EC-Council Certified Ethical Hacker (CEH) v12Mobile Platform, IoT, and OT HackingHard

An unauthenticated attacker discovers a smart light bulb in a publicly accessible area that responds to commands sent via a proprietary wireless protocol. By reverse engineering the protocol, the attacker can send commands to change the light's color and brightness. However, they are unable to cause any permanent damage or gain access to other networked devices. Which of the following attack vectors is the attacker primarily exploiting?

  1. AInsecure direct object references.
  2. BAbsence of authentication/authorization for device commands.
  3. CZero-day vulnerability in the device's operating system.
  4. DLack of input validation on device commands.
Show answer & explanation

Correct answer: B. Absence of authentication/authorization for device commands.

The attacker's ability to send commands to the light bulb without prior authentication implies a fundamental absence of authentication and/or authorization for device commands. While reverse engineering the protocol is part of the process, the core vulnerability is that the device accepts commands from any source.

Why the other options are wrong

  • A. Insecure direct object references relate to accessing other resources via predictable IDs, which isn't the primary issue of controlling the light bulb itself without authentication.
  • C. A zero-day OS vulnerability would likely allow for more severe control or persistence, not just command execution.
  • D. Lack of input validation might allow for buffer overflows or crashes, but the scenario describes successful command execution, not malformed input leading to errors.

IoT Insecure Authorization

A vulnerability in IoT devices where commands or access to resources are not properly authenticated or authorized, allowing unauthorized users to control the device or access its data.

  • Devices accept commands from any source without verifying identity.
  • Can lead to unauthorized control, data manipulation, or denial of service.
  • Often due to simplified design for ease of use, neglecting security.

Memory trick: No 'auth' on IoT commands is like an open door to the smart light.

More Mobile Platform, IoT, and OT Hacking questions