Download - Let's Hack a House

Transcript
Page 1: Let's Hack a House

Let’s hack a house.

Tony Gambacorta

[email protected]

Page 2: Let's Hack a House

I’m supposed to scare you.

Page 3: Let's Hack a House

Distance

Ratio

Physical Access Same WiFi Darkest Peru

One-to-One

One-to-Many

Page 4: Let's Hack a House

When is a WebCam not a WebCam?

Page 5: Let's Hack a House

Coffee Cup Ambush

Page 6: Let's Hack a House

WebCamCompliance

Security

A consumer sees… Peace of Mind

Page 7: Let's Hack a House

WebCam

Linux Server

Network Access

Microphone

Camera

A geek sees…

Page 8: Let's Hack a House

WebCamAbility to inject data

Eyes and ears inside

Attack platform

A bad actor sees…

Page 9: Let's Hack a House

Variations on a theme…

Let’s hack some stuff!

Page 10: Let's Hack a House

Pro Tip: You’ll probably break something your first time. Plan accordingly.

Page 11: Let's Hack a House

UART

Page 12: Let's Hack a House

This adapter just lets my laptop’s USB talk to other devices

Page 13: Let's Hack a House
Page 14: Let's Hack a House

} I’ll do all this stuff when I’m booting up.

Page 15: Let's Hack a House

Coffee Cup Ambush

Page 16: Let's Hack a House

Eyes and Ears Inside

• See who comes and goes • Listen to conversations

Ability to inject data

• Edit live video • Delete video

Attack Platform

• Scan internal networks • Distribute malware • APT toe-hold

Page 17: Let's Hack a House

Bedtime Reading

Key Takeaway:

Everything is just parts connected to other parts.

Page 18: Let's Hack a House

Distance

Ratio

target-centric 1:1 ratio

physical access { }

vulnerability-centric 1 : many ratio remote access{ }

Page 19: Let's Hack a House

Forget Alice.

Any Brady will do.

Page 20: Let's Hack a House

Enumerate the Widgets.

Page 21: Let's Hack a House

That’s funny…Your URL: https://FG-59301.iotco.com

S/N = XX-00000

26 * 26 * 10 * 10 * 10 * 10 * 10

67.6 Million Possibilities

Page 22: Let's Hack a House

67.6 Million Possibilities

3,380,000 active hosts

That’s funny…

Page 23: Let's Hack a House

123456

password

12345

12345678

qwerty

Nope.

Nope.

Nope.

Nope.

Nope.

Nope.

Nope.

Nope.

Nope.

We’re in!

Nope.

Nope.

Nope.

Nope.

Nope.

We’re in!

Nope.

Nope.

Nope.

Nope.

123456789 LOCKED.

Common Passwords

Average Success Rate: 3-5%

Think sideways

Page 24: Let's Hack a House

That’s (not so) funny…3,380,000 Active Hosts

1% Success Rate

33,800 Compromised Devices

Page 25: Let's Hack a House

The one-offs are enough to make the news.

Page 26: Let's Hack a House

Bedtime Reading

Key Takeaway:

Statistically, if I know who your users are, you’re gonna have a bad time.

Page 27: Let's Hack a House

So What?• We’ve seen all of these attacks before, at scale

• Learn from the lessons of fraud

• Every once in a while, get your hands dirty

Page 28: Let's Hack a House
Page 29: Let's Hack a House

Thanks!


Top Related