IoT Hacking - Polycom Conference Phone - Web Exploitation

Поделиться
HTML-код
  • Опубликовано: 20 окт 2024
  • In this video we demonstrate some typical web application analysis performed when security testing IoT devices.
    gist.github.co...
    cve.mitre.org/...
    IoT Hackers Hangout Community Discord Invite:
    / discord
    🛠️ Stuff I Use 🛠️
    🪛 Tools:
    XGecu Universal Programmer: amzn.to/4dIhNWy
    Multimeter: amzn.to/4b9cUUG
    Power Supply: amzn.to/3QBNSpb
    Oscilloscope: amzn.to/3UzoAZM
    Logic Analyzer: amzn.to/4a9IfFu
    USB UART Adapter: amzn.to/4dSbmjB
    iFixit Toolkit: amzn.to/44tTjMB
    🫠 Soldering & Hot Air Rework Tools:
    Soldering Station: amzn.to/4dygJEv
    Microsoldering Pencil: amzn.to/4dxPHwY
    Microsoldering Tips: amzn.to/3QyKhrT
    Rework Station: amzn.to/3JOPV5x
    Air Extraction: amzn.to/3QB28yx
    🔬 Microscope Setup:
    Microscope: amzn.to/4abMMao
    Microscope 0.7X Lens: amzn.to/3wrV1S8
    Microscope LED Ring Light: amzn.to/4btqiTm
    Microscope Camera: amzn.to/3QXSXsb
    About Me:
    My name is Matt Brown and I'm an Hardware Security Researcher and Bug Bounty Hunter. This channel is a place where I share my knowledge and experience finding vulnerabilities in IoT systems.
    Soli Deo Gloria
    💻 Social:
    twitter: / nmatt0
    linkedin: / mattbrwn
    github: github.com/nma...
    #hacking #iot #cybersecurity #privacy #wireshark

Комментарии • 34

  • @funkadellicd
    @funkadellicd 6 месяцев назад +12

    So pumped that you're putting these out so frequently. I found your channel recently and was sad when i blew through some of your other vid series so fast and you started back up just in time!

    • @franklinodom4259
      @franklinodom4259 6 месяцев назад

      Big same, i thought I missed the Matt boat, stoked to see new uploads!

  • @TradieTrev
    @TradieTrev 6 месяцев назад +9

    Well done Matt! Great series on the Polycom, I do enjoy your unscripted style!

  • @OnlyVoltsRT
    @OnlyVoltsRT 6 месяцев назад +5

    Ehy Matt. Really Cool!
    i usually practice about classic hacker stuff like web pentesting, ctf, hackthebox, etc etc... and i'm really curious about other hacking areas like : firmware extraction, IOT hacking etc. In this video you join the 2 things making a really really cool content. Well Done!

  • @matheuscezar6309
    @matheuscezar6309 6 месяцев назад +6

    Every new video it's a new learning. Thanks a lot! I speak from Brazil!!

  • @martinskorvald2121
    @martinskorvald2121 5 месяцев назад +3

    Why not try opening the S3 bucket to see if all versions of the firmware are there and maybe more things to use for investigation?

  • @amaama4140
    @amaama4140 5 месяцев назад

    Great video, can't wait to see your firmware analysis video.

  • @ingermany1523
    @ingermany1523 6 месяцев назад

    Keep it up. Really nice content. I am glad that I somehow manage to find your channel and to subscribe.

  • @OfficialProjectSMP
    @OfficialProjectSMP 6 месяцев назад +2

    Suggestion: number the episodes in this series for posterity 😊

  • @tubes41
    @tubes41 5 месяцев назад +1

    I wonder if you could just change the HTTP request to the polycom download server to get all the earlier versions of the firmware and their download links?

  • @adammoss5284
    @adammoss5284 3 месяца назад

    Thanks for the videos Matt, I purchased a poly phone to have a play with off the bay.
    Any chance looking over the HDX gear? I picked up a fair bit of this stuff and it looks fun. Found a video of a guy booting one and a compact flash card was staring me in the face so it looks kinda fun..

  • @saireddy9707
    @saireddy9707 5 месяцев назад

    awesome work matt great fan of your work keep doing such awesome content happy to see such great researchers like you in our infosec space who are always ready to contribute and educate.

  • @joshpontes1366
    @joshpontes1366 6 месяцев назад +2

    What microscope do you use? I got a little tomlov one on Amazon and haven’t been happy with it

    • @mattbrwn
      @mattbrwn  6 месяцев назад

      It's an Amscope. Same one Louis Rossmann uses.

  • @j3ssh594
    @j3ssh594 6 месяцев назад

    Awesome stuff Matt, You are the GOAT 🐐

  • @WangLees
    @WangLees 6 месяцев назад

    Keep up the great work Matt!

  • @majed3469
    @majed3469 6 месяцев назад +1

    if they use Rtos in their firmware, where the web application source code

  • @tylersharpe9413
    @tylersharpe9413 6 месяцев назад

    Thanks for sharing info on how to do stuff like this.

  • @matheuscezar6309
    @matheuscezar6309 6 месяцев назад +2

    The "/languages" endpoint looks like a LFI 🤔

    • @mattbrwn
      @mattbrwn  6 месяцев назад +1

      I tried that! no luck :(

  • @superboytiti
    @superboytiti 2 месяца назад

    Hi! Is ti possible Haking a polycom system like a g300 series? I would like to use it with Microsoft teams

  • @VillageShorts36
    @VillageShorts36 6 месяцев назад

    hi i have sti7111 boards can we open uart acess ?

  • @edwinking4407
    @edwinking4407 6 месяцев назад

    Fine and great video.

  • @doubled8511
    @doubled8511 4 месяца назад

    Which linux distro are you using?

    • @mattbrwn
      @mattbrwn  4 месяца назад +1

      arch linux :)

  • @Electrically-Electronic
    @Electrically-Electronic 6 месяцев назад

    Great keep it up.

  • @distortions
    @distortions 6 месяцев назад

    subbed!

  • @lmaoroflcopter
    @lmaoroflcopter 6 месяцев назад

    It would be a nice spot for xml injection.

  • @Tech2C
    @Tech2C 6 месяцев назад

    All these business comms devices have been supplanted by MS Teams nowadays

  • @Tech2C
    @Tech2C 6 месяцев назад

    All these business comms devices have been supplanted by MS Teams nowadays

    • @2Fast4Mellow
      @2Fast4Mellow 5 месяцев назад

      They are not. I visit a lot of larger corporations and they still use physical voip devices. You can't use MS Team/Skype/SlackWare/Zoom/Jitsi/Matrix-Synapse/GoogleMeet to contact regular people. The other person(s) have to use the same software. We do use HTML5 WebRTC sip (software) phone for customer/service desk (callcenter) solutions, but they are all running behind Kamailio/Asterisk PBX setups.
      Board rooms are still using these conference bridge phones. They are still the norm to quickly get a whole bunch of different people together and they are all using their own hardware. Good luck getting a zoom link to your ISP service desk. Even when you are in a meeting a need a quick update of a specific project, they call an extension, ask the question and get an answer directly or they get called back. Ever tried to order a pizza with MS Teams? Works much better with last century technology...
      Conference software have their place, but in general are only used to communicate with familiar people. When you need to contact someone you don't know, most people use the plain old telephone...

    • @adammoss5284
      @adammoss5284 3 месяца назад

      That eagle eye camera of theirs and their zone mics are way too nice to throw in a dumpster.