Abusing the Internet of Things

291 Pages · 41.57 mb ·

Nitesh Dhanjani

Internet

Table of contents

- Copyright (Page 6)
- Table of Contents (Page 9)
- Foreword (Page 13)
- Preface (Page 15)
- Who This Book Is For (Page 15)
- How to Use This Book (Page 16)
- Conventions Used in This Book (Page 17)
- Using Code Examples (Page 18)
- Safari® Books Online (Page 18)
- How to Contact Us (Page 19)
- Acknowledgments (Page 19)
- Chapter 1. Lights Out—Hacking Wireless Lightbulbs to Cause Sustained Blackouts (Page 21)
- Why hue? (Page 22)
- Controlling Lights via the Website Interface (Page 24)
- Information Leakage (Page 32)
- Drive-by Blackouts (Page 33)
- Weak Password Complexity and Password Leaks (Page 34)
- Controlling Lights Using the iOS App (Page 36)
- Stealing the Token from a Mobile Device (Page 45)
- Malware Can Cause Perpetual Blackouts (Page 45)
- Changing Lightbulb State (Page 50)
- If This Then That (IFTTT) (Page 52)
- Conclusion (Page 55)
- Chapter 2. Electronic Lock Picking—Abusing Door Locks to Compromise Physical Security (Page 57)
- Hotel Door Locks and Magnetic Stripes (Page 58)
- The Onity Door Lock (Page 58)
- The Magnetic Stripe (Page 59)
- The Programming Port (Page 61)
- Security Issues (Page 61)
- Vendor Response (Page 62)
- The Case of Z-Wave-Enabled Door Locks (Page 63)
- Z-Wave Protocol and Implementation Analysis (Page 63)
- Exploiting Key-Exchange Vulnerability (Page 64)
- Bluetooth Low Energy and Unlocking via Mobile Apps (Page 65)
- Understanding Weaknesses in BLE and Using Packet-Capture Tools (Page 66)
- Kevo Mobile App Insecurities (Page 70)
- Conclusion (Page 77)
- Chapter 3. Assaulting the Radio Nurse—Breaching Baby Monitors and One Other Thing (Page 79)
- The Foscam Incident (Page 80)
- Foscam Vulnerabilities Exposed by Researchers (Page 81)
- Using Shodan to Find Baby Monitors Exposed on the Internet (Page 82)
- Exploiting Default Credentials (Page 84)
- Exploiting Dynamic DNS (Page 85)
- The Foscam Saga Continues (Page 87)
- The Belkin WeMo Baby Monitor (Page 88)
- Bad Security by Design (Page 95)
- Malware Gone Wild (Page 96)
- Some Things Never Change: The WeMo Switch (Page 97)
- Conclusion (Page 103)
- Chapter 4. Blurred Lines—When the Physical Space Meets the Virtual Space (Page 105)
- SmartThings (Page 106)
- Hijacking Credentials (Page 115)
- Abusing the Physical Graph (Page 120)
- SmartThings SSL Certificate Validation Vulnerability (Page 125)
- Interoperability with Insecurity Leads to…Insecurity (Page 126)
- SmartThings and hue Lighting (Page 127)
- SmartThings and the WeMo Switch (Page 133)
- Conclusion (Page 138)
- Chapter 5. The Idiot Box—Attacking “Smart” Televisions (Page 141)
- The TOCTTOU Attack (Page 143)
- The Samsung LExxB650 Series (Page 144)
- The Exploit (Page 146)
- You Call That Encryption? (Page 149)
- Understanding XOR (Page 149)
- I call it Encraption (Page 152)
- Understanding and Exploiting the App World (Page 156)
- Decrypting Firmware (Page 156)
- Cursory Exploration of the Operating System (Page 158)
- Remotely Exploiting a Samsung Smart TV (Page 162)
- Inspecting Your Own Smart TV (and Other IoT Devices) (Page 166)
- Say Hello to the WiFi Pineapple Mark V (Page 166)
- Capturing credentials and stripping TLS (Page 170)
- Conclusion (Page 174)
- Chapter 6. Connected Car Security Analysis—From Gas to Fully Electric (Page 177)
- The Tire Pressure Monitoring System (TPMS) (Page 178)
- Reversing TPMS Communication (Page 179)
- Eavesdropping and Privacy Implications (Page 181)
- Spoofing Alerts (Page 182)
- Exploiting Wireless Connectivity (Page 183)
- Injecting CAN Data (Page 184)
- Bluetooth Vulnerabilities (Page 186)
- Vulnerabilities in Telematics (Page 187)
- Significant Attack Surface (Page 189)
- The Tesla Model S (Page 190)
- Locate and Steal a Tesla the Old-Fashioned Way (Page 194)
- Social Engineering Tesla Employees and the Quest for Location Privacy (Page 198)
- Handing Out Keys to Strangers (Page 199)
- Or Just Borrow Someone’s Phone (Page 201)
- Additional Information and Potential Low-Hanging Fruit (Page 202)
- AutoPilot and the Autonomous Car (Page 205)
- Conclusion (Page 207)
- Chapter 7. Secure Prototyping—littleBits and cloudBit (Page 209)
- Introducing the cloudBit Starter Kit (Page 210)
- Setting Up the cloudBit (Page 212)
- Designing the SMS Doorbell (Page 219)
- Oops, We Forgot the Button! (Page 221)
- Security Evaluation (Page 224)
- WiFi Insecurity, Albeit Brief (Page 225)
- Sneaking in Command Execution (Page 227)
- One Token to Rule them All (Page 230)
- Beware of Hardware Debug Interfaces (Page 233)
- Abuse Cases in the Context of Threat Agents (Page 236)
- Nation-States, Including the NSA (Page 237)
- Terrorists (Page 238)
- Criminal Organizations (Page 238)
- Disgruntled or Nosy Employees (Page 239)
- Hacktivists (Page 241)
- Vandals (Page 242)
- Cyberbullies (Page 246)
- Predators (Page 247)
- Bug Bounty Programs (Page 247)
- Conclusion (Page 249)
- Chapter 8. Securely Enabling Our Future—A Conversation on Upcoming Attack Vectors (Page 251)
- The Thingbots Have Arrived (Page 251)
- The Rise of the Drones (Page 252)
- Cross-Device Attacks (Page 253)
- Hearing Voices (Page 254)
- IoT Cloud Infrastructure Attacks (Page 258)
- Backdoors (Page 259)
- The Lurking Heartbleed (Page 260)
- Diluting the Medical Record (Page 261)
- The Data Tsunami (Page 264)
- Targeting Smart Cities (Page 265)
- Interspace Communication Will Be a Ripe Target (Page 266)
- The Dangers of Superintelligence (Page 267)
- Conclusion (Page 268)
- Chapter 9. Two Scenarios—Intentions and Outcomes (Page 271)
- The Cost of a Free Beverage (Page 271)
- There’s a Party at Ruby Skye (Page 272)
- Leveraging the BuzzWord (Page 273)
- The Board Meeting (Page 273)
- What Went Wrong? (Page 274)
- A Case of Anger, Denial, and Self-Destruction (Page 275)
- The Benefit of LifeThings (Page 275)
- Social Engineering Customer Support by Caller ID Spoofing (Page 276)
- The (In)Secure Token (Page 277)
- Total Ownership (Page 279)
- The Demise of LifeThings (Page 280)
- Conclusion (Page 283)
- Index (Page 285)
- Colophon (Page 291)
- About the Author  (Page 291)