Illuminating Vulnerabilities – The Dark Side of Smart Bulbs
摘要
Smart devices, like smart bulbs, are devices that have the capability for users to remotely control their behavior and functionality. The ability for users to remotely control these devices also brings potential vulnerabilities that could sabotage an entire network. This research focuses on penetration testing of IoT devices to see how vulnerable these devices are to malicious contenders. IoT devices are daily-use appliances and tools that can connect to the internet. This includes the coffee makers in some of our kitchens, garage door openers, even smart light bulbs that some of us use to remotely illuminate the room through our phone. Unlike desktop and laptop computers, these IoT devices rarely have any physical or logical intrusion detection or intrusion prevention mechanisms in them. Due to this, IoT devices are more prone to attacks compared to other wireless-compatible devices. In this research project, the main goals to accomplish include intruding into a smart bulb, establishing remote connections with the bulb, and manipulating the smart bulb’s behavior through scripting. The process starts with using Ubertooth One to capture the Bluetooth signal from the smart bulb. The ultimate command and control phase of the project is accomplished using scripts within a Kali Linux VM. Besides exploiting the vulnerabilities in the smart bulb, educating users on how to prevent such attacks from happening to their IoT devices is another focal point in this study. Defending IoT devices is feasible, and this paper concludes with recommendations for defense-in-depth strategies users can implement to protect their devices and home network.