Unraveling the Intricacies of IoT Penetration Testing
Connected devices ship fast and get tested rarely. The methodologies, the practical obstacles, and the best practices behind a real IoT penetration test.
Read the post →The latest security treads, threat analysis, testing methodology, and more — from the people doing the work.
113 posts
Connected devices ship fast and get tested rarely. The methodologies, the practical obstacles, and the best practices behind a real IoT penetration test.
Read the post →Cryptographic failures are rarely broken maths. They are missing encryption, weak defaults, and secrets in the wrong place. What testing finds in practice.
Read the post →SSRF turns your own server into an attacker’s proxy, reaching internal systems it should never touch. How it is exploited, and why blocklists do not hold.
Read the post →Testing a connected device means testing the hardware, the firmware, the radio, and the app behind it. A short introduction to what IoT testing involves.
Read the post →Untrusted data turned back into objects is how remote code execution happens in C#, Java, PHP, and Python. What the flaw looks like and how to design it out.
Read the post →Attackers register domains that look almost exactly like yours. How typosquatting and cheap top-level domains work, and how to get ahead of both.
Read the post →Weak authentication is the door attackers try first. Credential stuffing, session handling, and MFA gaps, with what a tester looks for in each of them.
Read the post →Shared local administrator passwords are how a single workstation becomes the whole domain. Why the accounts are risky, and what to do instead of removing them.
Read the post →Phishing is still the number one way organizations get breached. Why technical controls alone do not stop it, and what a realistic test program looks like.
Read the post →TLS 1.0 through 1.3, what changed at each step, and why a scanner still complains about the old ones. A short guide to which versions to turn off, and when.
Read the post →