lukas seidel

@pr0me.bsky.social

Firmware Security • Embedded Systems • AI x Infosec • Researcher @binarly • PhD Candidate @TUBerlin • Capturing Flags with ENOFLAG

recently, the google scholar feed I used to explore new work in my fields of interest was removed. so I built my own paper discovery website: a minimalistic design with high information density and full control over search terms.

Bild

okay deepwiki is pretty sweet. just replace 'github' with 'deepwiki' in a repo's url and it will generate an architecture overview, explanations for components, flow diagrams etc. I tried it on large code bases like afl++ and libafl and it's actually impressive

Bild

the guy who reversed the denuvo drm @momo5502.bsky.social works on a high-perf windows emulator for security research. I noticed that it supports icicle as a backend, a fuzzing-specific emulator. awesome to see academic work being continuously developed and making it into the real world

Bild

the recording of my talk "Rethinking Emulation for Fu(zzi)n(g) and Profit: Near-Native Rehosting for Embedded ARM Firmware" is online! I had an absolute blast speaking and being at @re-verse.io, so many great talks and hallway discussions

RE//verse@re-verse.io · last yr.

We were slow with the last video update so we figured we'd do a two for one! Lukas talks about rehosting firmware for fuzzing (youtu.be/o_ckTnTQlfs) and Robin shows off a fantastic new tool for exploring code relationships beyond single binaries (www.youtube.com/watch?v=LsDn...)

3.7 is both in api and in cursor just utterly disappointing. when it does what it's supposed to, it's great, but man is it trying hard to misinterpret my intentions.

Bild

beautiful and incredibly interesting talk on reverse engineering the OG xbox by @ret2systems.bsky.social's Markus, incl. building a custom interposer to upgrade the CPU a deep dive into hardware hacking, an ode to hw engineering and a call for software-focused researchers to try new things

BildBild
RE//verse@re-verse.io · last yr.

Our first video from RE//verse 2025 is live! Part journey of personal discovery, part technical deep-dive, this presentation from Markus Gaasedelen was the highest rated in the feedback survey and is a must-see talk:

libAFL is a beast. it has so many settings to tweak, different modes to select and the code can be quite scary at first. but writing a target-specific custom fuzzer is super powerful! to get started, Trail of Bits just published a nice primer: appsec.guide/docs/fuzzing...

LibAFL

LibAFL # The LibAFL fuzzer implements features from AFL-based fuzzers like AFL++. Similarly to AFL++, LibAFL provides better fuzzing performance and more advanced features over libFuzzer. However, wit...

appsec.guide

my google scholar's 'recommended articles' feed has been empty for weeks. where is, it I miss it :/ anyone any recommendation for an alternative? some tunable feed of recent papers?

I had a blast speaking and being at the RE//verse conference! so many cool people and great discussions on firmware, fuzzing, ai and binary analysis if you want to find out more about firmware rehosting or are an enjoyer of ascii diagrams, check out the slides to my talk below :)

Bild

today was blessed. had a super fun day at Kennedy Space Center. and then I got to witness my first rocket launch in person, a falcon 9 bringing Intuitive Machine's lunar lander into orbit. my space-nerd heart is so happy.

Bild

2024 was a significant year for decompilation, constituting a possible resurgence in the field. Major talks, the thirty-year anniversary of research, movements in AI, and an all-time high for top publications in decompilation. Join me for a retrospective: mahaloz.re/dec-progr...

Decompiling 2024: A Year of Resurgance in Decompilation Research

The year 2024 was a resurgant year for decompilation. Academic publications from that year made up nearly 30% of all top publications ever made in decompilat...

mahaloz.re

"IoT Firmware Emulation and Its Security Application in Fuzzing" is a great read to get started with rehosting firmware it provides a taxonomy of nearly all the available approaches and discusses the most important concepts, such as peripheral modeling and fidelity trade-offs

Bild

happy new year 🎉 to continue the tradition, here is some of my favorite firmware & embedded security research of 2024: Defeating the new Raspberry Pi's RP2350 Security Features [1] Reversing and Hacking Firmware of an in-orbit Satellite to Re-establish Lost Communication [2]

Bild

recovering a satellite by creatively using existing telecommands and overwriting vtables to persistently add new commands without needing to touch (and risk breaking) the running OBC firmware. also, because that firmware didn't have an update mechanism incredible talk! media.ccc.de/v/38c3-hacki...

Hacking yourself a satellite - recovering BEESAT-1

In 2013, the satellite BEESAT-1 started returning invalid telemetry, rendering it effectively unusable. Because it is projected to remain...

media.ccc.de

The yearly academic security circus concludes. Exponential growth continues with 1146 published papers (vs 947 in '23 and 93 in '05). Essentially, we published 14% of all security papers this year. Two authors cracked 100 papers and 13 published >=10 this year. Details: nebelwelt.net/pubstats/top...

BildBildBild

one week left to submit to the SpaceSec NDSS workshop! some highlights from the first two years: A Case Study on Fuzzing Satellite Firmware [1] Merge/Space: A Security Testbed for Satellite Systems [2] Death By A Thousand COTS: Disrupting Satellite Comms using Low Earth Orbit Constellations [3]

Bild