Patch Wemo “FriendlyName” with OFRAK & Win Prizes
Wemo doesn’t want to patch the “FriendlyName” vulnerability. Not cool! Can you help us try to patch it??
Here are five (5) fun challenges to help you get familiar with OFRAK, a binary reverse engineering and modification framework. Ask questions in person or via Wemo IRC!
| Challenge | Description | “Flag” | What You’ll Need to Start |
|---|---|---|---|
| Get the firmware! | Rip it from the app or dump from flash! | Firmware hash | Initiative! Either the app or the smart plug hardware |
| Get that binary! | Use OFRAK GUI to find wemo_ctrl |
Hash of binary in OFRAK GUI | Smart plug firmware |
| Patch that binary! | Try to patch “FriendlyName” with OFRAK! | Show us your script (and modified binary). Extra points if patch works! | wemo_ctrl |
| Get root! | Get UART, get root! | Show us your shell and plugin_key from NVRAM | Smart plug hardware |
| Write some code! | Write OFRAK Wemo firmware unpacker/packer based on /sbin/firmware_update.sh |
Show us your components | Firmware and some skills |
Binaries for doing the challenges in any order:
- Challenge 1 –
wemo.apk - Challenge 2 –
flash.bin - Challenge 3 –
wemo_ctrl - Challenge 5 –
firmware_update.sh
Each challenge has a different password. If you're at Summercon 2023, come by and ask us for access!