0:06 Most of IoT devices, they have Telnet open or SSH keys or default passwords. 0:16 So when you are buying the IoT device, smart, whatever, whatever smart, right? 0:23 That stuff costs like $5, $10 usually. 0:26 It's like cheap, for example. 0:28 You can buy some cheap IoT device. 0:30 And those cheap IoT devices, they are printed in the factory. 0:37 Where they do not really think about security of those devices. 0:41 They just want the device to be cheap and work. 0:44 So it means that usually those devices, they can have the default password, which was never asked to be changed. 0:55 This is first stuff. 0:57 Also, we talk about routers. 0:59 Routers are not like IoT devices, but they can be, you know, in the similar category 1:07 with the smart TV and stuff where they all have the default passwords or default. 1:17 SSH key. 1:19 So sometimes when vendor is creating the software, they generate SSH key and that key is 1:30 The same for all devices. 1:32 Let's imagine that you are doing your project and you are like company with low amount of budget. 1:39 You don't have enough time to do cybersecurity. 1:43 And you are doing like babysitter, IoT, whatever stuff, like online nanny. 1:51 And all what it does, it allows you to check your kit from the phone, like camera, and it works through the internet. 2:02 For some reason, you know, that device is having SSH. 2:09 Why? 2:10 Because... 2:12 It can allow guys to debug it, right? 2:17 And by default, it's not turned off. 2:20 It can be SSH. 2:21 It can be AirSync. 2:23 It can be Telnet. 2:26 Debug port. 2:27 Usually, debug port is not disabled. 2:30 Usually. 2:31 Why? 2:32 Because vendors are trying to, you know, if you will bring it, right? 2:39 If you bring it and say like, what happened to this stuff? 2:42 What they will do? 2:43 They will need to reassemble it and press some button and enable that debug port. 2:49 They're not going to do it. 2:50 You understand? 2:51 It is just by default there. 2:53 Like SSH, Telnet, if you will scan, if you will just go to market, you know, mall, buy. 3:01 IoT device connected to your network and you will scan it, it will have like big amount of ports open and some of them are like for web interface and some of them for like controlling that device. 3:15 So now you created that device. 3:19 And you are going to sell it. 3:22 So it is working fine. 3:24 It is showing the camera. 3:26 It is collecting the microphone information. 3:31 And it works when you connect it, for example, right? 3:34 So everything is great. 3:36 But there is one catch that it has SSH or Telnet. 3:41 Telnet credentials can be known or Telnet can be without credentials. 3:54 So you can just connect to device and get the full access to it without even credentials. 3:59 This is first thing. 4:00 Second thing, credentials can be default. 4:03 If one person will know this credential somehow, it means all what was produced in that company will be compromised because credentials will be like 1, 2, 3, 1, 2, 3. 4:17 How did you get them? 4:18 You can brute force. 4:20 The other way, you can open the device itself. 4:24 You can connect like this. 4:26 I will show you. 4:29 JTEC. 4:35 J tag debug port. 4:39 So that stuff costs zero money, three dollars. 4:44 Just to do this. 4:48 So what is JTEC? 4:54 This is JTEC. 4:59 A lot of devices, they have debug physical port, physical. 5:07 And you can just disassemble it, connect to it, and after you can download the firmware. 5:16 So with JTAG, so what does the JTAG allow you to do? 5:20 Upload firmware or download the firmware, usually. 5:26 And when you download the firmware, you can just, you know, run the... 5:38 Decompilation of that firmware and I can show you how to do it today. 5:45 I can even show right now so you will understand. 5:48 So let's .bin this is example of 5:56 Oh, this is a different one. 5:58 Download, download. 6:00 forward.bin file github firmware vulnerable i just want to show you so 6:12 Let's imagine that you downloaded the firmware. 6:15 So what are you going to do with it? 6:18 Okay. 6:19 Vulnerable firmware GitHub. 6:25 This is the guy which we need. 6:31 Where is it? 6:35 It has the... 6:39 I just need to download bin file. 6:43 Bin. 6:44 IoT gold. 6:47 I need to download the bin file. 6:54 Bin is something that is uploaded everywhere as a default format, bin. 7:04 What is going on? 7:06 Where has that been? 7:17 Damn vulnerable. 7:23 Fear and worry. 7:25 This one. 7:29 Yes, firmware. 7:31 So here it is. 7:33 So I'm downloading the firmware. 7:37 So now I'm going to 7:42 to do something about it. 7:45 I'm going to decompile it. 7:48 There are some tools. 7:49 I can show you one tool. 7:52 It's called Binwalk. 7:56 A lot of people are using it. 8:00 So. 8:03 How it works. 8:13 Hard to see. 8:17 Let me show you. 8:19 Yeah. 8:20 So you just download Bitwalk and you pass the firmware to it. 8:24 And it will help you to decompile it or to find some secrets. 