/IOT-hacking-Roadmap

GNU General Public License v3.0GPL-3.0

IOT hacking Roadmap

Tools

Table Of Content :

To Study :

– electronics basics
– Microcontrollers
– Understanding the difference between SOC , microcontroller and microprocessor.
– The basics of linux based systems including embedded linux
– Try to designe your own hardware.
– Analyze , review hardware components and try to understand each part.
– Understanding protocols : CAN , UART , SPI , I2C , JTAG , 1wire and wiegand.
– Wireless technologies: wifi , bluetooth. BLE , zigbee , lorawan and IR.
– Access control : NFC , RFID and mechanical locks.
– Firmware analysis and modification
– ARM exploitation.
– Reverse engineering.
– Webapps security.
– Common Network services and attacks.

Software Tools :

BinWalk
Firmware-mod-kit
Qemu
minicom
Openocd
Flashrom
tftpd server
hexdump
KillerBee
Attify OS

Hardware Tools :

– Arduino
– Stm32 board
– Raspberry pi
– Buspirate
– Usb ttl
– Screw drivers
– Jumping wires
– Bread board
– EEPROM programmer
– Rtl-sdr
– Hackrf one
– Proxmark3
– Esp8266.
– Esp32
– Logic analyzer
– MR3020 Router
– supported USB WIFI Adapter - List of some supported models – WIFI Deauther
– AVR Programmer
– EEPROM Programmer
– STLink
– Nethunter support android phone
– Lily go bad USB Payloads
– Digispark Payloads
– wifi pineapple
– USB killer
– EMP generator
– Evil crow RF
– WHID injector USB
– RSP1 SdR
– Universal RF remote
– Ubertooth one
– DSlogic logic analyzer
– Chameleon mini

Tested supported WIFI adapters :

Manufacturer Model chipset Manufacturer Supports Monitor mode Supports Injection Supports Master mode
Belkin f5d7050 qualcomm True True True
Netis WF2503 Realtek True True True
Netis WF2120 Realtek True True True
alfa wireless AWUS036H Realtek True True False

Resources :

– 🔗 owasp IOT top10 Link
– 🔗 OWASP Embedded Application Security Link
– 🔗 Attify Link
– 🔗 CWE Most Important Hardware Weaknesses Link.
– 🔗 Blackhat hardware training roadmap Blackhat
– 🔗 exploitee WIKI exploitee
– 🔗 SALVADOR MENDOZA Blog
– 📹 Security society "Arabic" Youtube
– 📹 Liveoverflow Youtube
– 📹 Lockpickinglawyer Youtube
– 📹 Joe grand Youtube
– 📹 Ahmed Alroky "Arabic" Youtube
– 📹 hardwear.io hardwear.io
– 📙 Practical hardware pentesting Amazon
– 📙 The hardware hacking handbook Amazon
– 📙 Proxmark3 handbook Github
– 📙 The car hackers handbook Amazon
– 📙 Practical iot hacking Amazon
– 📙 Simply arduino 'Arabic' Link.
– 📙 Simple raspberry pi Link.
– Repo : the hacker hardware toolkit Github

Tutorials :

How I hacked a hardware crypto wallet and recovered $2 million | Goe Grand
Raspberry Pi Transmitter with RPITX Version 2
Running PinAP & Karma on Pineapple MK V clone
GPS Spoofing With The HackRF On Windows

Contact me :

Linkedin
Email : ahmedalroky@gmail.com