{"id":11758,"date":"2023-03-20T08:31:53","date_gmt":"2023-03-20T08:31:53","guid":{"rendered":"https:\/\/conference.hitb.org\/hitbincyber2024\/product\/teepwn-breaking-tees-by-experience-hitb2023hkt\/"},"modified":"2023-03-27T05:38:29","modified_gmt":"2023-03-27T05:38:29","slug":"teepwn-breaking-tees-by-experience-hitb2023hkt","status":"publish","type":"product","link":"https:\/\/conference.hitb.org\/hitbincyber2024\/product\/teepwn-breaking-tees-by-experience-hitb2023hkt\/","title":{"rendered":"TEEPwn: Breaking TEEs by Experience"},"content":{"rendered":"<p>&nbsp;<\/p>\n<hr \/>\n<div class=\"page\" title=\"Page 3\">\n<div class=\"layoutArea\">\n<h5>This 4-day TEEPwn course is one of two Raelize&#8217;s Pwn training courses. The other is BOOTPwn which is being held in Amsterdam on April 2023. <span style=\"color: #993300\"><em>To find out more about this April&#8217;s 4-day BOOTPwn course, <strong><a href=\"https:\/\/sectrain.hitb.org\/courses\/bootpwn-breaking-secure-boot-by-experience-hitb2023ams\/\">click here.<\/a><br \/>\n<\/strong><\/em><\/span><\/h5>\n<div>\n<hr \/>\n<\/div>\n<\/div>\n<\/div>\n<div class=\"page\" title=\"Page 3\">\n<div class=\"layoutArea\">\n<div class=\"page\" title=\"Page 3\">\n<div class=\"page\" title=\"Page 3\">\n<h4><strong><span style=\"color: #993300\">ATTEND IN-PERSON<\/span>: Onsite in Phuket<\/strong><\/h4>\n<h4><strong>DATE: 21-24 August 2023<\/strong><\/h4>\n<\/div>\n<h4><strong>TIME: 09:00 to 17:00 ICT\/GMT+7<\/strong><\/h4>\n<table style=\"height: 146px\" width=\"599\">\n<tbody>\n<tr>\n<td><strong>Date<\/strong><\/td>\n<td><strong>Day<\/strong><\/td>\n<td style=\"text-align: left\"><strong>Time<\/strong><\/td>\n<td><strong>Duration<\/strong><\/td>\n<\/tr>\n<tr>\n<td>21 Aug<\/td>\n<td>Monday<\/td>\n<td>0900-17:00 ICT\/GMT+7<\/td>\n<td>8 Hours<\/td>\n<\/tr>\n<tr>\n<td>22 Aug<\/td>\n<td>Tuesday<\/td>\n<td>0900-17:00 ICT\/GMT+7<\/td>\n<td>8 Hours<\/td>\n<\/tr>\n<tr>\n<td>23 Aug<\/td>\n<td>Wednesday<\/td>\n<td>0900-17:00 ICT\/GMT+7<\/td>\n<td>8 Hours<\/td>\n<\/tr>\n<tr>\n<td>24 Aug<\/td>\n<td>Thursday<\/td>\n<td>0900-17:00 ICT\/GMT+7<\/td>\n<td>8 Hours<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<h4><strong><span style=\"color: #993300\">Please note:<\/span><\/strong><\/h4>\n<\/div>\n<\/div>\n<p>The 4<sup>th<\/sup> day is an optional day, which may be used by the attendees to complete the left-over exercises. During this day, only online support is available via Discord. No in-person presence is available from the trainers nor required by the attendees.<\/p>\n<hr \/>\n<p>&nbsp;<\/p>\n<h5>It&#8217;s notoriously hard to secure a Trusted Execution Environment (TEE) due to the interaction between complex hardware and a large trusted code base (TCB). The security provided by TEEs has been broken on a wide variety of devices, including mobile phones, smart TVs and even vehicles. Publicly disclosed TEE vulnerabilities were often exploited directly from the less-trusted Rich Execution Environment (REE). Many of these vulnerabilities were speandcific for TEEs and required novel exploitation techniques.<\/h5>\n<p>The TEEPwn experience provides an offensive system-level perspective and dives into the darker corners of TEE Security. It is designed with a system-level approach, where you will experience powerful exploitation of TEE vulnerabilities. The TEEPwn experience is hands-on, gamified and driven by an exciting jeopardy-style Capture the Flag (CTF).