IoT Pentesting and Hardware Hacking
Testing IoT device security — from firmware analysis and UART/JTAG debugging through flash dumping, side-channel attacks, and hardware backdoors.
When to Use
Assessing physical IoT device security
Extracting firmware for vulnerability analysis
Hardware debugging interfaces (UART, JTAG, SWD)
Side-channel and fault injection analysis
Wireless protocol analysis on IoT devices
Hardware Hacking Techniques
HARDWARE_TECHNIQUES = {
'firmware_extraction': 'Dump flash via SPI, chip-off, UART bootloader, or update file analysis',
'uart_debug': 'Connect to UART (TX/RX/GND) at 115200 baud — often gives root shell',
'jtag_swd': 'Debug port via JTAG/SWD — full device control, memory read/write',
'eeprom_i2c': 'Read configuration EEPROM via I2C — credentials, API keys, certs',
'flash_dump': 'Dump SPI flash (Winbond, Macronix) with Bus Pirate, flashrom, or chip-off',
'side_channel': 'Power analysis, electromagnetic, timing — extract crypto keys',
'fault_injection': 'Glitch power/clock to bypass secure boot, authentication',
}
# Firmware analysis workflow
FIRMWARE_ANALYSIS = [
"binwalk firmware.bin — extract filesystem",
"strings firmware.bin | grep -E 'password|key|secret|token|http://|https://'",
"firmwalker firmware.extracted/ — find interesting paths and configs",
"checksec --file=extracted/sbin/init — check binary mitigations",
"Ghidra decompile: analyze binaries for hardcoded creds and backdoors",
]
Verification Checklist
Physical interfaces identified (UART, JTAG, SWD, SPI, I2C)
UART console accessed (baud rate detection, root shell)
Flash/firmware dumped (via SPI or chip-off)
Firmware analyzed (filesystem, binaries, hardcoded secrets)
Default credentials tested (admin/admin, root:root)
OTA update mechanism analyzed (signed? encrypted? replay?)
Wireless protocols tested (Zigbee, Z-Wave, BLE, WiFi)
Physical security assessed (tamper switches, epoxy, potting)
No destructive testing on production devices (unless authorized)
1 --- 2 name: iot-pentesting-hardware-hacking 3 description: Use when testing IoT device and hardware security. 4 license: MIT 5 --- 6 7 # IoT Pentesting and Hardware Hacking 8 9 Testing IoT device security — from firmware analysis and UART/JTAG debugging through flash dumping, side-channel attacks, and hardware backdoors. 10 11 ## When to Use 12 13 - Assessing physical IoT device security 14 - Extracting firmware for vulnerability analysis 15 - Hardware debugging interfaces (UART, JTAG, SWD) 16 - Side-channel and fault injection analysis 17 - Wireless protocol analysis on IoT devices 18 19 ## Hardware Hacking Techniques 20 21 ```python 22 HARDWARE_TECHNIQUES = { 23 'firmware_extraction': 'Dump flash via SPI, chip-off, UART bootloader, or update file analysis', 24 'uart_debug': 'Connect to UART (TX/RX/GND) at 115200 baud — often gives root shell', 25 'jtag_swd': 'Debug port via JTAG/SWD — full device control, memory read/write', 26 'eeprom_i2c': 'Read configuration EEPROM via I2C — credentials, API keys, certs', 27 'flash_dump': 'Dump SPI flash (Winbond, Macronix) with Bus Pirate, flashrom, or chip-off', 28 'side_channel': 'Power analysis, electromagnetic, timing — extract crypto keys', 29 'fault_injection': 'Glitch power/clock to bypass secure boot, authentication', 30 } 31 32 # Firmware analysis workflow 33 FIRMWARE_ANALYSIS = [ 34 "binwalk firmware.bin — extract filesystem", 35 "strings firmware.bin | grep -E 'password|key|secret|token|http://|https://'", 36 "firmwalker firmware.extracted/ — find interesting paths and configs", 37 "checksec --file=extracted/sbin/init — check binary mitigations", 38 "Ghidra decompile: analyze binaries for hardcoded creds and backdoors", 39 ] 40 ``` 41 42 ## Verification Checklist 43 44 - [ ] Physical interfaces identified (UART, JTAG, SWD, SPI, I2C) 45 - [ ] UART console accessed (baud rate detection, root shell) 46 - [ ] Flash/firmware dumped (via SPI or chip-off) 47 - [ ] Firmware analyzed (filesystem, binaries, hardcoded secrets) 48 - [ ] Default credentials tested (admin/admin, root:root) 49 - [ ] OTA update mechanism analyzed (signed? encrypted? replay?) 50 - [ ] Wireless protocols tested (Zigbee, Z-Wave, BLE, WiFi) 51 - [ ] Physical security assessed (tamper switches, epoxy, potting) 52 - [ ] No destructive testing on production devices (unless authorized)