IoTSecurity101 icon indicating copy to clipboard operation
IoTSecurity101 copied to clipboard

A Curated list of IoT Security Resources

Awesome

  • A Collection for IoT Security Resources
  • You are welcome to fork and contribute

Approach Methodology

  • 1. Network
  • 2. Web (Front & Backend and Web services)
  • 3. Mobile App (Android & iOS)
  • 4. Wireless Connectivity (Zigbee , WiFi , Bluetooth , etc)
  • 5. Firmware Pentesting (OS of IoT Devices)
  • 6. Hardware Hacking & Fault Injections & SCA Attacks
  • 7. Storage Medium
  • 8. I/O Ports

Contents

  • IoT Security information

    • IoT Security Chat groups
    • Books
    • Blogs
    • Cheatsheets
    • Search Engines
    • CTF
    • Youtube
    • Exploitation Tools
    • IoT Pentesting OSes
    • IoT Vulnerabilites Checking Guides
    • IoT Labs
    • Awesome IoT Pentesting Guides
  • Network

  • Web IoT Message Protocols

    • MQTT
    • CoAP
  • Mobile app

    • Mobile security (Android & iOS)
  • Wireless Protocols

    • RADIO HACKING STARTING GUIDE
    • Cellular Hacking GSM BTS
    • Zigbee
    • Bluetooth
  • Firmware

    • Reverse Engineering Tools
    • Online Assemblers
    • ARM
    • Pentesting Firmwares and emulating and analyzing
    • Firmware samples to pentest
    • Bootloader
  • Hardware

    • IoT Hardware Intro
    • [IoT Hardware hacking Intro]
    • Required hardware to pentest IoT
    • Hardware interfaces
    • SPI
    • UART
    • JTAG
    • SideChannel Attacks & Glitching attacks
  • Storage Medium


To seen Hacked devices


Chat groups for IoT Security


Books For IoT Pentesting


Blogs for iotpentest

  • https://payatu.com/blog/
  • https://raelize.com/blog/
  • http://jcjc-dev.com/
  • https://w00tsec.blogspot.in/
  • http://www.devttys0.com/
  • https://wrongbaud.github.io/
  • https://embeddedbits.org/
  • https://www.rtl-sdr.com/
  • https://keenlab.tencent.com/en/
  • https://courk.cc/
  • https://iotsecuritywiki.com/
  • https://cybergibbons.com/
  • http://firmware.re/
  • http://blog.k3170makan.com/
  • https://blog.tclaverie.eu/
  • http://blog.besimaltinok.com/category/iot-pentest/
  • https://ctrlu.net/
  • http://iotpentest.com/
  • https://blog.attify.com
  • https://duo.com/decipher/
  • http://www.sp3ctr3.me
  • http://blog.0x42424242.in/
  • https://dantheiotman.com/
  • https://blog.danman.eu/
  • https://quentinkaiser.be/
  • https://blog.quarkslab.com
  • https://blog.ice9.us/
  • https://labs.f-secure.com/
  • https://mg.lol/blog/
  • https://cjhackerz.net/
  • https://github.com/sponsors/bunnie/
  • https://iotmyway.wordpress.com/
  • https://www.synacktiv.com/publications.html
  • http://blog.cr4.sh/
  • https://ktln2.org/
  • https://naehrdine.blogspot.com/

Awesome CheatSheets


Search Engines for IoT Openly devices


CTF For IoT And Embeddded

  • https://github.com/hackgnar/ble_ctf
  • https://www.microcorruption.com/
  • https://github.com/Riscure/Rhme-2016
  • https://github.com/Riscure/Rhme-2017
  • https://blog.exploitlab.net/2018/01/dvar-damn-vulnerable-arm-router.html
  • https://github.com/scriptingxss/IoTGoat

YouTube Channels for IoT Pentesting


Vehicle Security Resources

  • https://github.com/jaredthecoder/awesome-vehicle-security

IoT Vulnerabilites Checking Guides


IoT Gateway Software


IoT Pentesting OSes


Exploitation Tools


Reverse Engineering Tools


Introduction


IoT Web and message services

MQTT

Softwares

CoAP


RADIO HACKER QUICK START GUIDE

Cellular Hacking GSM BTS

BTS

GSM SS7 Pentesting


Zigbee ALL Stuff

SW TOOLS

Hardware Tools for Zigbee


BLE Intro and SW-HW Tools to pentest

Bluetooth and BLE Pentest Tools

Hardware for bluetooth hacking

BLE Pentesting Tutorials


Mobile security (Android & iOS)


Online Assemblers


ARM


Pentesting Firmwares and emulating and analyzing


Firmware samples to pentest


Bootloader

Dev


Storage Medium


IoT hardware Overview and Hacking

Hardware Gadgets to pentest

Attacking Hardware Interfaces

SPI

UART

JTAG

SideChannel Attacks and Glitching attacks


Awesome IoT Pentesting Guides


Vulnerable IoT and Hardware Applications

  • IoT Goat : https://github.com/scriptingxss/IoTGoat

  • IoT : https://github.com/Vulcainreo/DVID

  • Safe : https://insinuator.net/2016/01/damn-vulnerable-safe/

  • Router : https://github.com/praetorian-code/DVRF

  • SCADA : https://www.slideshare.net/phdays/damn-vulnerable-chemical-process

  • PI : https://whitedome.com.au/re4son/sticky-fingers-dv-pi/

  • SS7 Network: https://www.blackhat.com/asia-17/arsenal.html#damn-vulnerable-ss7-network

  • VoIP : https://www.vulnhub.com/entry/hacklab-vulnvoip,40/


follow the people