Egg Hunt in Tesla Infotainment: A First Look at Reverse Engineering of Qt Binaries
Haohuang Wen, Zhiqiang Lin
摘要
As one of the most popular C++ extensions for developing graphical user interface (GUI) based applications, Qt has been widely used in desktops, mobiles, IoTs, automobiles, etc. Although existing binary analysis platforms (e.g., angr and Ghidra) could help reverse engineer Qt binaries, they still need to address many fundamental challenges such as the recovery of control flow graphs and symbols. In this paper, we take a first look at understanding the unique challenges and opportunities in Qt binary analysis, developing enabling techniques, and demonstrating novel applications. In particular, although callbacks make control flow recovery challenging, we notice that Qt's signal and slot mechanism can be used to recover function callbacks. More interestingly, Qt's unique dynamic introspection can also be repurposed to recover semantic symbols. Based on these insights, we develop QTRE for function callback and semantic symbol recovery for Qt binaries. We have tested QTRE with two suites of Qt binaries: Linux KDE and the Tesla Model S firmware, where QTRE additionally recovered 10,867 callback instances and 24,973 semantic symbols from 123 binaries, which cannot be identified by existing tools. We demonstrate a novel application of using QTRE to extract hidden commands from a Tesla Model S firmware. QTRE discovered 12 hidden commands including five unknown to the public, which can potentially be exploited to manipulate vehicle settings.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- BaseMirror: Automatic Reverse Engineering of Baseband Commands from Android's Radio Interface LayerWenqiang Li, Haohuang Wen, Zhiqiang LinCCS 2024 · 被引用 1 次
- Unleashing the Power of Generative Model in Recovering Variable Names from Stripped BinaryXiangzhe Xu, Zhuo Zhang, Zian Su, Ziyang Huang 等NDSS 2025
- GUIFuzz++: Unleashing Grey-box Fuzzing on Desktop Graphical User Interfacing ApplicationsDillon Otto, Tanner Rowlett, Stefan NagyASE 2025
- You Can't Judge a Binary by Its Header: Data-Code Separation for Non-Standard ARM Binaries Using Pseudo LabelsHadjer Benkraouda, Nirav Diwan, Gang WangS&P 2025
它引用的顶会 Paper16
- SOK: (State of) The Art of War: Offensive Techniques in Binary AnalysisYan Shoshitaishvili, Ruoyu Wang, Christopher Salls, Nick Stephens 等S&P 2016 · 被引用 1,085 次
- IntelliDroid: A Targeted Input Generator for the Dynamic Analysis of Android MalwareMichelle Y. Wong, David LieNDSS 2016 · 被引用 253 次
- RetroWrite: Statically Instrumenting COTS Binaries for Fuzzing and SanitizationSushant Dinesh, Nathan Burow, Dongyan Xu, Mathias PayerS&P 2020 · 被引用 187 次
- TriggerScope: Towards Detecting Logic Bombs in Android ApplicationsYanick Fratantonio, Antonio Bianchi, William K. Robertson, Engin Kirda 等S&P 2016 · 被引用 161 次
- Ramblr: Making Reassembly Great AgainRuoyu Wang, Yan Shoshitaishvili, Antonio Bianchi, Aravind Machiry 等NDSS 2017 · 被引用 155 次
相关 Paper
- Automated Cross-Platform Reverse Engineering of CAN Bus Commands From Mobile AppsHaohuang Wen, Qingchuan Zhao, Qi Alfred Chen, Zhiqiang LinNDSS 2020
- QueryX: Symbolic Query on Decompiled Code for Finding Bugs in COTS BinariesHyungSeok Han, JeongOh Kyea, Yonghwi Jin, Jinoh Kang 等S&P 2023
- Detecting Exception Handling Bugs in C++ ProgramsHao Zhang, Ji Luo, Mengze Hu, Jun Yan 等ICSE 2023 · 被引用 7 次
- iDEA: Static Analysis on the Security of Apple Kernel DriversXiaolong Bai, Luyi Xing, Min Zheng, Fuping QuCCS 2020 · 被引用 10 次
- Deeply Reinforcing Android GUI Testing with Deep Reinforcement LearningYuanhong Lan, Yifei Lu, Zhong Li, Minxue Pan 等ICSE 2024 · 被引用 21 次
