
Explore setting up a personal IoT testing lab with VMware and Kali Linux, extract and emulate firmware with FERMA Dying, and analyze case studies on remote code execution.
Set up a complete IoT penetration testing lab by installing VMware Workstation, Latifi OS with preinstalled tools, and firmware for analysis within a Debian-based virtual environment.
Explore how the internet of things connects devices and gateways through direct connections and gateway architectures, enabling data transfer and highlighting security vulnerabilities and attack vectors.
Use Shodan and Google to locate IoT devices like webcams and industrial control systems by IP, identify open ports and web servers, and recognize vulnerabilities with emphasis on authorized testing.
Explore what firmware is, its bootloader, kernel, file systems, and busybox utilities across architectures like MIPS and ARM, and why firmware analysis aids IoT security research.
Explore extracting and analyzing IoT firmware with boardwalk, focusing on the software approach. Inspect architecture, compression, and file systems, and review credentials in shadow to spot backdoors.
Identify the attack surface by downloading and extracting IoT firmware, analyzing its content with binwalk and grep, and spotting insecure protocols like telnet in a wireless bridge device, with authorization.
This lecture guides you through analyzing and extracting IoT firmware, locating usernames and password hashes, and cracking passwords with Hashcat using a dictionary attack to gain device access.
Emulate an IoT firmware using the Firmadyne emulator and a Python automation script, bypassing the need for a physical device while accessing the firmware via its web interface.
We download and analyze a vulnerable IoT firmware, extract its files, identify a vulnerable page enabling remote code execution, and demonstrate exploitation via a proxy and burp suite.
Learn how shellcodes are small, architecture-dependent machine code payloads used after exploiting a vulnerability. Generate reverse, bind, or two-stage shellcodes with MSF venom, and set up delivery and listeners.
Learn how to backdoor an IoT device by extracting and analyzing its firmware, generating a payload, and flashing it to persist on startup.
Emulate firmware and demonstrate a dictionary attack against the IoT login page using Burp Suite to access the control panel and analyze payloads and login status.
Extract and analyze firmware to detect backdoors by examining scripts and firewall configurations. Decode suspicious base64 strings to reveal a listener on port 763 for remote access.
The wrap-up stresses that IoT devices often prioritize functionality over security, leaving wireless and firmware layers vulnerable to backdoors, and urges ongoing education with practical IoT hacking resources.
Welcome to Practical Internet of Things Hacking - 2021
Nowadays almost, every device has Internet access. IoT promises to bring supply chain efficiency, decreased maintenance downtime, home conveniences, and much more. There’s a lot of power being bestowed upon these little guys. And with great power… comes great vulnerabilities. Every IoT device no matter large or small it is, needs an operating environment. In the IoT world of embedded systems, that’s called firmware. But what is it, how do we hack it and what are the impacts for your home, in your organization and on your careers? We’re very excited to bring you a mini course of its kind that will takes you into a unique journey of extracting, reversing and exploiting the Firmware of Internet of Things. This course is ideal for penetration testers, security enthusiasts and network administrators.
The following materials will be covered in this course:
Introduction to Internet of Things (IoT).
Installing AttifyOS the de-facto operating system for Internet of Things penetration testing.
Learn how to extract and explore IoT firmware.
Learn how to find vulnerabilities in a specific IoT firmware.
Learn how to practically backdoor a specific IoT firmware.
Learn how to manually detect backdoors in IoT firmware.
Learn how to perform dictionary attack against IoT control panel login forms.
Learn how to emulate Firmware devices without the need to purchase or brick an IoT device.
No prior knowledge is needed!
It doesn't need any prior knowledge to learn IoT hacking however, a basic Linux skills will be like putting a cherry on the top of the cake :)
This course starts with very basics. First, you will learn how to install the tools, some terminology. Then the show will start and you will learn everything with hands-on practices.
Free and popular tools are used you don’t need to buy any tool or software.
You'll also get:
Lifetime Access to The Course.
Fast & Friendly Support in the Q&A section.
Udemy Certificate of Completion Ready for Download.
24/7 support, so if you have any questions you can post them in the Q&A section or DM me and I will make sure to get back to you ASAP.
Very Important Note:
The word hacking in the course implies performing Ethical penetration testing against your own devices or the devices that you already obtained a written permission from their administrators or owners.