- 30
- 62 233
IoT Village
เข้าร่วมเมื่อ 21 พ.ค. 2020
IoT Village advocates for advancing security in the Internet of Things (IoT) industry through bringing researchers and industry together. IoT Village hosts talks by expert security researchers, interactive hacking labs, live bug hunting in the latest IoT tech, and competitive IoT hacking contests.
CBC Padding Walkthrough
In this video, join Ali Esparza from IoT Village in a hands on example of AES CBC Padding Oracle Attack. You will learn a bit about the operation of AES CBC and how it can be broken.
มุมมอง: 543
วีดีโอ
The Budget Hacker’s Arsenal: A Review of Microcontroller-Based Cyber Weapons
มุมมอง 258ปีที่แล้ว
The world of hacking has a secret: power doesn't have to come with a high price tag. Dive into the world of budget-friendly microcontrollers with Kody, and discover the might of the ESP8266, ESP32s2, and others in the realm of cyber warfare. He’ll demonstrate microcontroller-based projects using the ESP8266, ESP32s2, and other platforms to perform Wi-Fi phishing, HID bad USB attacks, and bleedi...
Making for Hackers 101
มุมมอง 120ปีที่แล้ว
“I used to take everything apart when I was a kid.” This is a common story heard when asked of hackers how they got their start. That insatiable desire to figure out how things work;how to make things do what they were never meant to do. It’s all part of the hacker mindset. Break. Mod. Tinker! But it’s not just hackers. Similar origin stories come from physicists, engineers and many others in S...
From RCE to proper shell - when the stars are not aligned
มุมมอง 109ปีที่แล้ว
In 2015, Zoltan Balazs bought a cheap IP camera. While setting it up, he accidentally found a command injection vulnerability. Exploiting the vulnerability was not trivial due to character restrictions, payload length restriction, and the command was executed in the background - totally blind. The first half of the presentation will walk through the journey of how he exploited the vulnerability...
From Hacker to Accidental CEO
มุมมอง 80ปีที่แล้ว
What is ethical hacking, and why is it important? In this video, IoT Village co-founder and ISE's CEO Stephen Bono is interviewed by Ben Schmerler, Senior Solutions Consultant at ISE. Together, they discuss Steve's hacker roots, and how he founded a company of ethical hackers who work with some of the largest corporations in the world.
Static Analysis of IoT Binaries - Analyzing the TP-Link Tapo C210 | Part 3
มุมมอง 394ปีที่แล้ว
In this video we continue our series on the TP-Link Tapo C210 camera. Using the shell we have from the UART interface, we extract the binary for the device's HTTPS server in order to analyze it in Ghidra. While analyzing the binary, we follow along with a blog which demonstrates how a command injection vulnerability was found in a previous model of Tapo camera. After following the execution flo...
Getting UART - Analyzing the TP-Link Tapo C210 | Part 2
มุมมอง 881ปีที่แล้ว
In this video we'll demonstrate how hackers can gain access to an IoT device by targeting physical components such as the UART interface. Because UART is used by vendors in order to debug the device during the development process, often times it will provide root access to the system. This is what makes UART and other serial protocol interfaces prime targets for hackers. If you'd like to follow...
IoT Network Analysis - Analyzing the TP-Link Tapo C210 | Part 1
มุมมอง 7752 ปีที่แล้ว
Analyzing network protocols is an important part of any assessment of IoT devices. Some of the most impactful exploits of devices are found due to custom implementations of network protocols. In this video we go over a few steps of how we conduct manual network analysis of IoT devices. Learn more about the work of the IoT Village team: www.ise.io/research/
Emulating IoT Firmware - DLink DCS932
มุมมอง 5552 ปีที่แล้ว
Emulating firmware can be useful when analyzing a device because it can give you something more flexible to work with, and the process of getting it working will get you familiar with it as well, which is good because each IoT device is unique.
Cybersecurity Career Panel - Don Donzal, Sara Pickering, John Hammond
มุมมอง 2353 ปีที่แล้ว
IoT Village Career Panel. Learn from industry insiders what certs matter at what points in your career. Be sure to check in at the Certs, Careers, and Chat Networking Lounge immediately following the panel for one-on-one advice.
Practical IoT Hacking: Fireside Chat with Authors - Paulino Calderon, Fotios Chantzis, Lily Newman
มุมมอง 2673 ปีที่แล้ว
Hear from authors @calderpwn and @ithilgore discuss their new book Practical IoT Hacking and learn about attacking the internet of things, discovering the art of passive reconnaissance, and assessing security on all layers of an IoT system.
Command Injection Workshop Walkthrough - Zoltán Balázs (@zh4ck)
มุมมอง 1723 ปีที่แล้ว
"Command injection is one of the most commonly exploited vulnerabilities in the IoT area. What makes exploiting command injection fun is all the different restrictions. Can't you inject space? Are you limited in the number of characters? Can't you see the output of the executed command? Is the command executed in a background process? Are you interested in finding a command injection vulnerabil...
