IoT penetration testing featured image of a circuit board

How To Perform IoT Penetration Testing

Unless you have been living under a rock for the past 5 years you’ll have noticed the IoT industry has been ripe with software vulnerabilities. Everything from cars, fridges and children toys have been exploited by hackers.

So what’s the solution? What can manufactures do to prevent their devices being so inherently insecure.

IoT Penetration Testing

A form of security testing called penetration testing (aka pen testing for short) is a form of ethical hacking which has been around ever since the invention of locks and pretty much every security and access system. Manufacturers and cyber security experts will pay to have their systems tested by professional penetration testers for weaknesses that could be exploited by cyber criminals to gain access without following due procedures. these tests help strengthen device security, protect against unauthorised usage, avoiding privilege elevation, increase privacy, improve user data privacy and set stronger encryptions to avoid man in the middle attacks.

IoT penetration testing is much similar to this traditional white hat hacker pen testing procedure which involves just taking shots at the systems to try and find weaknesses and exploit them but it introduces a more complex environment to test in a wider surface and attack vectors. It actually require that the expert create an ecosystem for every specific IoT device and test the unique array of attack vectors so as to uncover all potential vulnerabilities.

This means that IoT can thwart more sophisticated attacks unlike the traditional one that lure the human user to open a malicious link. In IoT, the system does not have any end user behind the device which makes it that much more difficult to break in.also the scope of IoT is much larger than the familiar windows and Linux systems and extends to some uncommon systems like ARM, MIPS, and PowerPC among many others. The communication protocols are also deep end stuff like ZigBee SDR and BLE.

Steps to conduct an IOT penetration testing

Determine the protocols and their weaknesses

The tester is able to find out what kind of information is a low hanging fruit for hackers to capture and
exploit to gain access to the system.

Conduct web app security testing to check for vulnerabilities to exploit

Basic and advanced web application security testing will identify any weaknesses found within web based applications, API’s or client the configuration of the device being tested.

Find a back door into system

Using the pen testing tools embedded, testers have to find a backdoor into the system just like a real life hacker would.

Testing obscure OS instances

Whether the device is running linux based OS or some on-off operating system, the tester has to find any weaknesses in the OS if any. Other times devices lack any OS in the first place in which case the application has to be fully decompiled to determine if vulnerable.

Reverse engineer applications to check for vulnerabilities

A penetration tester has to be good at network security, web testing, embedded engineering, testing obscure OS instances, and reverse engineering apps. For one to pull off this kind of test effectively, they have to be well versed with all of the above areas or work in teams to complement each other skills.
While this is only the tip of the iceberg of what there is to know about IoT penetration tests, thisis basically what is done.

Standards and Methodologies

There are a number of standards for penetration testing, typically for IoT devices you would want to refer to the OWASP project and ensure any testing you conduct (or use a 3rd party for) is manual. Automated tools can be used as part of the process but the basis of the testing should approached by an pen tester with a similar hacker mindset of a real hacker.

We hope this has helped provide an overview for those wishing to conduct a IoT penetration test, if you have an questions please drop me a comment below and I will do my best to get back to you with a day or two.

Gaming mouse on a pad for header image

Buyers Tips For Gaming Mice in 2017

Gamers might find themselves in dilemma when it comes to purchasing the best gaming mouse. With the right gaming mouse, the experience to play the game becomes smooth and it will offer the best performance. A cheap gaming mouse will not be able to offer the best performance when playing games, the same goes for an incorrectly configured gaming mouse. We recommend you spend some significant time learning your mouse settings and configuring your gaming mouse to benefit the most from the purchase. There are a variety of gaming mice available and it becomes hard to choose the right gaming mouse. There are some factors that one will need to consider when they are purchasing the right and the best gaming mouse. To help one out, this article provides some of the key features you’ll need to review when looking for the best gaming mouse of 2017. So, lets jump right in and review the top gaming mice features for 2017:

A Look At Some Buyers Tips For Gaming Mice:

  • First of all, one will need to check out the various brands of gaming mice that are available in the market. After this, one will need to select the gaming mouse option from all purpose gaming mouse or specialized gaming mouse. If one is only looking for gaming purpose, then it is best to choose the specialized gaming mouse. However, if one is looking for using the mouse for other purposes, other than playing game, then one should definitely opt for all purpose gaming mouse as it will be the best option, on the other hand, the all specialized gaming mouse will not be able to give better performance when it comes to other purposes, other than gaming.

