BEGIN:VCALENDAR
PRODID;X-RICAL-TZSOURCE=TZINFO:-//com.denhaven2/NONSGML ri_cal gem//EN
CALSCALE:GREGORIAN
VERSION:2.0
BEGIN:VTIMEZONE
TZID;X-RICAL-TZSOURCE=TZINFO:Europe/Berlin
BEGIN:DAYLIGHT
DTSTART:20160327T020000
RDATE:20160327T020000
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
TZNAME:CEST
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
DTEND;TZID=Europe/Berlin;VALUE=DATE-TIME:20160820T154500
DTSTART;TZID=Europe/Berlin;VALUE=DATE-TIME:20160820T150000
DTSTAMP;VALUE=DATE-TIME:20160823T104124Z
UID:6e4bf1ae-b805-434e-bb88-493918f4c499@frab.hsbp.org
DESCRIPTION:Hardly a day goes by without an article about a new IoT (Inte
 rnet of Things) device being hacked. IP cameras\, routers\, baby monitor
 s\, smart homes\, NAS devices\, light bulbs\, cars\, rifles\, you name i
 t. We have seen in the past 5-10 years how horrible the security of thes
 e devices is. Some people play VNC roulette\, others hijack cars driven 
 by a journalist. Junk hacking has become part of the ITSEC industry. Jou
 rnalists are happy because of improved click-through rates through scary
  headlines\, security researchers feel they are the celebrities of the d
 ay. But this is just part of the full story.\n\nDuring my research\, I h
 ave created a methodology about the different risks IoT devices can intr
 oduce into a network. Most of the IoT security research focuses on the I
 oT device itself and its vulnerabilities\, but don’t consider the enviro
 nment. Is the device openly available to the whole IPv4 Internet? Is UPn
 P allowed on your router? Is the IoT device on IPv6? Can the device be h
 acked through a regular browser? Can the attacker use WebRTC to get info
 rmation about the user’s home IP network? Is it possible to port scan an
 d fingerprint home devices through a browser? What are the limitations o
 f these scans considering that a proper Same-Origin Policy is implemente
 d in the browser? How can DNS rebind attacks bypass the Same-Origin Poli
 cy? Why are the XSS and CSRF attacks so risky when it comes to IoT secur
 ity? \nIn my presentation I will answer all these questions (and more)\,
  aided by live hacking of a NAS device on the home network through the v
 ictim’s browser\, from the Internet. \n\nI will also demonstrate that Io
 T devices (IP camera in my case) with cloud connections are also suscept
 ible to hacks due to basic security weaknesses in the cloud servers\, li
 ke lack of brute-force protections or weak default passwords. This hack 
 is a real one using real devices\, which means thousands of IP cameras a
 re at risk.\n\nAt the end of the session we will cover the most importan
 t security tips people can use at home or at the company to protect thei
 r network against these vulnerable IoT devices. For example how Adblock 
 can be configured to defeat Intranet hacking or which DNS server to use 
 to prevent DNS rebind attacks.\n\nIf you have already bought or are plan
 ning to buy smart devices for home or enterprise use (or you are interes
 ted in a fun presentation)\, this presentation is for you.\n
URL:https://camp.hsbp.org/2016/pp7e0/fahrplan/events/13.html
SUMMARY:The real risks of the IoT security-nightmare
ORGANIZER:camppp7e0
LOCATION:Klapka
END:VEVENT
END:VCALENDAR
