Sydney Johns RE for the Rest of Us An Introduction to Reverse Engineering

Blacks in Cyber Village @ DEF CON 33 · Day 1 · Blacks in Cyber Village

Overview

Sydney Jones’s talk, "RE for the Rest of Us: An Introduction to Reverse Engineering," delivered at the Blacks in Cyber Village, provides a comprehensive and accessible entry point into the often-intimidating world of reverse engineering. Aimed at beginners, the session expertly navigates both hardware reverse engineering (RE) and software reverse engineering, leveraging practical examples with an Arduino Uno board and the powerful Ghidra software reverse engineering suite. Jones, a cybersecurity researcher and PhD student at Virginia Tech, emphasizes a hands-on approach, guiding the audience through fundamental concepts from identifying physical components to inspecting binary behavior.

Watch on YouTube

Visual summary for Sydney Johns RE for the Rest of Us An Introduction to Reverse Engineering
Visual summary for Sydney Johns RE for the Rest of Us An Introduction to Reverse Engineering

Key moments

  1. 0:00 Introduction to Sydney Jones and talk overview
  2. 2:00 Detailed agenda for the reverse engineering talk
  3. 3:18 What is Reverse Engineering? Definition and goals
  4. 4:06 Distinguishing between hardware and software reverse engineering
  5. 5:29 Hands-on exercise: Identifying IC board components
  6. 7:24 ATMega 16U2: USB to serial converter explanation
  7. 8:18 Understanding the 16MHz crystal oscillator's function

RE for the Rest of Us: An Introduction to Reverse Engineering

Speakers: Sydney Jones, Cybersecurity Researcher, PhD Student at Virginia Tech

Conference: Blacks in Cyber Village

YouTube: https://www.youtube.com/watch?v=h9ewUS6FTFQ

Overview

Sydney Jones’s talk, "RE for the Rest of Us: An Introduction to Reverse Engineering," delivered at the Blacks in Cyber Village, provides a comprehensive and accessible entry point into the often-intimidating world of reverse engineering. Aimed at beginners, the session expertly navigates both hardware reverse engineering (RE) and software reverse engineering, leveraging practical examples with an Arduino Uno board and the powerful Ghidra software reverse engineering suite. Jones, a cybersecurity researcher and PhD student at Virginia Tech, emphasizes a hands-on approach, guiding the audience through fundamental concepts from identifying physical components to inspecting binary behavior.

The talk demystifies reverse engineering by breaking it down into actionable steps, demonstrating how to analyze existing systems to understand their inner workings, security structures, and logic. It highlights the critical interplay between physical hardware inspection and software analysis, showcasing how tools and methodologies can be applied to real-world devices. By providing concrete exercises, Jones empowers attendees to grasp complex topics like firmware extraction, assembly code analysis, and decompilation, making a crucial field of cybersecurity approachable for those new to it.

This presentation is particularly significant because it addresses the common barrier to entry in reverse engineering: the perceived complexity and the need for specialized knowledge. Jones’s pedagogical approach, rooted in her own learning journey, ensures that participants gain not only theoretical understanding but also practical skills. The talk underscores the importance of reverse engineering for various applications, including malware analysis, vulnerability assessment, and recovering lost code, thereby equipping future cybersecurity professionals with essential capabilities.

Background

▶ Watch: Introduction to Sydney Jones and talk overview (0:00)

Reverse engineering is the systematic process of analyzing an existing item to extract technical information required to reproduce or understand it. Its core objective is to discern how a system functions, rather than merely replicating it. This involves understanding its design, security mechanisms, and operational logic. Reverse engineering efforts often commence when only a partial understanding of a system is available, such as having a physical hardware device without documentation, or possessing a binary executable without its corresponding source code.

The discipline broadly bifurcates into two main categories: hardware reverse engineering and software reverse engineering. Hardware RE entails the physical disassembly and meticulous examination of a device's components, often involving specialized tools like heat guns to de-solder and inspect integrated circuits (ICs) bit by bit. This process typically involves identifying part numbers, looking up datasheets for each chip, and tracing electrical connections to understand component interactions. A critical aspect of hardware RE is the ability to diagnose connectivity issues and validate component functionality, frequently performed using tools like multimeters for continuity and voltage checks. Furthermore, locating and exploiting diagnostic ports such as UART or JTAG is crucial, as these often provide direct access to a device's internal systems, bypassing security mechanisms to extract or analyze firmware.

