Talk With an Expert

SANS 2025: SANS@Night - SBOMs the Hard Way: Hacking Bob the Minion

  • Wed, Apr 16, 2025
  • 6:00PM - 7:00PM UTC
  • English
  • Larry Pesce
  • Technical Presentation
Webcast Hero

This presentation delves into the intricate process of generating a Software Bill of Materials (SBOM) for the Bob the Minions WiFi router by Davolink—a device whose firmware isn't publicly available. Traditional SBOM creation methods rely on readily accessible firmware, but Davolink's restricted release policies necessitated an unconventional approach.

This talk covers the step-by-step journey of hardware disassembly, firmware extraction via SPI flash and JTAG/SWD interfaces, and the tools and techniques employed. Finally, we'll demonstrate how the recovered firmware is used to generate a comprehensive SBOM, highlighting any security vulnerabilities discovered and reported to the vendor.

This session aims to provide attendees with practical insights into overcoming SBOM generation challenges in the IoT domain through hands-on hardware hacking, and leveraging the firmware and SBOMs for vulnerability discovery, as well as security improvement.

Meet the speaker

Larry Pesce
Larry Pesce

Larry Pesce

Vice President of Services

Larry has revolutionized embedded device security with decades of hands-on offensive research, co-authoring SANS's flagship wireless and IoT penetration testing courses, and pioneering SBOM exploitation techniques for supply chain defense strategies.

Read more about Larry Pesce