
Abusing the Internet of Things
Description
Alles über E-Books | Antworten auf Fragen rund um E-Books, Kopierschutz und Dateiformate finden Sie in unserem Info- & Hilfebereich.
This book is a marvellous thing: an important intervention in the policy debate about information security and a practical text for people trying to improve the situation.
? Cory Doctorowauthor, co-editor of Boing BoingA future with billions of connected "things" includes monumental security concerns. This practical book explores how malicious attackers can abuse popular IoT-based devices, including wireless LED lightbulbs, electronic door locks, baby monitors, smart TVs, and connected cars.
If you're part of a team creating applications for Internet-connected devices, this guide will help you explore security solutions. You'll not only learn how to uncover vulnerabilities in existing IoT devices, but also gain deeper insight into an attacker's tactics.
- Analyze the design, architecture, and security issues of wireless lighting systems
- Understand how to breach electronic door locks and their wireless mechanisms
- Examine security design flaws in remote-controlled baby monitors
- Evaluate the security design of a suite of IoT-connected home products
- Scrutinize security vulnerabilities in smart TVs
- Explore research into security weaknesses in smart cars
- Delve into prototyping techniques that address security in initial designs
- Learn plausible attacks scenarios based on how people will likely use IoT devices
More details
Other editions
Additional editions

Content
- Intro
- Copyright
- Table of Contents
- Foreword
- Preface
- Who This Book Is For
- How to Use This Book
- Conventions Used in This Book
- Using Code Examples
- Safari® Books Online
- How to Contact Us
- Acknowledgments
- Chapter 1. Lights Out-Hacking Wireless Lightbulbs to Cause Sustained Blackouts
- Why hue?
- Controlling Lights via the Website Interface
- Information Leakage
- Drive-by Blackouts
- Weak Password Complexity and Password Leaks
- Controlling Lights Using the iOS App
- Stealing the Token from a Mobile Device
- Malware Can Cause Perpetual Blackouts
- Changing Lightbulb State
- If This Then That (IFTTT)
- Conclusion
- Chapter 2. Electronic Lock Picking-Abusing Door Locks to Compromise Physical Security
- Hotel Door Locks and Magnetic Stripes
- The Onity Door Lock
- The Magnetic Stripe
- The Programming Port
- Security Issues
- Vendor Response
- The Case of Z-Wave-Enabled Door Locks
- Z-Wave Protocol and Implementation Analysis
- Exploiting Key-Exchange Vulnerability
- Bluetooth Low Energy and Unlocking via Mobile Apps
- Understanding Weaknesses in BLE and Using Packet-Capture Tools
- Kevo Mobile App Insecurities
- Conclusion
- Chapter 3. Assaulting the Radio Nurse-Breaching Baby Monitors and One Other Thing
- The Foscam Incident
- Foscam Vulnerabilities Exposed by Researchers
- Using Shodan to Find Baby Monitors Exposed on the Internet
- Exploiting Default Credentials
- Exploiting Dynamic DNS
- The Foscam Saga Continues
- The Belkin WeMo Baby Monitor
- Bad Security by Design
- Malware Gone Wild
- Some Things Never Change: The WeMo Switch
- Conclusion
- Chapter 4. Blurred Lines-When the Physical Space Meets the Virtual Space
- SmartThings
- Hijacking Credentials
- Abusing the Physical Graph
- SmartThings SSL Certificate Validation Vulnerability
- Interoperability with Insecurity Leads to.Insecurity
- SmartThings and hue Lighting
- SmartThings and the WeMo Switch
- Conclusion
- Chapter 5. The Idiot Box-Attacking "Smart" Televisions
- The TOCTTOU Attack
- The Samsung LExxB650 Series
- The Exploit
- You Call That Encryption?
- Understanding XOR
- I call it Encraption
- Understanding and Exploiting the App World
- Decrypting Firmware
- Cursory Exploration of the Operating System
- Remotely Exploiting a Samsung Smart TV
- Inspecting Your Own Smart TV (and Other IoT Devices)
- Say Hello to the WiFi Pineapple Mark V
- Capturing credentials and stripping TLS
- Conclusion
- Chapter 6. Connected Car Security Analysis-From Gas to Fully Electric
- The Tire Pressure Monitoring System (TPMS)
- Reversing TPMS Communication
- Eavesdropping and Privacy Implications
- Spoofing Alerts
- Exploiting Wireless Connectivity
- Injecting CAN Data
- Bluetooth Vulnerabilities
- Vulnerabilities in Telematics
- Significant Attack Surface
- The Tesla Model S
- Locate and Steal a Tesla the Old-Fashioned Way
- Social Engineering Tesla Employees and the Quest for Location Privacy
- Handing Out Keys to Strangers
- Or Just Borrow Someone's Phone
- Additional Information and Potential Low-Hanging Fruit
- AutoPilot and the Autonomous Car
- Conclusion
- Chapter 7. Secure Prototyping-littleBits and cloudBit
- Introducing the cloudBit Starter Kit
- Setting Up the cloudBit
- Designing the SMS Doorbell
- Oops, We Forgot the Button!
- Security Evaluation
- WiFi Insecurity, Albeit Brief
- Sneaking in Command Execution
- One Token to Rule them All
- Beware of Hardware Debug Interfaces
- Abuse Cases in the Context of Threat Agents
- Nation-States, Including the NSA
- Terrorists
- Criminal Organizations
- Disgruntled or Nosy Employees
- Hacktivists
- Vandals
- Cyberbullies
- Predators
- Bug Bounty Programs
- Conclusion
- Chapter 8. Securely Enabling Our Future-A Conversation on Upcoming Attack Vectors
- The Thingbots Have Arrived
- The Rise of the Drones
- Cross-Device Attacks
- Hearing Voices
- IoT Cloud Infrastructure Attacks
- Backdoors
- The Lurking Heartbleed
- Diluting the Medical Record
- The Data Tsunami
- Targeting Smart Cities
- Interspace Communication Will Be a Ripe Target
- The Dangers of Superintelligence
- Conclusion
- Chapter 9. Two Scenarios-Intentions and Outcomes
- The Cost of a Free Beverage
- There's a Party at Ruby Skye
- Leveraging the BuzzWord
- The Board Meeting
- What Went Wrong?
- A Case of Anger, Denial, and Self-Destruction
- The Benefit of LifeThings
- Social Engineering Customer Support by Caller ID Spoofing
- The (In)Secure Token
- Total Ownership
- The Demise of LifeThings
- Conclusion
- Index
- Colophon
- About the Author
System requirements
File format: PDF
Copy-Protection: Adobe-DRM (Digital Rights Management)
System requirements:
- Computer (Windows; MacOS X; Linux): Install the free reader Adobe Digital Editions prior to download (see eBook Help).
- Tablet/smartphone (Android; iOS): Install the free app Adobe Digital Editions or the app PocketBook before downloading (see eBook Help).
- E-reader: Bookeen, Kobo, Pocketbook, Sony, Tolino and many more (only limited: Kindle).
The file format PDF always displays a book page identically on any hardware. This makes PDF suitable for complex layouts such as those used in textbooks and reference books (images, tables, columns, footnotes). Unfortunately, on the small screens of e-readers or smartphones, PDFs are rather annoying, requiring too much scrolling.
This eBook uses Adobe-DRM, a „hard” copy protection. If the necessary requirements are not met, unfortunately you will not be able to open the eBook. You will therefore need to prepare your reading hardware before downloading.
Please note: We strongly recommend that you authorise using your personal Adobe ID after installation of any reading software.
For more information, see our eBook Help page.