Noobie.dog

TPM Sniffing

Early 2025 I was asked to carry out an end to end build review and a full security assessment of a laptop. The brief was similar to a stolen laptop scenario, assume physical access, assess what could realistically be achieved, and report on the risks. This was not new territory

DEEP DIVE: Victure PC440 IP Camera - Part 3: Buffer Overflows

First thing I think we need to do is look to see how we can generate a Wi-Fi QR code, and how it’s made up. Then Debug using a Wi-Fi QR code on the device. The format was originally invented, and documented, by the QR decoder. Since then, the

DEEP DIVE: Victure PC440 IP Camera - Part 4: Weaponising the Exploit

Now that we have a classic stack buffer overflow, let’s see if we can weaponize it to our benefit! Before we get to just a random exploit, let’s talk about what we want it to do Be reproducible, Be remote (in this case, a form side channel) and

DEEP DIVE: Victure PC440 IP Camera - Part 1: Extracting Firmware and Getting a shell

I bought this camera a few years ago when I was interested in looking at a few different available opens that were cheap AF on Amazon. I wanted to look at an RF based Baby monitor and an IP based Baby Monitor. The RF version was the one that I

DEEP DIVE: Victure PC440 IP Camera - Part 2: Understanding the binaries!

Digging into the firmware: Bash Script Jenga For Part two we are going to look at the order in which the files are run, then look at what the system is doing. I have a particular interest in the QR code stuff and potentially the update stuff. So, from part

Noobie.dog © 2026