Attackers may attempt exploiting Internet of Things (IoT) devices to operate them unduly as well as to gather personal data of the legitimate device owners'. Vulnerability Assessment and Penetration Testing (VAPT) sessions help to verify the effectiveness of the adopted security measures. However, VAPT over IoT devices, namely VAPT targeted at IoT devices, is an open research challenge due to the variety of target technologies and to the creativity it may require. Therefore, this article aims at guiding penetration testers to conduct VAPT sessions over IoT devices by means of a new cyber Kill Chain (KC) termed PETIoT. Several practical applications of PETIoT confirm that it is general, while its main novelty lies in the combination of attack and defence steps. PETIoT is demonstrated on a relevant example, the best-selling IP camera on Amazon Italy, the TAPO C200 by TP-Link, assuming an attacker who sits on the same network as the device's in order to assess all the network interfaces of the device. Additional knowledge is generated in terms of three zero-day vulnerabilities found and practically exploited on the camera, one of these with High severity and the other two with Medium severity by the CVSS standard. These are camera Denial of Service (DoS), motion detection breach and video stream breach. The application of PETIoT culminates with the proof-of-concept of a home-made fix, based on an inexpensive Raspberry Pi 4 Model B device, for the last vulnerability. Ultimately, our responsible disclosure with the camera vendor led to the release of a firmware update that fixes all found vulnerabilities, confirming that PetIoT has valid impact in real-world scenarios.
翻译:攻击者可能试图利用Things(IoT)的互联网装置来不适当地操作这些装置,并收集合法装置所有人的个人数据。脆弱性评估和渗透测试(VAPT)会有助于核实所采用的安全措施的有效性。然而,对IoT装置的VAPT(即针对IoT装置的VAPT)是公开的研究挑战,因为目标技术种类繁多,而且可能需要创造性。因此,这篇文章的目的是指导穿透测试者通过称为PETTIT的新的网络杀手链(KC)在Iot设备上进行VAPT课程。PETIoT的若干实际应用证实,这是一般性的,而其主要的新颖之处在于攻击和防御步骤的结合。 PETIO是一个相关的例子,即亚马逊意大利最畅销的IP摄像头、TP-Link的所有TPAPO C200,假定攻击者与该装置处于同一网络上,以便评估该装置的所有网络界面界面。另外一项知识是建立在SDVS的透明性、真实性、真实性、真实性、真实性、真实性、真实性、真实性、真实性、真实性、真实性、真实性、真实性、真实性、真实性、真实性、真实性、真实性、真实性、真实性、真实性、真实性、真实性、真实性、真实性、真实性、真实性、真实性、真实性、真实性能能能能能能能能能能能能能能能能能、通过Sl 一种比、真实性、真实性、真实性、真实性、真实性、真实性、真实性、真实性、真实性、真实性能能、真实性能、真实性能、真实性能能能能能能能变变变变变变变变变变变变、以C4的、真实性能、真实性、真实性能、真实性、真实性、真实性、真实性、真实性、真实性、真实性能、真实性、真实性能、真实性能能能、真实性能、真实性能、真实性能、真实性能、真实性能能能、真实性能、通过SOVDVDVDVDVDVDVDVDVDVDVDVDVDVDV的变能能能能能能能、