8:28 So you will need to spend some time with this tool to find what you need. 8:34 But that is all tool. 8:37 It is not that good. 8:39 You will need to spend a lot of time to find something. 8:42 So here, Guy found the private key. 8:46 And also he decompiled it. 8:48 You see 2,456 files. 8:52 So yeah, let me show you some easier stuff. 8:59 Um, 9:04 Firmware. 9:05 Yeah. 9:06 So, let's... 9:10 Take that stuff, which we just downloaded. 9:14 And let's do deep extraction. 9:16 Start scan. 9:18 So now we are having some magic done in the background, but 9:23 magic is that it is decompiling that binary and trying to extract all the possible files and trying to find patterns 9:37 on those files which can match, for example, private key, SSH private key, 9:43 or anything else, or it is trying to access the default location of SSH keys and stuff. 9:53 Trying to find vulnerabilities based on the old libraries and something else. 10:00 Let's wait a little bit. 10:01 It's taking time because it is decompiling it. 10:06 So this is entropy. 10:10 Let's wait. 10:12 See the profile. 10:13 Now it's done. 10:14 Took us like 10 seconds. 10:16 So it is eight megabytes of memory. 10:21 It has a lot of different compression, compression, compression. 10:25 So let's see the findings. 10:27 Strings, email address. 10:30 So as you can see, this is false positive. 10:33 It tried to find the email address from the firmware, but it is false positive. 10:39 No vulnerabilities, but let's see if we can find here something juicy. 10:48 Email address. 10:51 Secure boot variable. 10:54 So, for example, this application has a secure boot. 11:00 So you can see where it is located. 11:05 And you can navigate also to file system and try to find something that you can be interested in. 11:12 But we don't find any high or critical vulnerabilities here automatically. 11:20 So we can see the extracted files. 11:26 So it's usually the strings command. 11:31 So nothing interesting here. 11:35 But the idea is that potentially it can find the crypto keys. 11:42 Or it can find the IoT backdoors or vulnerabilities or credentials. 11:46 So we just have a big amount of info findings, which are not giving us a lot. 11:53 They just tell us, you know, there are some images, compressed, whatever stuff. 11:59 But if it will be some key, we will find that key.
0:06 Most of IoT devices, they have Telnet open or SSH keys or default passwords. 0:16 So when you are buying the IoT device, smart, whatever, whatever smart, right? 0:23 That stuff costs like $5, $10 usually. 0:26 It's like cheap, for example. 0:28 You can buy some cheap IoT device. 0:30 And those cheap IoT devices, they are printed in the factory. 0:37 Where they do not really think about security of those devices. 0:41 They just want the device to be cheap and work. 0:44 So it means that usually those devices, they can have the default password, which was never asked to be changed. 0:55 This is first stuff. 0:57 Also, we talk about routers. 0:59 Routers are not like IoT devices, but they can be, you know, in the similar category 1:07 with the smart TV and stuff where they all have the default passwords or default. 1:17 SSH key. 1:19 So sometimes when vendor is creating the software, they generate SSH key and that key is 1:30 The same for all devices. 1:32 Let's imagine that you are doing your project and you are like company with low amount of budget. 1:39 You don't have enough time to do cybersecurity. 1:43 And you are doing like babysitter, IoT, whatever stuff, like online nanny. 1:51 And all what it does, it allows you to check your kit from the phone, like camera, and it works through the internet. 2:02 For some reason, you know, that device is having SSH. 2:09 Why? 2:10 Because... 2:12 It can allow guys to debug it, right? 2:17 And by default, it's not turned off. 2:20 It can be SSH. 2:21 It can be AirSync. 2:23 It can be Telnet. 2:26 Debug port. 2:27 Usually, debug port is not disabled. 2:30 Usually. 2:31 Why? 2:32 Because vendors are trying to, you know, if you will bring it, right? 2:39 If you bring it and say like, what happened to this stuff? 2:42 What they will do? 2:43 They will need to reassemble it and press some button and enable that debug port. 2:49 They're not going to do it. 2:50 You understand? 2:51 It is just by default there. 2:53 Like SSH, Telnet, if you will scan, if you will just go to market, you know, mall, buy. 3:01 IoT device connected to your network and you will scan it, it will have like big amount of ports open and some of them are like for web interface and some of them for like controlling that device. 3:15 So now you created that device. 3:19 And you are going to sell it. 3:22 So it is working fine. 3:24 It is showing the camera. 3:26 It is collecting the microphone information. 