DEF CON 32 - Anyone can hack IoT- Beginner’s Guide to Hacking Your First IoT Device - Andrew Bellini

  Рет қаралды 86,251

DEFCONConference

DEFCONConference

Күн бұрын

Yes, anyone can hack IoT devices and I’ll show you how! It doesn’t matter if you’re an experienced pen tester in other fields, completely new to cybersecurity or just IoT curious, by the end of this talk you’ll have the knowledge to hack your first device. You might be thinking - but I thought IoT was complicated, required knowledge of hardware, and expensive tools. In this talk, I’m here to dispel those myths by directly showing you the methodology, tools and tactics you can use to go and hack an IoT device today (or maybe when you get home). I’ll cover what IoT devices are best for beginners, what tools you need (and don’t need), how to build a small toolkit for less than $100, common tactics to get a foothold into IoT devices and how to find your first vulnerability or bug.

Пікірлер: 44
@Twoshoes22Jason
@Twoshoes22Jason Ай бұрын
Probably one of the clearest and most concise talks this year from what I've seen so far
@the_sandman00
@the_sandman00 20 күн бұрын
Found 5 vulnerabilities on the first day. 1 critical, 1 high. Thanks man. This sparked a curiosity
@weihe1220
@weihe1220 8 күн бұрын
Hi bro, how did you do it? Can you share some relevant basic information?
@the_sandman00
@the_sandman00 8 күн бұрын
@ portscan-> found ftp -> did enumeration-> found default cred login -> in ftp rootfs access is granted -> dumped entire filesystem-> can modify entire fs, etc
@SmallTimeTrees
@SmallTimeTrees 2 күн бұрын
@@weihe1220did you watch the video?
@74Gee
@74Gee Ай бұрын
Without a doubt this is the best IoT hacking speed run out there.
@coffeehousephilosopher7936
@coffeehousephilosopher7936 Ай бұрын
This is why I love this channel, any talk I might have had to miss or force to choose over the other is right on this channel... Thanks DEFCONconferences
@Entropy67
@Entropy67 Ай бұрын
Wow super useful talk, thanks! I've been interested in IoT hacking but too busy to look into it, I just happen to have almost all the tools and a cheap router... And some free time...
@chsovi7164
@chsovi7164 Ай бұрын
"we're expecting there to be a big surge of IoT devices because of AI" is just about the scariest news someone could drop
@frankwuolukka2087
@frankwuolukka2087 20 күн бұрын
Great presentation, thank you for the clear and concise talk. I believe you said that folks there could get a copy of your slides but would you mind making them available to the rest of us?
@stevet7522
@stevet7522 Ай бұрын
These talks just reinforce the reason i dont have IoT, smart devices, or really much of anything in my house. The fact that i have wifi makes me paranoid enough.
@Frappe3621
@Frappe3621 Ай бұрын
My iot lights use WiFi to make themselves into motion sensors! They send it between themselves and see where they are interrupted! Any WiFi enabled device could potentially do this, your WiFi can tell where you are in your house
@jean-naymar602
@jean-naymar602 Ай бұрын
@@Frappe3621 New fear unlocked.
@cracc_baby
@cracc_baby 10 күн бұрын
bruh im kinda scared rn.. my cats new litterbox needed to connect to wifi (allegedly for firmware updates) same with the vaccum! both made in china btw :(
@daviddunkelheit9952
@daviddunkelheit9952 Ай бұрын
Power capacitors that are discharged can develop ‘phantom charge’ as the dielectric was in a contrary position physically for longer duration. Ambient charge is enough to cause the capacitor’s to return to previous charged state.
@theodorekorehonen
@theodorekorehonen 13 күн бұрын
A lot of devices nowadays have parasitic resistors to make them safe(r) but I still always short the big filter caps just to make sure. And I do indeed get some sparks sometimes