Software RE, conversely, focuses on transforming non-human-readable code (like binary executables) back into a human-understandable format. This is commonly applied to analyze malware, validate software functionality, or recover lost source code. The process typically begins with firmware extraction from a device's memory, often using tools like AVRdude for microcontrollers. Once the firmware is obtained, it undergoes flash analysis, where tools like flashrom and Binwalk are used to identify file structures and formats (e.g., ELF for Linux/Arduino, EXE for Windows). The extracted binaries are then subjected to disassembly, converting machine code into assembly language, which is an intermediate, slightly more human-readable representation. Advanced tools like Ghidra then perform decompilation, attempting to reconstruct high-level source code (e.g., C or C++) from the assembly, making the program's logic significantly easier to comprehend. The challenge lies in this transformation, as binary code is a highly optimized, low-level representation, making the reconstruction of original source code a complex endeavor.

Key Findings

▶ Watch: What is Reverse Engineering? Definition and goals (3:18)

The talk delivers several key findings and practical insights for aspiring reverse engineers, emphasizing that the field is accessible with the right approach and tools. A primary discovery is the crucial role of documentation in both hardware and software analysis. Jones demonstrates that even without initial source code or schematics, publicly available datasheets for ICs and meticulous documentation of one's own RE process significantly accelerate understanding and future tasks.

For hardware, a core finding is the efficacy of basic diagnostic tools like multimeters for validating board integrity and functionality. The ability to perform a continuity test to identify intact electrical traces and to verify voltage outputs (e.g., 3.3V and 5V on an Arduino) provides immediate feedback on a device's operational status before delving into deeper analysis. This practical, hands-on validation is presented as a fundamental first step in hardware RE.

In the realm of software, the talk highlights Ghidra's power in demystifying binary code. A significant finding is Ghidra's capability to decompile an ELF binary back into a C-like representation, dramatically simplifying the process of understanding program logic compared to raw assembly. Furthermore, Ghidra's string search functionality proves invaluable for quickly identifying hardcoded secrets such as usernames and passwords, even when only the binary is available. This demonstrates a critical vulnerability often exploited in real-world systems and showcases how RE tools can quickly uncover such flaws.

Finally, a overarching finding is the importance of iterative learning and practice. Jones stresses that reverse engineering, while initially overwhelming, becomes manageable through consistent engagement with core tools like Ghidra, Binwalk, and Object Dump. The talk concludes that building experience through practical exercises and documenting each step fosters a deeper understanding and proficiency, transforming complex concepts into recognizable patterns.

Technical Deep Dive

▶ Watch: Distinguishing between hardware and software reverse engineering (4:06)

The technical deep dive of the talk is structured around a practical exploration of an Arduino Uno board, demonstrating both hardware and software reverse engineering techniques.

Hardware Reverse Engineering: Arduino Uno

Jones begins by illustrating the process of identifying key components on the Arduino Uno. This involves visually inspecting the board for part numbers and then consulting datasheets (either online via Google reverse image search or Octopart, or from a provided GitHub repository).

  1. ATMEL Mega 16U2 (USB-to-Serial Converter):
  • Function: This chip facilitates communication between the computer's USB port and the ATmega328P microcontroller, converting USB signals to serial (UART) and vice versa.
  • Pins: 32 pins.
  • Interfaces/Protocols: Uses UART serial and USB. Visual inspection shows its connections directly to the USB port.
  1. 16MHz Crystal Oscillator:
  • Function: Provides a precise clock signal crucial for the microcontroller's timing operations, enabling functions like wait or delay commands. Without it, the processor cannot operate synchronously.
  • Pins: 2 pins.
  • Interfaces/Protocols: A passive timing component, it does not use complex interfaces or protocols.
  1. 47µF 25V Capacitor:
  • Function: Essential for power regulation, ensuring stable voltage outputs (5V and 3.3V) on the board by preventing fluctuations.
  • Pins: 2 pins.
  • Interfaces/Protocols: A passive component.
  1. ATmega328P (Microcontroller):
  • Function: The "brain" of the Arduino, handling input/output (I/O) operations and controlling peripherals. It executes the flashed firmware.
  • Pins: 28 pins.
  • Interfaces/Protocols: Primarily uses UART for serial communication and supports various digital I/O operations. Its pins are directly connected to the Arduino's digital I/O headers.

Following component identification, the talk moves to board connectivity checks using a multimeter.

  • Continuity Test: This test verifies if an electrical path exists between two points. The multimeter is set to continuity mode, and probes are placed on different points of a soldered trace on the back of the board. A beeping sound and a reading of 0.00 ohms indicate a continuous, low-resistance path, confirming the connection. This is vital for diagnosing broken traces or faulty components, especially if a board has been exposed to excessive heat.
  • Voltage Test: With the Arduino powered, the multimeter is used to verify the 3.3V and 5V power outputs, ensuring the board is receiving and regulating power correctly.