No More Burnout - Chloé Messdaghi @ChloeMessdaghi
มุมมอง 1073 ปีที่แล้ว
"Have you ever felt like no matter how much sleep you get, you feel exhausted? Struggle to concentrate? Having trouble balancing work and personal life? Or perhaps feel your work is your life? Burnout. We all go through it at one point. It feels like you are low on battery and it can cause emotional and physical issues. Mental health is an ongoing issue within infosec before and during COVID-19...
Toward A More Secure Secure IP Camera - John Tyner
มุมมอง 923 ปีที่แล้ว
Most, if not all IoT cameras, stream or are able to stream their audio/video using the RTSP protocol. For general ease of use, these cameras rarely, if ever, implement authentication or encryption for their streams. Higher end manufacturers like Axis and Bosch utilize SRTP, and various VMS systems can take advantage of that to enable encrypted streams. However, those VMS systems do not always c...
One Way Ticket To A Smart Destination: Evolution Of Smart Airports - Ecem KISACIK
มุมมอง 1.6K3 ปีที่แล้ว
IoT has a very broad application areas. Through the last decade, IoT had advanced in many sectors. Aviation is one these sectors that are developing by these enhancements. In this paper, I investigate the smart systems and services at the airports. Smart airports use various integrated systems and services at different levels of operation such as baggage claim, gates, check-in kiosks, etc. More...
Magic Home Pro Device Takeover - Victor Hanna @9lyph
มุมมอง 2013 ปีที่แล้ว
Magic Home Pro Device Takeover - Victor Hanna @9lyph
Emulating IoT Malware and Firmware with Docker+QEMU - Ilya @drablyechos
มุมมอง 4.7K4 ปีที่แล้ว
Emulating IoT Malware and Firmware with Docker QEMU - Ilya @drablyechos
SYNwall - A Zero-configuration (IoT) Firewall - Cesare Pizzi @red5heep
มุมมอง 1934 ปีที่แล้ว
SYNwall - A Zero-configuration (IoT) Firewall - Cesare Pizzi @red5heep
Panel: Effects of IoT on Corporate Security During Work from Home
มุมมอง 844 ปีที่แล้ว
Panel: Effects of IoT on Corporate Security During Work from Home
Power Line Communication Security on Smart Meters - Fatih Kayran @kayranfatih
มุมมอง 6704 ปีที่แล้ว
Power Line Communication Security on Smart Meters - Fatih Kayran @kayranfatih
SCADA/ICS Inherited Insecurity: From Nuclear Power Plants to Oil Rigs - Aleksander Gorkowienko
มุมมอง 1354 ปีที่แล้ว
SCADA/ICS Inherited Insecurity: From Nuclear Power Plants to Oil Rigs - Aleksander Gorkowienko
The Great Hotel Hack: Adventures in Attacking Hospitality Industry - Etizaz Mohsin @aitezazmohsin
มุมมอง 3074 ปีที่แล้ว
The Great Hotel Hack: Adventures in Attacking Hospitality Industry - Etizaz Mohsin @aitezazmohsin
Do You Even Segment Your IoT Network Bro? - Arun Raghuramu @finalfr0ntier
มุมมอง 2514 ปีที่แล้ว
Do You Even Segment Your IoT Network Bro? - Arun Raghuramu @finalfr0ntier
The Evolving Security Policy Landscape and How it Impacts You - Amit Elazari @amitelazari
มุมมอง 884 ปีที่แล้ว
The Evolving Security Policy Landscape and How it Impacts You - Amit Elazari @amitelazari
Identification of the CABLEHAUNT eCos Bug Using GHIDRA - Peter Eacmen @eacmen
มุมมอง 4544 ปีที่แล้ว
Identification of the CABLEHAUNT eCos Bug Using GHIDRA - Peter Eacmen @eacmen
A Look at IoT Device Inter-chip Communication Analysis - Deral Heiland @percent_x
มุมมอง 2264 ปีที่แล้ว
A Look at IoT Device Inter-chip Communication Analysis - Deral Heiland @percent_x
Hacking Reimaged Retro Computers - David Lodge @tautology0
มุมมอง 2654 ปีที่แล้ว
Hacking Reimaged Retro Computers - David Lodge @tautology0
Flipper Zero - Multi-Tool Device for Hackers in a Tamagotchi Body - Pavel Zhovner @zhovner
มุมมอง 47K4 ปีที่แล้ว
Flipper Zero - Multi-Tool Device for Hackers in a Tamagotchi Body - Pavel Zhovner @zhovner
Did they ever fix this in an update?
How did you find the addresses of eCos memory blocks? (Memory Map)
Great information! Thank you!
Very well explained only how did you manage to get elf exported with Ghidra
Thanks for posting this. I learned quite a bit. I had trouble getting firmware-ananlysis-tools to work properly. How would one extract the firmware.tar.gz using binwalk that comes with Linux? It seems binwalk extract out axxx_firmware.tar file. Can I just gzip it? thanks
nm, i figured it out. shoudl stick with just one version of Python
useless garbage
Thank you for this great video. I have almost identified the UART points on the motherboard. Those points are soldered pads and not holes. So, will pcbite probe will help to connect to these pads?. Also, is it possible to connect with you personally?.
