<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Riyan Firmansyah Research &amp; Publications</title><link>https://advisory.ruz.fi/</link><description>Recent content on Riyan Firmansyah Research &amp; Publications</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 02 Jan 2025 00:00:00 +0000</lastBuildDate><atom:link href="https://advisory.ruz.fi/index.xml" rel="self" type="application/rss+xml"/><item><title>Introduction to Embedded System Hacking</title><link>https://advisory.ruz.fi/talks/skill-issue-takeover-cloud-managed-router-copy/</link><pubDate>Thu, 02 Jan 2025 00:00:00 +0000</pubDate><guid>https://advisory.ruz.fi/talks/skill-issue-takeover-cloud-managed-router-copy/</guid><description>Explain and explore embedded system hacking fundamentals, including static and dynamic analysis, real-world case studies, tools, and ethical considerations for security research and vulnerability disclosure.</description></item><item><title>Takeover Cloud Managed Router via CWMP Communication using MITM Scenario</title><link>https://advisory.ruz.fi/talks/idsecconf-2023-takeover-cloud-managed-router/</link><pubDate>Sat, 04 Nov 2023 00:00:00 +0000</pubDate><guid>https://advisory.ruz.fi/talks/idsecconf-2023-takeover-cloud-managed-router/</guid><description>Cloud Managed Routers are a combination of conventional routers and cloud management technology, developed to make it easier for users to remotely manage their routers. However, if implemented incorrectly, this feature can be exploited by unauthorized parties, and can even lead to the risk of router access being compromised. In this topic, I&amp;rsquo;ll briefly explain how this risk can arise.</description></item><item><title>Man-in-the-Middle Remote Code Execution via CWMP in ReyeeOS</title><link>https://advisory.ruz.fi/disclosures/cve-2023-53881-reyee-cwmp-mitm-rce/</link><pubDate>Fri, 04 Aug 2023 00:00:00 +0000</pubDate><guid>https://advisory.ruz.fi/disclosures/cve-2023-53881-reyee-cwmp-mitm-rce/</guid><description>ReyeeOS contains an unprotected CWMP (CPE WAN Management Protocol) communication that allows attackers to intercept and manipulate device communication through a man-in-the-middle attack, enabling arbitrary command execution on Ruijie Reyee devices.</description></item></channel></rss>