Memory Forensics of a Java Card Dump [chapter]

Jean-Louis Lanet, Guillaume Bouffard, Rokia Lamrani, Ranim Chakra, Afef Mestiri, Mohammed Monsif, Abdellatif Fandi
2015 Lecture Notes in Computer Science  
Nowadays several papers have shown the ability to dump the EEPROM area of several Java Cards leading to the disclosure of already loaded applet and data structure of the card. Such a reverse engineering process is costly and prone to errors. Currently there are no tools available to help the process. We propose here an approach to find in the raw data obtained after a dump, the area containing the code and the data. Then, once the code area has been identified, we propose to rebuilt the
more » ... binary Cap file in order to be able to obtain the source code of the applet stored in the card.
doi:10.1007/978-3-319-16763-3_1 fatcat:yivbhmziknbbpcvm55wu3oscp4