Yes, the pcbite probes will help when there's pads for the uart. you could also try soldering to the pads, but in my experience, soldering to pads is difficult because they're usually pretty thin and you can end up pulling them off. for me, the probes were a good investment. You can get in touch via the IoT Village Discord! discord.gg/BnKj7KR4
@@IoTVillage Thanks for the update. Could you please let me know how did you connected the probes to the TTL adpater pins?. It was hard to identify in this video.
The probes we linked in the description of the video come with wires that you can connect to the ground, rx, and tx pins of your adapter. You'll also have to look up the voltage and baud rate of the device you're testing so that whichever serial communication program you're using can read the output correctly.
@@IoTVillage Great. Could you also let me know if the probe has a magnet which will stick it to the solder pads on the motherboard?.
@@IoTVillage Hello Sir. I purchased the probe which you mentioned in the description. I connected the ground and tx pads to the ground and rx pins on ttl adapter using the probe but dont see anything on the putty. Can you suggest what else can I check?.
Thank you. Very helpful following along with your workflow.
Now if you'd just oust Putin then you'd be the ultimate man.
Good to know that this is from russian company. I was going to buy it, but now I rather wait until some chinese company will clone it.
Kinda your morale compass have quite a short memory, millions died from American bombs in Laos and Cambodia (it's Vietnam neighbours)...where any compensations or reparations, or anything. It's the most interesting example because most forgotten, people there don't even had concrete buildings before bombs. And you openly using american corporate products or ip. Humanity are animals and always will be.
I Love this guy
GREETINGS GUYS
Where can we see the page you are referring from? I would like to read about all its applications!
Please tell your president to pull out of Ukraine, thanks.
Super duper to know (since my flipper zero arrived just a week ago) that you've implemented NFC into FZ and how much your project have grown! You all did an awesome job and I am super pumped to try my new tamagotchi :) Still lot of work in front of you (and all of us since it is open source) :)
I feel like it's use is being only vaugly discussed? Like can flipper crack Wi-Fi codes that you see other people's phones?
The flipper zero with a wifi module could probably do a half handshake attack and get helpful info on your wifi login credentials. "See phones" is pretty vague. Dont leave your wifi enabled on your phone when your not using it, and change your home router password. the username is probably admin and the password is probably admin.
so it's safe to assume the project died now ?
Just ordered today
Ok my Honda has a factory remote start that came from a auction but I didn’t get the remote for it I bought the remote but I have to take it to Honda and pay them to program it wit this do that
I don't think so, but once you have it programmed you can clone the remote to your Flipper.
Hey you guys still around? Just found out about flipper and was interested in ordering, wasn't sure about mail right now
was that elons brain chip on that dolphin lol
Just got mine in the mail.
Hope to buy one soon! Great job!!
onde compro um aqui no Brasil?
Thank you. I needed this talk.
Nice 👍 work dude! This will come in handy
Thank-you @neodjboy ! Was a privilege to be able to share this small snippet of research at the IoT Village Virtual Event 2.0 !
I love joke about COVID ))) Sweeeeeet))
Amazing talk, Ted. Thank you!
Dolphin is good because all dolphins do is RAPE! They rape all day and all night anything and everything...I have never understood why people love dolphins they are super rapey and nobody seems to know this??? I have seen one rape a sea turtle messed up creatures!!!
but nobody who backed the kickstarter got one..........
They did actually
@@OGkrymsonclouds yes we did, eventually . . . . . .
Oh moskow will cry I mean cops :D best gadget ever I love it.
Остаётся только произношение подтянуть =D
I Love russia! Greetings from Germany :) Grate Job you Guys did!
Waiting for version 1. Loving it!
Is the flipper 1 and the flipper 0 both releasing at the same time? I'm not hearing as much talk about the flipper 1?
My style of botnet building
@Robert Wooten lol , wanna collab then ?
Can you get it yet?
Lovely and intellectual Guy
With the flipper one can you plug a monitor and keyboard into it and use it as a computer?
I think now days grages make different key every time you use it.
Yes most garage door openers these days use rolling codes. But even those are not foolproof
So awesome!!
Can I buy this even after Kickstart ends???
What would I need to learn to take it to it’s full potential. I would like to know if it is possible to hack train turnstiles lol. .
Congratulation for hitting 3 650 000 US$ on kickstarter. Anyone who asked where to get: www.kickstarter.com/projects/flipper-devices/flipper-zero-tamagochi-for-hackers
Вэри эксайтин, риэли. Ай виш ю гуд лак виз кикстартер кампани! Очень хорошая задумка, короче ) Но весь изюм будет в софте.
Greetings from America
Just ordered 3
Can it emulate NTAG215 (Amiibo) cards?
I hope it doesent get banned in like 2 weeks of realise
Even if it does you could, theoretically, build your own. I personally think these things are gonna blow up like sbc's did
@@Anonymous_Eyeballs bruh i hope not
Unfortunately I feel like the chances of that happening are high
@@luckyblaze4656 Just buy one quickly then man
they sold so many of them🤣 i got one too
Good day, IoT Village. this is fairly exciting video. thank. :)
where can I buy this device?
kickstarter