  • All purpose mice are one of the common types of mice available in the market. These mice come in various sizes and shapes. If one is looking to play a wide range of game, these mice are the best option as they are versatile and they are able to handle a wide range of actions.
  • Another type of mice which is available in the market is FPS mice is the best option for gaming mice as they are able to offer the best performance when playing the high performance games such as: call of duty, battlefield, rainbow six, counter strike etc. There is also a good amount of overlap between the all purpose mice and the FPS mice. The FPS mice will have a sniper button, which is distinctive and it is place right beneath the thumb. This will help to slow down the DPI and the gamer will be able to line up the difficult shots.
  • MMO mice are types of gaming mice which one can check out. This mice is the best for games such as world of Warcraft, star wars etc. This type of gaming mouse is bulky in size and it will offer excellent performance when playing these types of games. This mouse is perfect for firing off the difficult skill rotations and this is also with the second precision. Some of these mice will also help to assign the gamer with the alternate button maps and these can be easily accessed with the click of the finger.
  • RTS mice are a type of mice that will also help to provide excellent performance when playing action packed games such as: star crafts.
  • Customizable mice are expensive but they will offer the best experience when it comes to playing games. There are various price tags of these mice that one can purchase from the market without any hassle.
  • There are three types of cost categories that these gaming mice are categorized into. The cheaper categories are less than $50 dollars, although they will be able to offer the gamer to play the game but they will not be able to offer the excellent performance that one is looking for. The mid range mice are categories of $50 – $100 and they will offer good experience when playing the game. The expensive mice will cost more than $100 and they will offer the best experience. The price of the mouse will also vary from one brand to another and from one type of mouse to another. The new models of the gaming mice will also cost more than the regular ones and also the gaming mice which comes with extra features. This is why one should take a look at range of gaming mice according to their needs and requirements.

Some mice are heavier than others and if one is looking for a lighter weight mouse, they will need to take a look at the weight of the mice before purchasing them. A light weight gaming mouse is easier to move around and they are easier to handle as well.

  • Gaming mice can come with the option of laser sensor or optical sensor. Both of these work fine but it depends on the need of the player.
  • Connectivity is another factor one will need to consider. One can sync up these with the devices to get better experience when playing the action packed games.

One should always make sure to read the customer reviews and then select the gaming mouse, considering these factors to help them to select the best gaming mouse.

Gaming Mouse Windows Settings

As mentioned previously in this article, it’s important to correctly configure your mouse for gaming. Settings like mouse acceleration or incorrectly configured windows mouse sensitivity can greatly impact your gaming. We recommend you follow this guide on how to setup your windows mouse sensitivity and dpi settings for your new gaming mouse. You can have the best mouse in the world, but if you don’t spend the time to set it up correctly, it could lose you the competitive advantage!

An image of wearable tech products for 2017

Best Wearable Technology 2017

Wearable tech refers to all forms for electronics that you can wear on yourself as accessories, such as watches or as part of the fabric of your clothes. In 2017, such device have one common denominator which is connectivity to an internet of things so that they are constantly transmitting data. From smart watches and health and fitness to wearable PCs for tactical, media development and everyday use. So whether you are looking to get on the track or outdoor sports and cycling, you can benefit from shopping for some smart wearable tech toys to help monitor your health and keep track of time and other data.

History of wearable technologies

There are wearable gadgets out there with motion sensors that enable them to take photos and collect other data then remotely sync with your mobile devices in real time. Wearable’s never get old. The have been around for a while now but they are still fashionable technology coupled with some practical functionalities to make your life outdoors a whole lot easier.

Wearable’s have been around at least as an idea since early 1930s and have since evolved into the most sophisticated body worn or even implant technologies with surprisingly large storage and complex processing and network capabilities while adapting to the mistreatment’s of being body worn like flexing and accepting a shower or a dive in the pool. The beauty in it now is that the devices we are seeing in the market today have a practical application that will help simplify the consumer’s life rather than just for fashion and style as with other articles worn. These also enjoy connectivity with mobile devices and application on smartphones.

Why is there such a fuss about fashionable tech?

The key contributing factor to the growth of the smart wear industry has been the increasing popularity of the mobile networks and other wireless technologies for simpler and healthier lives. The software developers for wearable apps has not been left behind in developing smart apps to support wearable technologies and even offering it for free for use. This has diversified the use of wearable tech to other fields such as maps, sports and health.

More applications for smart wear for business

Businesses and companies are able to collect useful data about their employees and customers using smart wear. Also, business owners can keep track of their numbers while out of the office with ease. How companies and application developers choose to use the data they are able to capture through these devices remains subject to available and emerging privacy regulations and the willingness of users to allow access to personal data.

The future

Into the future, all indicators show that this tech is not about to go away thanks to its efficiency and popularity and most of all, volatility of use. This and their popularity as a fashion item, the smart wear items are likely to continue being one of the most used devices around the globe. We will continue to see innovation and more ergonomic designs in the future with more sophisticated power, processing and networking capabilities.