Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
"Hacking Internet of Things devices", Ivan Novikov
Search
OWASP Moscow
December 04, 2017
Technology
170
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
"Hacking Internet of Things devices", Ivan Novikov
OWASP Russia Meetup #2
OWASP Moscow
December 04, 2017
More Decks by OWASP Moscow
See All by OWASP Moscow
"Evolution of Application Security Programs through OWASP SAMM 2.0", Yan Kravchenko
owaspmoscow
0
640
«Проекты OWASP: SAMM выпуск 2», Тарас Иващенко, OZON
owaspmoscow
0
750
«Типичные ошибки реализации SMS-аутентификации», Ramazan (r0hack), DETEACT
owaspmoscow
0
1k
«Dev, Sec, Oops: How Agile Security increases Attack Surface», Денис Макрушин
owaspmoscow
0
740
«From captcha to RCE. Сложности реализации механизма CAPTCHA в изолированных системах», Виталий Малкин
owaspmoscow
0
610
«OWASP Сheat Sheet Series. Microservices-based security architecture documentation», Александр Барабанов
owaspmoscow
0
660
«Проекты OWASP: следим за безопасностью 3rd-party-компонент с помощью Dependency Track», Тарас Иващенко, OZON.
owaspmoscow
0
670
«Будущее без паролей: про FIDO2/WebAuthN и не только», Сергей Белов, Mail.Ru Group.
owaspmoscow
0
620
«CTFZone, или как перестать ресёрчить и полюбить CTF», Никита Вдовушкин, BI.ZONE.
owaspmoscow
1
600
Other Decks in Technology
See All in Technology
「面白い!」を信じ抜け。激動の時代を貫く、オンリーワン・エンジニアの条件
kizawa2020
0
280
AWS Blocks が楽しい #ゆるWeb札幌
tacck
PRO
0
170
Digitization部 紹介資料
sansan33
PRO
2
7.7k
顧客の要望は2次情報である 〜アンテナを張るFDEの構造論〜
noriakioji
3
970
全社に広がるMCPサーバーを、 どう安全に管理するか MCPass開発の舞台裏
mtpooh
3
160
「ミスを許さない手順書」を作ってみた 〜 個人的にはこれ以上できることはあまりなさそう/20260827-ssmjp-operation-procedure-update
opelab
11
8.6k
GopherCon @シアトル に行ってきました
logica0419
0
320
NANDでも描画したい!
nichica906
3
790
AIエージェントのためのデータ設計
daiz21
0
470
Distributed Transactions Under Fire: Building a Zero-Oversell Flash Sale Platform with Amazon Aurora DSQL
yama3133
0
100
型落ちシンクライアント端末のPoEモジュールを自作したかった話
logica0419
0
490
Introduction to Bill One Development Engineer
sansan33
PRO
0
470
Featured
See All Featured
We Analyzed 250 Million AI Search Results: Here's What I Found
joshbly
1
1.9k
Conquering PDFs: document understanding beyond plain text
inesmontani
PRO
4
3k
Navigating the moral maze — ethical principles for Al-driven product design
skipperchong
2
500
Applied NLP in the Age of Generative AI
inesmontani
PRO
4
2.4k
Reflections from 52 weeks, 52 projects
jeffersonlam
356
21k
StorybookのUI Testing Handbookを読んだ
zakiyama
31
6.9k
Visual Storytelling: How to be a Superhuman Communicator
reverentgeek
2
630
Primal Persuasion: How to Engage the Brain for Learning That Lasts
tmiket
0
430
Chasing Engaging Ingredients in Design
codingconduct
0
280
Lessons Learnt from Crawling 1000+ Websites
charlesmeaden
PRO
1
1.5k
Highjacked: Video Game Concept Design
rkendrick25
PRO
1
450
Design and Strategy: How to Deal with People Who Don’t "Get" Design
morganepeng
133
19k
Transcript
OWASP Russia Meetup #2, 28/02/15 research Hacking Internet of Things
devices Ivan Novikov (@d0znpp)
Internet of Things. Story #1 • Take any device •
Find serial port (buttons + display) • Connect “WiFi to serial” module • Profit • What about this connecter cost? • What about this device cost?
Internet of Things. Story #2 • Take your exists device
(wifi router) • Make /dev/something with magic • Profit • What about this device cost?
AP at IoT device to configure • Encryption and credentials
(defaults) • Make sure that configuration interface disabled after initial setup How to connect IoT to your WiFi
Magic way (have a special name): • Enter your WiFi
SSID and password to app • Press ENTER • Profit • How it works? How to connect IoT to your WiFi
SSID+password encoding to $SP Find a network with this SSID
= $SP Catch broadcast packet Decode $SP to SSID and password Profit Connection magic
None
Hardcoded IP address Using as NTP service Firewalls legitimates Count
devices remotely Memory corruption vulnerability in response parsing function? Backdoor stories $ strings IoT-6235571.bin | egrep '[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+' 208.67.222.222 10.10.100.254 10.10.100.100 255.255.255.0 http://10.10.100.100/ 10.10.10.3 =DHCP,0.0.0.0,0.0.0.0,0.0.0.0 61.ZZZ.YYY.XXX netname: SHANGHAI-JIAOTONG-UNIVERSITY country: CN descr: Shanghai Jiaotong University mnt-by: MAINT-CN-CHINANET-ZJ-HZ role: CHINANET-ZJ Hangzhou address: No.352 Tiyuchang Road,Hangzhou,Zhejiang.310003 country: CN person: Zhihao Zhou nic-hdl: ZZ1073-AP
None
None
None
5/5 devices hacked (3 vendors) 3/5 backdoors found (2 vendors)
0/5 physical damage through IoT device Our stats
Taxonomy Methodology Check lists New OWASP chapter? Most important
External from Internet (CSRF+) WiFi guest (server-side) Neighbor (WiFi w/o
password) Vendor (backdoors) Retailer (firmware modifications after manufacturing) Attackers
https://www.owasp.org/index.php/IoT_Security _Checklist Criteria
The end Contacts: @wallarm, @d0znpp research