这篇文章主要记录练习IoTGoat项目中的漏洞挑战,这些挑战基于2018年OWASP物联网十大漏洞,尽管时间比较久了,但是对于新手学习来说,还是十分不错的。具体如下:
| OWASP IoT Top 10 2018 | Description |
|---|---|
| I1 Weak, Guessable, or Hardcoded Passwords | Use of easily bruteforced, publicly available, or unchangeable credentials, including backdoors in firmware or client software that grants unauthorized access to deployed systems. |
| I2 Insecure Network Services | Unneeded or insecure network services running on the device itself, especially those exposed to the internet, that compromise the confidentiality, integrity/authenticity, or availability of information or allow unauthorized remote control. |
| I3 Insecure Ecosystem Interfaces | Insecure web, backend API, cloud, or mobile interfaces in the ecosystem outside of the device that allows compromise of the device or its related components. Common issues include a lack of authentication/authorization, lacking or weak encryption, and a lack of input and output filtering. |
| I4 Lack of Secure Update Mechanism | Lack of ability to securely update the device. This includes lack of firmware validation on device, lack of secure delivery (un-encrypted in transit), lack of anti-rollback mechanisms, and lack of notifications of security changes due to updates. |
| I5 Use of Insecure or Outdated Components | Use of deprecated or insecure software components/libraries that could allow the device to be compromised. This includes insecure customization of operating system platforms, and the use of third-party software or hardware components from a compromised supply chain |
| I6 Insufficient Privacy Protection | User’s personal information stored on the device or in the ecosystem that is used insecurely, improperly, or without permission. |
| I7 Insecure Data Transfer and Storage | Lack of encryption or access control of sensitive data anywhere within the ecosystem, including at rest, in transit, or during processing |
| I8 Lack of Device Management | Lack of security support on devices deployed in production, including asset management, update management, secure decommissioning, systems monitoring, and response capabilities. |
| I9 Insecure Default Settings | Devices or systems shipped with insecure default settings or lack the ability to make the system more secure by restricting operators from modifying configurations. |
| I10 Lack of Physical Hardening | Lack of physical hardening measures, allowing potential attackers to gain sensitive information that can help in a future remote attack or take local control of the device. |
下面的内容就是搭建环境以及完成这些挑战。
环境搭建
在环境搭建方面,官方给了很多方法,有下载磁盘镜像创建虚拟机的、有模拟固件利用QEMU在本地虚拟化IotGoat的、有Docker设置在容器里面运行的、也有用固件刷入树莓派的。当然对于新手来说,最简单的方法就是创建虚拟机,挑战也会在这个虚拟机上面进行完成。后面有机会的话,会在这里更新其他搭建方法。
虚拟机
这里不再说明VMware的安装了,有不会的就自行查找方法。
VMware准备好后,首先要获取IoTGoat固件Releases · OWASP/IoTGoat,进入页面后,直接点击下载IoTGoat-x86.vmdk,这个文件就是所需虚拟磁盘文件,所谓虚拟磁盘,就是模拟一个真实磁盘中的内容。

接着就开始在VMware里面开始创建了,和创建Ubuntu的方法是差不多的。不会的可以借鉴零基础实践物联网安全——IoTGoat物联网靶场实战(一)-CSDN博客这篇文章,这里就不再多说了。

跟着那篇文章一步一步做,出现上面这个图片的内容,就说明安装成功了。