<\/p>\n<p>Your journey starts by achieving a comprehensive understanding of TEEs, where you will learn how hardware and software concur to enforce effective security boundaries. You will then use this understanding for identifying interesting vulnerabilities across the entire TEE attack surface. You will then be challenged along the path to exploit them in multiple scenarios. All vulnerabilities are identified and exploited on our emulated attack platform which implements an ARMv8 (64-bit) TEE based on ARM TrustZone.<\/p>\n<p>You will take on different roles, as an attacker in control of:<\/p>\n<ul>\n<li>the REE, attempting to achieve privileged code execution in the TEE.<\/li>\n<li>the REE, trying to access assess protected by a Trusted Application (TA).<\/li>\n<li>a TA, aiming to escalate privileges to TEE OS.<\/li>\n<li>a TA, accessing the protected assets of other TAs.<\/li>\n<\/ul>\n<p>TEEPwn will guide you into an unexpected range of attack vectors and TEE-specific exploitation techniques, which may be leveraged for novel and creative software exploits. refining your skills to a new level.<\/p>\n<p>&nbsp;<\/p>\n<div class=\"page\" title=\"Page 4\">\n<div class=\"layoutArea\">\n<div class=\"column\">\n<p>&nbsp;<\/p>\n<p><strong>Deliverables<\/strong><\/p>\n<p>During the training we will provide you with the following:<\/p>\n<ul>\n<li>cloud-based virtual machine with all the required tooling installed<\/li>\n<li>access to the exercise modules and instructions<\/li>\n<li>walk through videos for the hands-on exercises<\/li>\n<\/ul>\n<p>We will also provide you the following in order to continue with the exercises after the training:<\/p>\n<ul>\n<li>offline virtual machine with all tooling preinstalled<\/li>\n<li>ability to copy the exercise modules and instructions<\/li>\n<li>ability to run the exercise modules forever<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong>Format<\/strong><\/p>\n<p>This <strong>TEEPwn experience<\/strong> will be given in a <u>hybrid format<\/u> where attendees are able to join in-person and online at the same time. Attendees need to select the desired format before the start of the training.<\/p>\n<ul>\n<li><strong>Option1:<\/strong> The <u>in-person format<\/u> requires attendees to join us on-site in Singapore for 3 days full of lectures and practical exercises. The lectures and support are provided in-person using a classroom setting.<\/li>\n<li><strong>Option 2:<\/strong> The <u>online format<\/u> requires attendees to join us online for 3 days full of lectures and practical exercises. The lectures from the in-person classroom are virtually streamed using Zoom. Support is provided virtually via Discord.<\/li>\n<\/ul>\n<p>Both formats include an optional 4<sup>th<\/sup> day which may be used by the attendees to complete the left-over exercises. During this day, for both formats, only online support is available via Discord. No in-person presence is available from the trainers nor required by the attendees.