@GameX236
@GameX236 3 күн бұрын
Sounds fun!
@AndreeaCe
@AndreeaCe Ай бұрын
1: pick the target, usually the target is the device not the person. Usually...
@ZambeziSentinel
@ZambeziSentinel 25 күн бұрын
I took screenshots of all the slides and fed to my AI to summarise. Did a good job 😊
@ShermaMahdi
@ShermaMahdi 24 күн бұрын
Amazing idea💥 Did de same thanks
@3rdeyesociety
@3rdeyesociety 11 күн бұрын
why wouldnt you just copy paste the transcript...
@ZambeziSentinel
@ZambeziSentinel 11 күн бұрын
@3rdeyesociety on phone and can't copy. Tried that first
@ZambeziSentinel
@ZambeziSentinel 11 күн бұрын
@@3rdeyesociety I tried but phone would not let me. Took a while to get every slide lol
@eyezikandexploits
@eyezikandexploits 29 күн бұрын
Been making my own showdan type project locally scanning for IoT and rigged a grep script for it
@joew1865
@joew1865 Ай бұрын
What was the software being used in the Reverse Engineering binaries & libs section?
@joew1865
@joew1865 Ай бұрын
Nevermind... it's called Ghidra
@daviddunkelheit9952
@daviddunkelheit9952 13 күн бұрын
@@joew1865 yes and it is suggested to use with Amazon Coretto rather than regular Java
@claasschlueter
@claasschlueter 16 күн бұрын
Really enjoyed it! Thanks
@BsktImp
@BsktImp Ай бұрын
07:58 Capacitors at even 5V or 12V: "hold my beer."
@AnonymousVv3
@AnonymousVv3 8 күн бұрын
Like Harvard or EC-COUNCIL University or etc for cyber degrees
@AmandaCook-rc8ce
@AmandaCook-rc8ce 28 күн бұрын
Hack or be hacked. It's like being blind and while they all can see.
@daviddunkelheit9952
@daviddunkelheit9952 Ай бұрын
I followed this beginner guide and I just couldn’t hack it.
@Pinkman875
@Pinkman875 20 күн бұрын
somebody knows any resource to keep digging in the iot / hardware hacking?
@mk71b
@mk71b Ай бұрын
8:55 He should have said "unplug the power cord."
@radwizard
@radwizard 24 күн бұрын
Remember those books from the 90s and early 2000s that claimed this…. But when you read them, they are the basics to using a console or lessons on OSI and TCP/IP? 😂❤
@XRatedPoetry
@XRatedPoetry Ай бұрын
We need 6 more likes on this video! No more, no less!
@criticalgrower
@criticalgrower Ай бұрын
When i see someone Who really knows what he s talking about ❤ how much i love that stuff unfortunately i m not lucky and good enough to make a living with it Bless Bellini ciao
@andrewc.2952
@andrewc.2952 24 күн бұрын
Is it sad that my immediate definition for an LoT device is that it means "Left on table". 😂 Like when people leave their devices unattended. Don't mind me, kinda new here. Lol
@AnonymousVv3
@AnonymousVv3 8 күн бұрын
Botnet: Online DDOS or DOS attack.
@iluvyunie
@iluvyunie Ай бұрын
this is why I never use my phone or pc to control any of these things
@Nicholas-f5
@Nicholas-f5 23 күн бұрын
Anyone hardware hacking in Austin, feel free to PM
Кто круче, как думаешь?
00:44
МЯТНАЯ ФАНТА
Рет қаралды 5 МЛН
The Ultimate Sausage Prank! Watch Their Reactions 😂🌭 #Unexpected
00:17
La La Life Shorts
Рет қаралды 8 МЛН
this new Linux feature makes hacking IMPOSSIBLE
11:08
Low Level
Рет қаралды 472 М.
DEF CON 31 - Private Keys in Public Places - Tom Pohl
40:06
DEFCONConference
Рет қаралды 57 М.
Hacker's Guide to UART Root Shells
17:40
Flashback Team
Рет қаралды 499 М.
how is this hacking tool legal?
11:42
Low Level
Рет қаралды 405 М.
Self-Extracting Executables for Hackers
41:06
John Hammond
Рет қаралды 87 М.
DEF CON 32 - The Darkest Side of Bug Bounty - Jason Haddix
32:30
DEFCONConference
Рет қаралды 44 М.
Tactics of Physical Pen Testers
44:17
freeCodeCamp Talks
Рет қаралды 914 М.
Кто круче, как думаешь?
00:44
МЯТНАЯ ФАНТА
Рет қаралды 5 МЛН