Web-based Attacks on Local IoT Devices

pdf

Abstract: In this paper, we present two web-based attacks against local IoT devices that any malicious web page or third-party script can perform, even when the devices are behind NATs. In our attack scenario, a victim visits the attacker’s website, which contains a malicious script that communicates with IoT devices on the local network that have open HTTP servers. We show how the malicious script can circumvent the same-origin policy by exploiting error messages on an HTML5 interface or by carrying out DNS rebinding attacks.

  • 1739809
  • 2018
  • CPS-PI Meeting 2018
  • Poster
  • Posters (Sessions 8 & 11)
Submitted by Anonymous on