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<p>&nbsp;<\/p>\n<p><strong>Topics Covered<br \/>\n<\/strong><\/p>\n<ul>\n<li>TEE Fundamentals\n<ul>\n<li>TEE overview<\/li>\n<li>Security model<\/li>\n<\/ul>\n<\/li>\n<li>ARM TrustZone-based TEEs\n<ul>\n<li>TEE SW components<\/li>\n<li>TEE attacker model<\/li>\n<li>TEE attack surface<\/li>\n<\/ul>\n<\/li>\n<li>REE \u2013&gt; TEE attacks\n<ul>\n<li>Secure Monitor<\/li>\n<li>TEE OS (SMC interface)<\/li>\n<li>Exploitation:\n<ul>\n<li>Vulnerable SMC handlers<\/li>\n<li>Broken design<\/li>\n<li>Unchecked Pointers<\/li>\n<li>Restricted writes<\/li>\n<li>Range checks<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li>REE \u2013&gt; TA attacks\n<ul>\n<li>Communicating with TAs<\/li>\n<li>Global Platform APIs<\/li>\n<li>Exploitation:\n<ul>\n<li>Type confusion<\/li>\n<li>TOCTOU (Double fetch)<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li>TA \u2013&gt; TEE attacks\n<ul>\n<li>TEE OS (Syscall interface)<\/li>\n<li>Drivers<\/li>\n<li>Exploitation:\n<ul>\n<li>Unchecked pointers from TA<\/li>\n<li>Vulnerable crypto primitives<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li>TA \u2013&gt; TA attacks\n<ul>\n<li>State confusion<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><strong>\u00a0<\/strong><\/p>\n<p>&nbsp;<\/p>\n<hr \/>\n<div class=\"page\" title=\"Page 3\">\n<div class=\"layoutArea\">\n<h5>This 4-day TEEPwn course is one of two Raelize&#8217;s Pwn training courses. The other is BOOTPwn which is being held in Amsterdam on April 2023. <span style=\"color: #993300\"><em>To find out more about this April&#8217;s 4-day BOOTPwn course, <strong><a href=\"https:\/\/sectrain.hitb.org\/courses\/bootpwn-breaking-secure-boot-by-experience-hitb2023ams\/\">click here<\/a><\/strong><\/em><\/span><\/h5>\n<hr \/>\n<div><\/div>\n<\/div>\n<\/div>\n<div class=\"page\" title=\"Page 3\">\n<div class=\"layoutArea\">\n<h4><strong style=\"font-size: 16px\"><span style=\"color: #993300\">\u00a0<\/span><\/strong><\/h4>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; This 4-day TEEPwn course is one of two Raelize&#8217;s Pwn training courses. The other is BOOTPwn which is being held in Amsterdam on April 2023. To find out more about this April&#8217;s 4-day BOOTPwn course, click here. ATTEND IN-PERSON: Onsite in Phuket DATE: 21-24 August 2023 TIME: 09:00 to 17:00 ICT\/GMT+7 Date Day Time [&hellip;]<\/p>\n","protected":false},"featured_media":11757,"template":"","meta":{"_acf_changed":false},"product_cat":[59,77,57],"product_tag":[],"class_list":{"0":"post-11758","1":"product","2":"type-product","3":"status-publish","4":"has-post-thumbnail","6":"product_cat-4-day-training","7":"product_cat-hitb2023hkt","8":"product_cat-in-person","10":"first","11":"instock","12":"featured","13":"shipping-taxable","14":"purchasable","15":"product-type-simple"},"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>TEEPwn: Breaking TEEs by Experience - HITB (in)Cyber 2024 - Abu Dhabi<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/conference.hitb.org\/hitbincyber2024\/product\/teepwn-breaking-tees-by-experience-hitb2023hkt\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"TEEPwn: Breaking TEEs by Experience - HITB (in)Cyber 2024 - Abu Dhabi\" \/>\n<meta property=\"og:description\" content=\"&nbsp; This 4-day TEEPwn course is one of two Raelize&#8217;s Pwn training courses. The other is BOOTPwn which is being held in Amsterdam on April 2023. To find out more about this April&#8217;s 4-day BOOTPwn course, click here. ATTEND IN-PERSON: Onsite in Phuket DATE: 21-24 August 2023 TIME: 09:00 to 17:00 ICT\/GMT+7 Date Day Time [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/conference.hitb.org\/hitbincyber2024\/product\/teepwn-breaking-tees-by-experience-hitb2023hkt\/\" \/>\n<meta property=\"og:site_name\" content=\"HITB (in)Cyber 2024 - Abu Dhabi\" \/>\n<meta property=\"article:modified_time\" content=\"2023-03-27T05:38:29+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/conference.hitb.org\/hitbincyber2024\/wp-content\/uploads\/sites\/21\/2023\/03\/christofaro.