Common IoT Device Vulnerabilities in 2023
The same weaknesses turn up in connected device after connected device. Default credentials, exposed debug interfaces, unsigned firmware, and plaintext traffic.
Read the post →The latest security treads, threat analysis, testing methodology, and more — from the people doing the work.
113 posts
The same weaknesses turn up in connected device after connected device. Default credentials, exposed debug interfaces, unsigned firmware, and plaintext traffic.
Read the post →A connected device is a network host, a radio, a mobile app, and a cloud API at once. Why partial IoT testing misses the paths that actually get exploited.
Read the post →Moving a service off port 443 hides it from nobody. Why non-standard web ports are indexed anyway, and what to do about the ones you did not know were open.
Read the post →Password complexity rules help, right up to the point they push people into predictable patterns. What actually resists cracking, and how to prove it.
Read the post →Two engagements with the same name can differ enormously in depth. What separates a real penetration test from an automated scan with a report attached.
Read the post →A twenty-year-old IIS quirk still leaks file and directory names to anyone who asks. How the enumeration works, whether it still matters, and how to stop it.
Read the post →Port 3389 exposed to the internet is remote desktop left unlocked. What Shodan shows an attacker about your network before a single packet is sent to it.
Read the post →The last of our MobSF coverage: browsable activities, network security config, certificate analysis, and where the automated report stops being useful.
Read the post →Being small is not protection; it makes you a cheaper target. Why smaller organizations get tested less, and a practical route to a first engagement.
Read the post →Trusting an update, a package, or a pipeline you cannot verify is its own vulnerability class. Integrity controls, with the supply chain breaches that prove it.
Read the post →