3:31 And it works when you connect it, for example, right? 3:34 So everything is great. 3:36 But there is one catch that it has SSH or Telnet. 3:41 Telnet credentials can be known or Telnet can be without credentials. 3:54 So you can just connect to device and get the full access to it without even credentials. 3:59 This is first thing. 4:00 Second thing, credentials can be default. 4:03 If one person will know this credential somehow, it means all what was produced in that company will be compromised because credentials will be like 1, 2, 3, 1, 2, 3. 4:17 How did you get them? 4:18 You can brute force. 4:20 The other way, you can open the device itself. 4:24 You can connect like this. 4:26 I will show you. 4:29 JTEC. 4:35 J tag debug port. 4:39 So that stuff costs zero money, three dollars. 4:44 Just to do this. 4:48 So what is JTEC? 4:54 This is JTEC. 4:59 A lot of devices, they have debug physical port, physical. 5:07 And you can just disassemble it, connect to it, and after you can download the firmware. 5:16 So with JTAG, so what does the JTAG allow you to do? 5:20 Upload firmware or download the firmware, usually. 5:26 And when you download the firmware, you can just, you know, run the... 5:38 Decompilation of that firmware and I can show you how to do it today. 5:45 I can even show right now so you will understand. 5:48 So let's .bin this is example of 5:56 Oh, this is a different one. 5:58 Download, download. 6:00 forward.bin file github firmware vulnerable i just want to show you so 6:12 Let's imagine that you downloaded the firmware. 6:15 So what are you going to do with it? 6:18 Okay. 6:19 Vulnerable firmware GitHub. 6:25 This is the guy which we need. 6:31 Where is it? 6:35 It has the... 6:39 I just need to download bin file. 6:43 Bin. 6:44 IoT gold. 6:47 I need to download the bin file. 6:54 Bin is something that is uploaded everywhere as a default format, bin. 7:04 What is going on? 7:06 Where has that been? 7:17 Damn vulnerable. 7:23 Fear and worry. 7:25 This one. 7:29 Yes, firmware. 7:31 So here it is. 7:33 So I'm downloading the firmware. 7:37 So now I'm going to 7:42 to do something about it. 7:45 I'm going to decompile it. 7:48 There are some tools. 7:49 I can show you one tool. 7:52 It's called Binwalk. 7:56 A lot of people are using it. 8:00 So. 8:03 How it works. 8:13 Hard to see. 8:17 Let me show you. 8:19 Yeah. 8:20 So you just download Bitwalk and you pass the firmware to it. 8:24 And it will help you to decompile it or to find some secrets. 8:28 So you will need to spend some time with this tool to find what you need. 8:34 But that is all tool. 8:37 It is not that good. 8:39 You will need to spend a lot of time to find something. 8:42 So here, Guy found the private key. 8:46 And also he decompiled it. 8:48 You see 2,456 files. 8:52 So yeah, let me show you some easier stuff. 8:59 Um, 9:04 Firmware. 9:05 Yeah. 9:06 So, let's... 9:10 Take that stuff, which we just downloaded. 9:14 And let's do deep extraction. 9:16 Start scan. 9:18 So now we are having some magic done in the background, but 9:23 magic is that it is decompiling that binary and trying to extract all the possible files and trying to find patterns 9:37 on those files which can match, for example, private key, SSH private key, 9:43 or anything else, or it is trying to access the default location of SSH keys and stuff. 9:53 Trying to find vulnerabilities based on the old libraries and something else. 10:00 Let's wait a little bit. 10:01 It's taking time because it is decompiling it. 10:06 So this is entropy. 10:10 Let's wait. 10:12 See the profile. 10:13 Now it's done. 10:14 Took us like 10 seconds. 10:16 So it is eight megabytes of memory. 10:21 It has a lot of different compression, compression, compression. 10:25 So let's see the findings. 10:27 Strings, email address. 10:30 So as you can see, this is false positive. 10:33 It tried to find the email address from the firmware, but it is false positive. 10:39 No vulnerabilities, but let's see if we can find here something juicy. 10:48 Email address. 10:51 Secure boot variable. 10:54 So, for example, this application has a secure boot. 11:00 So you can see where it is located. 11:05 And you can navigate also to file system and try to find something that you can be interested in. 11:12 But we don't find any high or critical vulnerabilities here automatically. 11:20 So we can see the extracted files. 11:26 So it's usually the strings command. 11:31 So nothing interesting here. 11:35 But the idea is that potentially it can find the crypto keys. 11:42 Or it can find the IoT backdoors or vulnerabilities or credentials. 11:46 So we just have a big amount of info findings, which are not giving us a lot. 11:53 They just tell us, you know, there are some images, compressed, whatever stuff. 11:59 But if it will be some key, we will find that key.