Lastly, the concept of diagnostic ports is introduced. While the Arduino Uno uses a USB type-B socket for programming and communication, the talk broadens this to include UART and JTAG ports, which are common on other devices. These ports are critical for reverse engineers as they often provide direct, low-level access to a device’s internal memory and systems, potentially bypassing higher-level security mechanisms to extract firmware or debug code.

Software Reverse Engineering: From C to Binary with Ghidra

The transition to software RE begins with firmware extraction. Although Jones provides a pre-compiled ELF file for the workshop, she explains that typically, tools like AVRdude would be used with the Arduino's USB port to pull the firmware from the bootloader.

Once the firmware (binary file) is obtained, the standard flash analysis workflow involves:

  1. Extraction of Embedded Files: Using tools like flashrom.
  2. File Structure Identification: Using Binwalk to determine the file format (e.g., ELF, EXE). The Arduino uses the Executable and Linkable Format (ELF), common in Linux-based and open-source systems, which can be analyzed with tools like objdump and GDB. Windows systems typically use EXE files, often analyzed with Ghidra or IDA Pro.
  3. Code Analysis: The core of software RE is converting binary code back into human-readable formats.
  • Disassembly: The talk illustrates the journey from high-level C code to assembly language and then to raw binary/hexadecimal. A simple C program that adds two numbers (5 + 12 = 17) is shown. Its corresponding assembly code, while more complex than C, still reveals recognizable patterns like function calls (EAX, EBX), arithmetic operations (add), and library calls (printF). In contrast, the hexadecimal dump of the same file is largely unintelligible, highlighting the need for disassemblers and decompilers. Tools like object dump are useful for viewing assembly and memory representations.
  • Code Analysis Types:
  • Static Analysis: Examining the code without executing it, focusing on structure, logic, and potential vulnerabilities.
  • Dynamic Analysis: Running the program and observing its behavior, memory usage, and interactions.
  • Documentation: Jones stresses the importance of creating memory maps, flowcharts, and pseudocode during analysis to reconstruct the program's logic and architecture effectively.

Demo / Proof of Concept

▶ Watch: ATMega 16U2: USB to serial converter explanation (7:24)

The practical demonstration centers around flashing custom firmware to an Arduino Uno and then performing a detailed software reverse engineering analysis using Ghidra.

Flashing Firmware to Arduino

The first part of the demo involves compiling and uploading .ino (Arduino sketch) files to the Arduino board. This process requires:

  1. Arduino Cloud Platform: Using the web-based IDE or the desktop Arduino IDE.
  2. Arduino Driver Installation: Ensuring the computer can communicate with the Arduino board by installing the necessary drivers (e.g., Arduino Cloud Agent).

Two primary .ino files are used for demonstration:

  • "Blink of an Eye": A simple program designed to make an LED on the Arduino blink at 200-millisecond intervals for half a minute. This serves as a basic verification that the flashing process works correctly and the board is responsive.
  • "Give Me the Address": This is the main executable used for the Ghidra demonstration. Its functionality is twofold:
  • It adds two integers together.
  • Crucially, it contains hardcoded user credentials. These credentials are defined in a secret.h header file as char constants: a username "Alice" and a password "password123". This setup provides clear targets for the subsequent Ghidra analysis.

Ghidra Analysis of "Give Me the Address" ELF File

The "Give Me the Address" .ino file is compiled into an ELF binary and then loaded into Ghidra. The objectives of this analysis are:

  1. Locate the main function: Ghidra automatically identifies and displays functions, making main easily discoverable within the decompiled code view.
  2. Observe Variable Mapping: The demo shows how Ghidra maps variables (e.g., A=5, B=12, and hexadecimal values BD, A1) from the original C code to registers or specific memory locations in the assembly and decompiled views. Using Ghidra's search function (Ctrl+F) for these values allows the analyst to trace their usage and manipulation within the program logic. For instance, the hexadecimal value BD is shown to correspond to register R24 in the assembly code, revealing the relationship between high-level variables and their low-level representations.
  3. Identify Hardcoded Username and Password: This is a highlight of the demo. The analyst navigates to Ghidra's "Search" menu and selects "For Strings." This powerful feature automatically scans the entire binary for all embedded strings. The demo clearly reveals "Alice" and "password123" among the search results. Further inspection in Ghidra shows that the password, "password123," is stored character by character at different sequential memory locations. This demonstrates how easily hardcoded sensitive data can be extracted from a binary, even without access to the original source code or header files.

