Nullcon Goa 2023 | Reverse Engineering RGB Keyboard Backlights With Linux Kernel Drivers by Rishit

Опубликовано: 17 Февраль 2026
на канале: nullcon
1,069
45

This talk by our speaker Rishit Bansal, tentatively covers the following topics:

00:00 Speaker and Talk Introduction
01:37 Chapter 1: Reverse Engineering the HP Light Studio Application
09:22 Chapter 2: Understanding ACPI and WMI
19:55 Chapter 3: Developing WMI Drivers on the Linux Kernel
25:34 Demo
29:16 Q&A

Click here to download the slides: https://goa2023.nullcon.net/goa-2023/...

Abstract:
--------------------
This talk revolves around a recent hobby open source project I undertook to reverse engineer a Windows HP Laptop RGB Keyboard driver and re-implement the same functionality on Linux by writing a kernel driver. Initially, I thought this would be straightforward, but I was proven wrong fast! Due to the lack of any unified interface for keyboard backlights, laptop manufacturers create their own proprietary firmware to interface these devices using obscure Windows APIs. The first phase of my talk explains how I reverse-engineered these APIs to understand how they work and what I learned in the process. A lot of the standards used here are not only applicable to Keyboard LEDs but all manufacturer-specific functionality in general. In this section of the talk, I aim to explain different reverse engineering techniques for dotnet / Windows native applications. The second phase of my talk describes about how I started contributing to the Linux kernel and submitted my first patch to the mainline 6.x Linux Kernel. It also talks about my ongoing work on Linux HP WMI drivers, where I am working with Kernel Maintainers to introduce new standards to hopefully unify RGB keyboard drivers on Linux: something which Windows was unable to do!

#kernel #RGBkeyboard #Infosec #Nullcon #NullconGoa2023
--------------------------------------------------------------------------------------------------
Follow nullcon on Facebook:   / nullcon  
Twitter:   / nullcon  
LinkedIn:   / nullcon  
Website: https://nullcon.net