DEF CON 32 - Anyone can hack IoT- Beginner’s Guide to Hacking Your First IoT Device - Andrew Bellini

แชร์
ฝัง
  • เผยแพร่เมื่อ 22 พ.ย. 2024

ความคิดเห็น • 44

  • @Twoshoes22Jason
    @Twoshoes22Jason หลายเดือนก่อน +78

    Probably one of the clearest and most concise talks this year from what I've seen so far

  • @the_sandman00
    @the_sandman00 21 วันที่ผ่านมา +18

    Found 5 vulnerabilities on the first day. 1 critical, 1 high. Thanks man. This sparked a curiosity

    • @weihe1220
      @weihe1220 9 วันที่ผ่านมา +1

      Hi bro, how did you do it? Can you share some relevant basic information?

    • @the_sandman00
      @the_sandman00 9 วันที่ผ่านมา

      @ portscan-> found ftp -> did enumeration-> found default cred login -> in ftp rootfs access is granted -> dumped entire filesystem-> can modify entire fs, etc

    • @SmallTimeTrees
      @SmallTimeTrees 3 วันที่ผ่านมา

      @@weihe1220did you watch the video?

  • @coffeehousephilosopher7936
    @coffeehousephilosopher7936 หลายเดือนก่อน +22

    This is why I love this channel, any talk I might have had to miss or force to choose over the other is right on this channel... Thanks DEFCONconferences

  • @74Gee
    @74Gee หลายเดือนก่อน +17

    Without a doubt this is the best IoT hacking speed run out there.

  • @Entropy67
    @Entropy67 หลายเดือนก่อน +26

    Wow super useful talk, thanks! I've been interested in IoT hacking but too busy to look into it, I just happen to have almost all the tools and a cheap router... And some free time...

  • @chsovi7164
    @chsovi7164 หลายเดือนก่อน +21

    "we're expecting there to be a big surge of IoT devices because of AI" is just about the scariest news someone could drop

  • @daviddunkelheit9952
    @daviddunkelheit9952 หลายเดือนก่อน +5

    Power capacitors that are discharged can develop ‘phantom charge’ as the dielectric was in a contrary position physically for longer duration. Ambient charge is enough to cause the capacitor’s to return to previous charged state.

    • @theodorekorehonen
      @theodorekorehonen 14 วันที่ผ่านมา

      A lot of devices nowadays have parasitic resistors to make them safe(r) but I still always short the big filter caps just to make sure. And I do indeed get some sparks sometimes

  • @frankwuolukka2087
    @frankwuolukka2087 21 วันที่ผ่านมา +1

    Great presentation, thank you for the clear and concise talk. I believe you said that folks there could get a copy of your slides but would you mind making them available to the rest of us?

  • @GameX236
    @GameX236 4 วันที่ผ่านมา +1

    Sounds fun!

  • @stevet7522
    @stevet7522 หลายเดือนก่อน +9

    These talks just reinforce the reason i dont have IoT, smart devices, or really much of anything in my house. The fact that i have wifi makes me paranoid enough.

    • @Frappe3621
      @Frappe3621 หลายเดือนก่อน +2

      My iot lights use WiFi to make themselves into motion sensors!
      They send it between themselves and see where they are interrupted!
      Any WiFi enabled device could potentially do this,
      your WiFi can tell where you are in your house

    • @jean-naymar602
      @jean-naymar602 หลายเดือนก่อน

      @@Frappe3621 New fear unlocked.

    • @cracc_baby
      @cracc_baby 10 วันที่ผ่านมา

      bruh im kinda scared rn.. my cats new litterbox needed to connect to wifi (allegedly for firmware updates) same with the vaccum! both made in china btw :(

  • @joew1865
    @joew1865 หลายเดือนก่อน +4

    What was the software being used in the Reverse Engineering binaries & libs section?

    • @joew1865
      @joew1865 หลายเดือนก่อน +7

      Nevermind... it's called Ghidra

    • @daviddunkelheit9952
      @daviddunkelheit9952 14 วันที่ผ่านมา

      @@joew1865 yes and it is suggested to use with Amazon Coretto rather than regular Java

  • @AndreeaCe
    @AndreeaCe หลายเดือนก่อน +5

    1: pick the target, usually the target is the device not the person. Usually...

  • @eyezikandexploits
    @eyezikandexploits หลายเดือนก่อน +2

    Been making my own showdan type project locally scanning for IoT and rigged a grep script for it

  • @ZambeziSentinel
    @ZambeziSentinel 25 วันที่ผ่านมา +3

    I took screenshots of all the slides and fed to my AI to summarise. Did a good job 😊

    • @ShermaMahdi
      @ShermaMahdi 25 วันที่ผ่านมา +2

      Amazing idea💥 Did de same thanks

    • @3rdeyesociety
      @3rdeyesociety 12 วันที่ผ่านมา +1

      why wouldnt you just copy paste the transcript...

    • @ZambeziSentinel
      @ZambeziSentinel 12 วันที่ผ่านมา

      @3rdeyesociety on phone and can't copy. Tried that first

    • @ZambeziSentinel
      @ZambeziSentinel 12 วันที่ผ่านมา +2

      @@3rdeyesociety I tried but phone would not let me. Took a while to get every slide lol

  • @claasschlueter
    @claasschlueter 17 วันที่ผ่านมา

    Really enjoyed it! Thanks

  • @Pinkman875
    @Pinkman875 21 วันที่ผ่านมา +1

    somebody knows any resource to keep digging in the iot / hardware hacking?

  • @AnonymousVv3
    @AnonymousVv3 9 วันที่ผ่านมา

    Like Harvard or EC-COUNCIL University or etc for cyber degrees

  • @BsktImp
    @BsktImp หลายเดือนก่อน +9

    07:58 Capacitors at even 5V or 12V: "hold my beer."

  • @daviddunkelheit9952
    @daviddunkelheit9952 หลายเดือนก่อน +3

    I followed this beginner guide and I just couldn’t hack it.

  • @mk71b
    @mk71b หลายเดือนก่อน +1

    8:55 He should have said "unplug the power cord."

  • @AmandaCook-rc8ce
    @AmandaCook-rc8ce 29 วันที่ผ่านมา +2

    Hack or be hacked. It's like being blind and while they all can see.

  • @radwizard
    @radwizard 25 วันที่ผ่านมา

    Remember those books from the 90s and early 2000s that claimed this…. But when you read them, they are the basics to using a console or lessons on OSI and TCP/IP? 😂❤

  • @XRatedPoetry
    @XRatedPoetry หลายเดือนก่อน +1

    We need 6 more likes on this video! No more, no less!

  • @andrewc.2952
    @andrewc.2952 24 วันที่ผ่านมา

    Is it sad that my immediate definition for an LoT device is that it means "Left on table". 😂 Like when people leave their devices unattended. Don't mind me, kinda new here. Lol

  • @criticalgrower
    @criticalgrower หลายเดือนก่อน +2

    When i see someone Who really knows what he s talking about ❤ how much i love that stuff unfortunately i m not lucky and good enough to make a living with it Bless Bellini ciao

  • @iluvyunie
    @iluvyunie หลายเดือนก่อน +2

    this is why I never use my phone or pc to control any of these things

  • @AnonymousVv3
    @AnonymousVv3 9 วันที่ผ่านมา

    Botnet: Online DDOS or DOS attack.

  • @Nicholas-f5
    @Nicholas-f5 24 วันที่ผ่านมา

    Anyone hardware hacking in Austin, feel free to PM