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/conference.hitb.org\/hitbincyber2024\/product\/teepwn-breaking-tees-by-experience-hitb2023hkt\/\",\"url\":\"https:\/\/conference.hitb.org\/hitbincyber2024\/product\/teepwn-breaking-tees-by-experience-hitb2023hkt\/\",\"name\":\"TEEPwn: Breaking TEEs by Experience - HITB (in)Cyber 2024 - Abu Dhabi\",\"isPartOf\":{\"@id\":\"https:\/\/conference.hitb.org\/hitbincyber2024\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/conference.hitb.org\/hitbincyber2024\/product\/teepwn-breaking-tees-by-experience-hitb2023hkt\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/conference.hitb.org\/hitbincyber2024\/product\/teepwn-breaking-tees-by-experience-hitb2023hkt\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/conference.hitb.org\/hitbincyber2024\/wp-content\/uploads\/sites\/21\/2023\/03\/christofaro.jpg\",\"datePublished\":\"2023-03-20T08:31:53+00:00\",\"dateModified\":\"2023-03-27T05:38:29+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/conference.hitb.org\/hitbincyber2024\/product\/teepwn-breaking-tees-by-experience-hitb2023hkt\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/conference.hitb.org\/hitbincyber2024\/product\/teepwn-breaking-tees-by-experience-hitb2023hkt\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/conference.hitb.org\/hitbincyber2024\/product\/teepwn-breaking-tees-by-experience-hitb2023hkt\/#primaryimage\",\"url\":\"https:\/\/conference.hitb.org\/hitbincyber2024\/wp-content\/uploads\/sites\/21\/2023\/03\/christofaro.jpg\",\"contentUrl\":\"https:\/\/conference.hitb.org\/hitbincyber2024\/wp-content\/uploads\/sites\/21\/2023\/03\/christofaro.jpg\",\"width\":1200,\"height\":900},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/conference.hitb.org\/hitbincyber2024\/product\/teepwn-breaking-tees-by-experience-hitb2023hkt\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/conference.hitb.org\/hitbincyber2024\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Shop\",\"item\":\"https:\/\/conference.hitb.org\/hitbincyber2024\/shop\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"TEEPwn: Breaking TEEs by Experience\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/conference.hitb.org\/hitbincyber2024\/#website\",\"url\":\"https:\/\/conference.hitb.org\/hitbincyber2024\/\",\"name\":\"HITB (in)Cyber 2024 - Abu Dhabi\",\"description\":\"May 14 - 16, Etihad Arena \",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/conference.hitb.org\/hitbincyber2024\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"TEEPwn: Breaking TEEs by Experience - HITB (in)Cyber 2024 - Abu Dhabi","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/conference.hitb.org\/hitbincyber2024\/product\/teepwn-breaking-tees-by-experience-hitb2023hkt\/","og_locale":"en_US","og_type":"article","og_title":"TEEPwn: Breaking TEEs by Experience - HITB (in)Cyber 2024 - Abu Dhabi","og_description":"&nbsp; This 4-day TEEPwn course is one of two Raelize&#8217;s Pwn training courses. The other is BOOTPwn which is being held in Amsterdam on April 2023. To find out more about this April&#8217;s 4-day BOOTPwn course, click here. ATTEND IN-PERSON: Onsite in Phuket DATE: 21-24 August 2023 TIME: 09:00 to 17:00 ICT\/GMT+7 Date Day Time [&hellip;]","og_url":"https:\/\/conference.hitb.org\/hitbincyber2024\/product\/teepwn-breaking-tees-by-experience-hitb2023hkt\/","og_site_name":"HITB (in)Cyber 2024 - Abu Dhabi","article_modified_time":"2023-03-27T05:38:29+00:00","og_image":[{"width":1200,"height":900,"url":"https:\/\/conference.hitb.org\/hitbincyber2024\/wp-content\/uploads\/sites\/21\/2023\/03\/christofaro.