这篇文章主要记录练习IoTGoat项目中的漏洞挑战,这些挑战基于2018年OWASP物联网十大漏洞,尽管时间比较久了,但是对于新手学习来说,还是十分不错的。具体如下:

OWASP IoT Top 10 2018 Description
I1 Weak, Guessable, or Hardcoded Passwords Use of easily bruteforced, publicly available, or unchangeable credentials, including backdoors in firmware or client software that grants unauthorized access to deployed systems.
I2 Insecure Network Services Unneeded or insecure network services running on the device itself, especially those exposed to the internet, that compromise the confidentiality, integrity/authenticity, or availability of information or allow unauthorized remote control.
I3 Insecure Ecosystem Interfaces Insecure web, backend API, cloud, or mobile interfaces in the ecosystem outside of the device that allows compromise of the device or its related components. Common issues include a lack of authentication/authorization, lacking or weak encryption, and a lack of input and output filtering.
I4 Lack of Secure Update Mechanism Lack of ability to securely update the device. This includes lack of firmware validation on device, lack of secure delivery (un-encrypted in transit), lack of anti-rollback mechanisms, and lack of notifications of security changes due to updates.
I5 Use of Insecure or Outdated Components Use of deprecated or insecure software components/libraries that could allow the device to be compromised. This includes insecure customization of operating system platforms, and the use of third-party software or hardware components from a compromised supply chain
I6 Insufficient Privacy Protection User’s personal information stored on the device or in the ecosystem that is used insecurely, improperly, or without permission.
I7 Insecure Data Transfer and Storage Lack of encryption or access control of sensitive data anywhere within the ecosystem, including at rest, in transit, or during processing
I8 Lack of Device Management Lack of security support on devices deployed in production, including asset management, update management, secure decommissioning, systems monitoring, and response capabilities.
I9 Insecure Default Settings Devices or systems shipped with insecure default settings or lack the ability to make the system more secure by restricting operators from modifying configurations.
I10 Lack of Physical Hardening Lack of physical hardening measures, allowing potential attackers to gain sensitive information that can help in a future remote attack or take local control of the device.

下面的内容就是搭建环境以及完成这些挑战。

环境搭建

在环境搭建方面,官方给了很多方法,有下载磁盘镜像创建虚拟机的、有模拟固件利用QEMU在本地虚拟化IotGoat的、有Docker设置在容器里面运行的、也有用固件刷入树莓派的。当然对于新手来说,最简单的方法就是创建虚拟机,挑战也会在这个虚拟机上面进行完成。后面有机会的话,会在这里更新其他搭建方法。

虚拟机

这里不再说明VMware的安装了,有不会的就自行查找方法。

VMware准备好后,首先要获取IoTGoat固件Releases · OWASP/IoTGoat,进入页面后,直接点击下载IoTGoat-x86.vmdk,这个文件就是所需虚拟磁盘文件,所谓虚拟磁盘,就是模拟一个真实磁盘中的内容。

接着就开始在VMware里面开始创建了,和创建Ubuntu的方法是差不多的。不会的可以借鉴零基础实践物联网安全——IoTGoat物联网靶场实战(一)-CSDN博客这篇文章,这里就不再多说了。

跟着那篇文章一步一步做,出现上面这个图片的内容,就说明安装成功了。