IoT PenetrationTesting – A Deep Dive into Hidden Flaws

No ratings

Presented at BsidesZurich 2018 by

The presentation is aimed at disclosing the various hard to find vulnerabilities in IoT ecosystem. While we have billions of IoT device in cyberspace most still lack in basic security. One of the most important and hard to test part of IoT device is its firmware and vulnerabilities at hardware level. This talk will be aimed at understanding IoT ecosystem, identifying attack surfaces, reverse engineering the firmware, understanding firmware file systems, extracting standard and non standard sections from firmware, performing static, dynamic and behavioural analysis of firmware as well as hardware hacking. Talk will be accompanied with demo showing digging the firmware for various secrets, emulating cross platform binaries, fuzzing and finding buffer overflows, hardware hacking (SPI,UART,I2C). Talk and demo will be done with open source tools so audience can gain maximum from it. The major takeaways of the talk will be deep insight and understanding of pen testing IoT devices.