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/conference.hitb.org\/hitbincyber2024\/product\/teepwn-breaking-tees-by-experience-hitb2023hkt\/","url":"https:\/\/conference.hitb.org\/hitbincyber2024\/product\/teepwn-breaking-tees-by-experience-hitb2023hkt\/","name":"TEEPwn: Breaking TEEs by Experience - HITB (in)Cyber 2024 - Abu Dhabi","isPartOf":{"@id":"https:\/\/conference.hitb.org\/hitbincyber2024\/#website"},"primaryImageOfPage":{"@id":"https:\/\/conference.hitb.org\/hitbincyber2024\/product\/teepwn-breaking-tees-by-experience-hitb2023hkt\/#primaryimage"},"image":{"@id":"https:\/\/conference.hitb.org\/hitbincyber2024\/product\/teepwn-breaking-tees-by-experience-hitb2023hkt\/#primaryimage"},"thumbnailUrl":"https:\/\/conference.hitb.org\/hitbincyber2024\/wp-content\/uploads\/sites\/21\/2023\/03\/christofaro.jpg","datePublished":"2023-03-20T08:31:53+00:00","dateModified":"2023-03-27T05:38:29+00:00","breadcrumb":{"@id":"https:\/\/conference.hitb.org\/hitbincyber2024\/product\/teepwn-breaking-tees-by-experience-hitb2023hkt\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/conference.hitb.org\/hitbincyber2024\/product\/teepwn-breaking-tees-by-experience-hitb2023hkt\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/conference.hitb.org\/hitbincyber2024\/product\/teepwn-breaking-tees-by-experience-hitb2023hkt\/#primaryimage","url":"https:\/\/conference.hitb.org\/hitbincyber2024\/wp-content\/uploads\/sites\/21\/2023\/03\/christofaro.jpg","contentUrl":"https:\/\/conference.hitb.org\/hitbincyber2024\/wp-content\/uploads\/sites\/21\/2023\/03\/christofaro.jpg","width":1200,"height":900},{"@type":"BreadcrumbList","@id":"https:\/\/conference.hitb.org\/hitbincyber2024\/product\/teepwn-breaking-tees-by-experience-hitb2023hkt\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/conference.hitb.org\/hitbincyber2024\/"},{"@type":"ListItem","position":2,"name":"Shop","item":"https:\/\/conference.hitb.org\/hitbincyber2024\/shop\/"},{"@type":"ListItem","position":3,"name":"TEEPwn: Breaking TEEs by Experience"}]},{"@type":"WebSite","@id":"https:\/\/conference.hitb.org\/hitbincyber2024\/#website","url":"https:\/\/conference.hitb.org\/hitbincyber2024\/","name":"HITB (in)Cyber 2024 - Abu Dhabi","description":"May 14 - 16, Etihad Arena ","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/conference.hitb.org\/hitbincyber2024\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/conference.hitb.org\/hitbincyber2024\/wp-json\/wp\/v2\/product\/11758"}],"collection":[{"href":"https:\/\/conference.hitb.org\/hitbincyber2024\/wp-json\/wp\/v2\/product"}],"about":[{"href":"https:\/\/conference.hitb.org\/hitbincyber2024\/wp-json\/wp\/v2\/types\/product"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/conference.hitb.org\/hitbincyber2024\/wp-json\/wp\/v2\/media\/11757"}],"wp:attachment":[{"href":"https:\/\/conference.hitb.org\/hitbincyber2024\/wp-json\/wp\/v2\/media?parent=11758"}],"wp:term":[{"taxonomy":"product_cat","embeddable":true,"href":"https:\/\/conference.hitb.org\/hitbincyber2024\/wp-json\/wp\/v2\/product_cat?post=11758"},{"taxonomy":"product_tag","embeddable":true,"href":"https:\/\/conference.hitb.org\/hitbincyber2024\/wp-json\/wp\/v2\/product_tag?post=11758"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}