23
ZIGDIGGITY ZIGBEE HACKING TOOLKIT AUGUST 7-11, 2019 http://zigdiggity.com

ZIGBEE HACKING TOOLKIT - Bishop Fox...\爀 屲Unfortunately, existing Zigbee hacking solutions have fallen into disrepair, hav對ing barely been maintained, let alone improved upon

  • Upload
    others

  • View
    18

  • Download
    0

Embed Size (px)

Citation preview

ZIGDIGGITY ZIGBEE HACKING TOOLKIT

AUGUST 7-11, 2019

h t t p : / / z i g d i g g i t y . c o m

Presenter
Presentation Notes
https://github.com/BishopFox/zigdiggity https://www.bishopfox.com/ MORE Links - 2019 - Black Hat USA 2019 & DEF CON 27: https://www.defcon.org/html/defcon-27/dc-27-demolabs.html#ZigDiggity https://www.blackhat.com/us-19/arsenal/schedule/index.html#arsenal-lab---zigbee-hacking-smarter-home-invasion-with-zigdiggity-17151 Zigbee Hacking: Smarter Home Invasion with ZigDiggity - 56sec DEMO - 20Aug2019 – YouTube https://www.youtube.com/watch?v=rM495gGRTYQ ABSTRACT: Do you feel safe in your home with the security system armed? You may reconsider after watching a demo of our new hacking toolkit, ZigDiggity, where we target door & window sensors using an "ACK Attack". ZigDiggity will emerge as the weapon of choice for testing Zigbee-enabled systems, replacing all previous efforts. Zigbee continues to grow in popularity as a method for providing simple wireless communication between devices (i.e. low power/traffic, short distance), & can be found in a variety of consumer products that range from smart home automation to healthcare. Security concerns introduced by these systems are just as diverse and plentiful, underscoring a need for quality assessment tools. Unfortunately, existing Zigbee hacking solutions have fallen into disrepair, having barely been maintained, let alone improved upon. Left without a practical way to evaluate the security of Zigbee networks, we've created ZigDiggity, a new open-source pentest arsenal from Bishop Fox. Our DEMO-rich presentation showcases ZigDiggity's attack capabilities by pitting it against common Internet of Things (IoT) products that use Zigbee. Come experience the future of Zigbee hacking, in a talk that the New York Times will be hailing as "a veritable triumph of the human spirit." ... ya know, probably

WHAT IS ZIGDIGGITY???

BISHOPFOX PROPRIETARY | 2019

ht tp : / /z igd igg i ty.com

2

RaspBee radio + Raspberry Pi

ZigDiggity - GitHub Code

+ =

NEW ZIGBEE HACKING TOOLKIT – FREE, OPEN-SOURCE

Presenter
Presentation Notes
https://github.com/BishopFox/zigdiggity https://www.bishopfox.com/ RaspBee – Zigbee radio add-on for Raspberry Pi: https://www.amazon.com/RaspBee-premium-ZigBee-Raspberry-Firmware/dp/B00E6300DO Raspberry Pi 3 B+ https://www.amazon.com/CanaKit-Raspberry-Power-Supply-Listed/dp/B07BC6WH7V RasPad by SunFounder - great for creating portable Zigbee hacking solution, tablet to house the Raspberry Pi 3 B+ and RaspBee radio: https://www.amazon.com/SunFounder-RasPad-Built-Touchscreen-Compatible/dp/B07JG53K2W/

ZIGDIGGITY – WITH RASPAD

BISHOPFOX PROPRIETARY | 2019 3

PORTABLE ZIGBEE HACKING SOLUTION

Presenter
Presentation Notes
https://github.com/BishopFox/zigdiggity https://www.bishopfox.com/ RaspBee - Zigbee radio add-on for Raspberry Pi: https://www.amazon.com/RaspBee-premium-ZigBee-Raspberry-Firmware/dp/B00E6300DO Raspberry Pi 3 B+ https://www.amazon.com/CanaKit-Raspberry-Power-Supply-Listed/dp/B07BC6WH7V RasPad by SunFounder - great for creating portable Zigbee hacking solution, tablet to house the Raspberry Pi 3 B+ and RaspBee radio: https://www.amazon.com/SunFounder-RasPad-Built-Touchscreen-Compatible/dp/B07JG53K2W/

WHAT IS ZIGBEE???

BISHOPFOX PROPRIETARY | 2019 4

SIMPLE WIRELESS - LOW POWER / TRAFFIC, SHORT DISTANCE

BISHOPFOX PROPRIETARY | 2019

ht tp : / /z igd igg i ty.com

5

Presenter
Presentation Notes
https://github.com/BishopFox/zigdiggity Zigbee Hacking: Smarter Home Invasion with ZigDiggity - 56sec DEMO - 20Aug2019 – YouTube https://www.youtube.com/watch?v=rM495gGRTYQ

BISHOPFOX PROPRIETARY | 2019

Presenter
Presentation Notes
https://github.com/BishopFox/zigdiggity Zigbee Hacking: Smarter Home Invasion with ZigDiggity - 56sec DEMO - 20Aug2019 – YouTube https://www.youtube.com/watch?v=rM495gGRTYQ

BISHOPFOX PROPRIETARY | 2019 9

h t t p : / / z i g d i g g i t y . c o m

DEMO’S

Presenter
Presentation Notes
https://github.com/BishopFox/zigdiggity Zigbee Hacking: Smarter Home Invasion with ZigDiggity - 56sec DEMO - 20Aug2019 – YouTube https://www.youtube.com/watch?v=rM495gGRTYQ

BISHOPFOX PROPRIETARY | 2019 10

h t t p : / / z i g d i g g i t y . c o m

Presenter
Presentation Notes
https://github.com/BishopFox/zigdiggity Zigbee Hacking: Smarter Home Invasion with ZigDiggity - 56sec DEMO - 20Aug2019 – YouTube https://www.youtube.com/watch?v=rM495gGRTYQ

BISHOPFOX PROPRIETARY | 2019 11

h t t p : / / z i g d i g g i t y . c o m

BISHOPFOX PROPRIETARY | 2019 12

ZIGBEE - INSECURE REJOIN ZIGBEE ATTACK – CONVENIENCE VS SECURITY

h t t p s : / / s u p p o r t . s m a r t t h i n g s . c o m / h c / e n - u s / a r t i c l e s / 2 0 8 2 0 1 2 4 3 - Z i g B e e - I n s e c u r e - R e j o i n - F A Q

Presenter
Presentation Notes
https://support.smartthings.com/hc/en-us/articles/208201243-ZigBee-Insecure-Rejoin-FAQ

BISHOPFOX PROPRIETARY | 2019 13

h t t p : / / z i g d i g g i t y . c o m

BISHOPFOX PROPRIETARY | 2019 14

OBSCURE ZIGBEE ATTACK, NOW IMPLEMENTED ZIGBEE – ACK ATTACK

Presenter
Presentation Notes
http://www.ann.ece.ufl.edu/courses/eel6935_11fal/student_talks/Presentation_9-29-11.pdf#page=51 6.4.1 ACK Attack - Pg 174-175 - ZigBee Network Protocols and Applications - Wang - March 2014 - Google Books https://books.google.com/books?id=uJ_MBQAAQBAJ&lpg=PP1&dq=ZigBee%20network%20protocols%20and%20applications&pg=PA174#v=onepage&q=ZigBee%20network%20protocols%20and%20applications&f=false

THANK YOU

ht tp : / /z igd igg i ty.com