EC-Council Certified Ethical Hacker (CEH) v12Mobile Platform, IoT, and OT HackingEasy
A cybersecurity analyst is investigating an incident where a smart thermostat in a manufacturing plant was remotely manipulated, causing a critical temperature fluctuation that disrupted production. The thermostat communicates wirelessly within a segmented network. Which of the following attack vectors was most likely exploited in this scenario?
- ADefault/Weak Credentials
- BDenial of Service (DoS)
- CCross-Site Scripting (XSS)
- DSQL Injection
Show answer & explanationAnswer & explanation
Correct answer: A. Default/Weak Credentials
IoT devices are frequently deployed with default passwords or easily guessable credentials, making them prime targets for unauthorized access and control. Remotely manipulating a device typically involves authentication, which weak credentials compromise.
Why the other options are wrong
- B. Denial of Service (DoS) aims to make a service unavailable, not to manipulate its functions like temperature control.
- C. Cross-Site Scripting (XSS) targets web applications to inject malicious scripts, not direct device control.
- D. SQL Injection targets databases, not typically used for direct device manipulation in a thermostat.
IoT Default Credentials
Pre-set usernames and passwords on Internet of Things (IoT) devices that are often not changed by users, creating a significant security vulnerability.
- Many IoT devices ship with universal default credentials.
- Attackers can easily find lists of these defaults online.
- Failure to change them allows unauthorized remote access.
Memory trick: IoT's door is often open with default keys.