The Ghidra tutorial, though presented rapidly due to time constraints, effectively illustrates the tool's capabilities in transforming opaque binary code into a comprehensible C-like representation, enabling the identification of program logic and critical data like hardcoded secrets.

Defensive Implications

▶ Watch: Understanding the 16MHz crystal oscillator's function (8:18)

The insights gained from reverse engineering, as demonstrated in this talk, carry significant implications for cybersecurity defenders. Understanding how an attacker might reverse engineer a system is crucial for building more resilient defenses.

Firstly, the ease with which hardcoded secrets like usernames and passwords can be extracted from a binary using tools like Ghidra highlights a critical vulnerability. Defenders must implement secure coding practices that avoid embedding sensitive information directly into executables or firmware. Instead, credentials should be managed through secure configuration files, environment variables, or dedicated secrets management systems, accessed at runtime, and ideally encrypted or hashed.

Secondly, the hardware reverse engineering segment underscores the importance of physical security for devices. If an attacker gains physical access to a device, they can identify components, trace connections, and potentially exploit diagnostic ports (UART, JTAG) to extract firmware or bypass security mechanisms. Defenders should consider tamper-evident seals, hardware-based security modules, and robust physical enclosure designs to deter such attacks. Furthermore, understanding the functions of critical components like microcontrollers and oscillators helps in designing secure boot processes and protecting intellectual property embedded in custom ICs.

Thirdly, the process of firmware analysis is invaluable for vulnerability assessment and malware analysis. Defenders can reverse engineer unknown binaries to identify malicious functionalities, understand exploit mechanisms, or uncover unintentional vulnerabilities in their own software. By disassembling and decompiling proprietary or third-party binaries, security teams can validate software behavior against security policies and ensure compliance, especially in critical infrastructure or IoT devices where source code may not be available.

Finally, the talk emphasizes the importance of documentation in the RE process. For defenders, maintaining thorough documentation of their own systems' architecture, firmware components, and security controls can significantly aid in incident response. If a system is compromised, having a clear understanding of its internal workings, derived from a defensive RE perspective, can expedite root cause analysis and mitigation efforts. Ultimately, adopting a reverse engineering mindset allows defenders to anticipate attacker techniques and build proactive, layered security measures.

Key Takeaways

  • Reverse Engineering is Accessible: Despite its perceived complexity, RE can be approached by beginners by focusing on core tools and practical exercises.
  • Hardware and Software are Intertwined: Effective RE often requires understanding both the physical components of a device and the software/firmware it runs.
  • Essential Tools for Beginners: Familiarity with tools like Ghidra (for decompilation), Binwalk (for file structure analysis), and multimeters (for hardware diagnostics) is fundamental.
  • Documentation is Paramount: Meticulous documentation of the RE process, component datasheets, and memory maps significantly streamlines analysis and future tasks.
  • Practice Makes Patterns: Consistent practice and repetition are key to developing the intuition and skills needed to identify common code patterns and vulnerabilities.
  • Avoid Hardcoding Secrets: The ease with which Ghidra can extract hardcoded credentials from binaries highlights a critical security vulnerability that developers must address.

About the Speaker(s)

Sydney Jones is a dedicated cybersecurity researcher and a PhD student at Virginia Tech. Her expertise spans several critical areas within cybersecurity, including reverse engineering, vulnerability assessment, and AI evaluation. Jones is passionate about sharing knowledge, particularly as she learns new concepts herself, embodying the philosophy of teaching while learning. Her talk at the Blacks in Cyber Village conference reflects her commitment to making complex technical fields like reverse engineering approachable and engaging for newcomers. Beyond her academic and professional pursuits, Sydney enjoys gaming (especially Animal Crossing), anime (Apothecary Diaries), and creative arts like painting.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A competent, well-structured intro talk for its intended audience — beginners at a community-focused village. Jones clearly knows her material and teaches it honestly, but the content is foundational by design: Arduino + Ghidra + hardcoded secrets is the canonical 101 curriculum. Nothing here will surprise anyone who's opened a binary before.

Heather Calloway (CISO) — WEAK

A competent, well-intentioned intro to reverse engineering for a beginner audience at a diversity-focused village. Outside my lane on pure technical instruction, but the defensive implications section surfaces real practitioner relevance — then stops short of telling anyone with institutional responsibility what to do with it.

→ Top-rated talks at Blacks in Cyber Village @ DEF CON 33

All talks from Blacks in Cyber Village @ DEF CON 33