IoTSecurity101
by V33RU
A Curated list of IoT Security Resources
AI summary
IoT Security Guide
A curated collection of IoT security resources and guides
- stars
- 2.8K
- forks
- 501
- watching
- 114
- entries
- 483
What's in the list
483 links in 45 sections, with live GitHub stats.activeno commit in 2y
Links
contribute
You are welcome to fork and
📑 Contents Overview / 🛡️ IoT Security Information
Specific Topics in IoT Security / Technical Research and Hacking
Specific Topics in IoT Security / Proof of Concepts known Device Vulnerabilities
Specific Topics in IoT Security / Community and Discussion Platforms
Specific Topics in IoT Security / IoT and Hardware Security Trainings
Specific Topics in IoT Security / Books for IoT Penetration Testing
Specific Topics in IoT Security / Awesome CheatSheets
Specific Topics in IoT Security / Search Engines for Internet-Connected Devices
Specific Topics in IoT Security / YouTube Channels for IoT Pentesting
Specific Topics in IoT Security / Vehicle Security Resources
Specific Topics in IoT Security / IoT Vulnerabilites Checking Guides
Specific Topics in IoT Security / IoT Gateway Software
Specific Topics in IoT Security / IoT Pentesting OSes
Specific Topics in IoT Security / Exploitation Tools
Specific Topics in IoT Security / Reverse Engineering Tools
- IDA Pro
: An interactive disassembler that provides extensive information about binary code and is widely used for static analysis
- GDB
: The GNU Project Debugger allows you to see what is going on 'inside' another program while it executes or what another program was doing at the moment it crashed
- Radare2
: An open-source framework for reverse engineering and analyzing binaries; includes a disassembler for multiple architectures
- Cutter
: A Qt and C++ GUI for Radare2, aiming to provide a more user-friendly interface as well as additional features
- Ghidra
: A software reverse engineering suite of tools developed by NSA that includes a decompiler, assembler, disassembler, and other tools to analyze binaries
- Binary Ninja
: A reverse engineering platform that is an alternative to IDA Pro, with a focus on binary analysis for security research and reverse engineering
- OllyDbg
: An x86 debugger that emphasizes binary code analysis, which is useful for reverse engineering and finding security vulnerabilities
- x64dbg
: An open-source x64/x32 debugger for windows with a focus on plugin support and scriptability
- Hopper
: A reverse engineering tool for macOS and Linux that lets you disassemble, decompile and debug your applications
- Immunity Debugger
: A powerful debugger for analyzing malware and reverse engineering with an integrated Python scripting interface for automation
- PEiD
: A tool that detects most common packers, cryptors, and compilers for PE files and is useful for reverse engineering of malware
Specific Topics in IoT Security / Introduction
Specific Topics in IoT Security / IoT Web and Message Services
- CVE-2020-13849
: A vulnerability in MQTT protocol 3.1.1, allowing remote attackers to cause a denial of service. CVSS score: 7.5 (High)
- CVE-2023-3028
: Involves insufficient authentication in MQTT backend, leading to potential data access and manipulation. CVSS score: 9.8 (Critical)
- CVE-2021-0229
: Pertains to uncontrolled resource consumption in Juniper Networks Junos OS MQTT server. CVSS score: 5.3 (Medium)
- CVE-2019-5432
: A malformed MQTT Subscribe packet can crash MQTT Brokers. CVSS score: 7.5 (High)
Specific Topics in IoT Security / RADIO HACKER QUICK START GUIDE
Specific Topics in IoT Security / Cellular Hacking GSM BTS
Specific Topics in IoT Security / NFC-RFID
Specific Topics in IoT Security / Zigbee ALL Stuff
Specific Topics in IoT Security / BLE Intro and SW-HW Tools to pentest
Specific Topics in IoT Security / DECT (Digital Enhanced Cordless Telecommunications)
Specific Topics in IoT Security / Mobile security (Android & iOS)
- Android App Reverse Engineering 101
A comprehensive guide to reverse engineering Android applications
- Android Application Pentesting Book
A detailed book on penetration testing techniques for Android devices
- Android Pentest Video Course - TutorialsPoint
A series of video tutorials on Android penetration testing
- Android Tamer
A Virtual/Live Platform for Android Security professionals, offering tools and environment for Android security
- iOS Pentesting
A guide to penetration testing in iOS environments
- OWASP Mobile Security Testing Guide
The Open Web Application Security Project's guide for mobile security testing, applicable to iOS
Specific Topics in IoT Security / Villages
Specific Topics in IoT Security / Online Assemblers
Specific Topics in IoT Security / ARM
Specific Topics in IoT Security / Pentesting Firmwares and emulating and analyzing
Specific Topics in IoT Security / Firmware samples to pentest
Specific Topics in IoT Security / Binary Analysis
Specific Topics in IoT Security / Symlinks Attacks
Specific Topics in IoT Security / Secureboot
Specific Topics in IoT Security / Storage Medium
Specific Topics in IoT Security / Payment Device Security
- Jackpotting Automated Teller Machines Redux
By Barnaby Jack
Specific Topics in IoT Security / IoT hardware Overview and Hacking
Specific Topics in IoT Security / Awesome IoT Pentesting Guides
Specific Topics in IoT Security / Fuzzing Things
- part1
[fuzzing-iot-binaries] - /
Specific Topics in IoT Security / FlipperZero
- Exploiting Flipper Zero’s NFC file loader
CVE-2022-40363:
Specific Topics in IoT Security / ICS
Specific Topics in IoT Security / Automotive
Specific Topics in IoT Security / Vulnerable IoT and Hardware Applications
DVID
IoT: -
- Damn Vulnerable Safe
Safe: -
- IoT-vulhub
IoT-vulhub: -
DVRF
Router: -
- Damn Vulnerable Chemical Process
SCADA: -
- Sticky Fingers DV-Pi
PI: -
- Damn Vulnerable SS7 Network
SS7 Network: -
- Hacklab VulnVoIP
VoIP: -
Hardware Hacking 101
Hardware Hacking 101: -
RHme-2015
RHME-2015: -
Rhme-2016
RHME-2016: -
Rhme-2017
RHME-2017: -
Specific Topics in IoT Security / CTF For IoT And Embeddded
BLE CTF
A framework focused on Bluetooth Low Energy security
Rhme-2016
Riscure's hardware security competition for 2016
Rhme-2017
Riscure's hardware security competition for 2017
IoTGoat
Deliberately insecure firmware based on OpenWrt for IoT security training
- IoT Village CTF
A Capture The Flag event specifically focused on IoT security
- IoTSec CTF
Offers IoT related challenges for continuous learning
- Damn Vulnerable ARM Router
A deliberately vulnerable ARM router for exploitation practice
- Firmware Security Training & CTF
Firmware analysis tools and challenges by Router Analysis Toolkit
ARM-X CTF
A set of challenges focused on ARM exploitation
- Azeria Labs ARM Challenges
Offers ARM assembly challenges and tutorials
- Microcorruption
Embedded security CTF focusing on lock systems
- Pwnable.kr
Offers various reverse engineering challenges
- Hack The Box
Platform offering a range of challenges, including hardware and reverse engineering
- Root Me
Platform with various types of challenges including hardware and reverse engineering
- CTFtime
Lists various CTFs, including those in hardware, IoT, and firmware
Specific Topics in IoT Security / follow the people
Specific Topics in IoT Security / Blogs for IoT Pentest
- Devttys0 Blog
(Use Wayback Machine for old blogs)
Nothing in this list matches your filter.