmware.RE
- K3170makan
- Tclaverie
- Besimaltinok
- Ctrlu
- IoT Pentest
- Duo Decipher
- Sp3ctr3
- 0x42424242
- Dantheiotman
- Danman
- Quentinkaiser
- Quarkslab
- Ice9
- F-Secure Labs
- MG.lol
- CJHackerz
- Bunnie's Blog
- Synacktiv Publications
- Cr4.sh
- Ktln2
- Naehrdine
- Limited Results
- Fail0verflow
- Exploit Security
- Attify Blog
- Jilles.com
- Syss Tech Blog
- HardBreak Wiki
- 8ksec
- Starlabs
- boschko.ca
- 0xtriboulet
- Nozomi Networks
منصات المجتمع
Villages
باحثون للمتابعة
- Jilles
- Joe Fitz
- Aseem Jakhar
- Cybergibbons
- Jasper
- Dave Jones
- bunnie
- Ilya Shaposhnikov
- Mark C.
- Aaron Guzman
- Yashin Mehaboobe
- Arun Magesh
- Mr-IoT
- QKaiser
- 9lyph
أبحاث خاصة بالأجهزة
الكاميرات
- ARLO: I'M WATCHING YOU
- Hacking a Tapo TC60 Camera
- Rooting a Hive Camera
- Pwn2Own: Synology BC500 IP Camera
- Turning Camera Surveillance on its Axis
- Pwn2Own Ireland 2024 - Ubiquiti AI Bullet
أجهزة المنزل الذكي
- Hacking a Smart Home Device
- The Silent Spy Among Us: Smart Intercom Attacks
- Pwnassistant - Home Assistant RCE
- Hacking Sonoff Smart Home IoT Device
مكبرات الصوت الذكية
- Turning Google smart speakers into wiretaps for $100k
- Smart Speaker Shenanigans: Making the Sonos ONE Sing its Secrets
- Listen Up: Sonos Over-The-Air Remote Kernel Exploitation and Covert Wiretap
- Streaming Zero-Fi Shells to Your Smart Speaker
الطابعات
- Pwning a Brother labelmaker, for fun and interop!
- lexmark printer haxx
- Pwn2Own Ireland 2024: Canon imageCLASS MF656Cdw
- Print Scan Hacks: Brother devices
الطائرات بدون طيار
- DJI Mavic 3 Drone Research: Firmware Analysis
- DJI Mavic 3 Drone Research: Vulnerability Analysis
- DJI - The ART of obfuscation
- Local Privilege Escalation on the DJI RM500 Smart Controller
أجهزة المطبخ
أجهزة NAS
- A Pain in the NAS: Synology DS920+ Edition
- Weekend Destroyer - RCE in Western Digital PR4100 NAS
- Exploiting the Synology TC500 at Pwn2Own Ireland 2024
أجهزة الألعاب
- Hacking the Nintendo DSi Browser
- mast1c0re: Exploiting the PS4 and PS5 through a game save
- Being Overlord on the Steam Deck with 1 Byte
- Hacking the XBox 360 Hypervisor
الهواتف/الأجهزة اللوحية
- Pixel 6 Bootloader Series
- Solo: A Pixel 6 Pro Story
- Gaining kernel code execution on an MTE-enabled Pixel 8
- Bypassing MTE with CVE-2025-0072
- Debugging the Pixel 8 kernel via KGDB
- A First Glimpse of the Starlink User Terminal
- Diving into Starlink's User Terminal Firmware
أبحاث TrustZone و TEE
- ARM TrustZone: pivoting to the secure world
- TEE Reversing
- A Deep Dive into Samsung's TrustZone - Parts 1-3
- Researching Xiaomi's TEE
- Kinibi TEE: Trusted Application Exploitation
- Reversing Samsung's H-Arx Hypervisor Framework
- EL3vated Privileges: Glitching Google WiFi Pro from Root to EL3
أبحاث Pwn2Own
- Your not so "Home Office" - SOHO Hacking at Pwn2Own
- Pwn2Own Toronto 2023 Series - Parts 1-5
- Pwn2Own: WAN-to-LAN Exploit Showcase
MCP / AI Agent
هندسة عكسية للبلوتوث
- bt-re-mad-skillz - مهارات LLM لهندسة عكسية لبرامج ثابتة لوحدة تحكم البلوتوث على طبقة HCI، لـ Claude Code و ChatGPT/Codex.
المساهمة
المساهمات مرحب بها. أرسل PR مع موارد جديدة تتبع البنية الموجودة.