[BlackHat USA tool] Internet Of Things Exploitation Framework

Expliot

(Pronounced – expl-aa-yo-tee)

Internet Of Things Exploitation Framework

Expliot is a framework for security testing IoT and IoT infrastructure. It provides a set of plugins (test cases) and can be extended easily to create new plugins. The name expliot is a pun on the exploit and explains the purpose of the framework i.e. IoT exploitation. It is developed in python3.

It can be used as a standalone tool for IoT security testing and more interestingly, it provides building blocks for writing new plugins/exploits and other IoT security assessment test cases with ease. EXPLIoT supports most IoT communication protocols, hardware interfacing functionality and test cases that can be used from within the framework to quickly map and exploit an IoT product or IoT Infrastructure.
It will help the security community in writing quick IoT test cases and exploits. The objectives of the framework are:

  1. Easy to use
  2. Easy to extend
  3. Support for most IoT protocols
  4. Support for Radio IoT protocols
  5. Support for hardware protocols
  6. One-stop-shop for IoT and IoT infrastructure security testing.

Currently, the framework has support for analyzing and exploiting various IoT, radio and hardware protocols. The current suite includes:
– BLE
– CAN
– DICOM (Will be fully implemented before the conference)
– MQTT
– Modbus
– I2C
– SPI
– UART

Install

  • Make sure you have python3 installed
  • $ Install bluepy dependency => libglib2 $ sudo apt-get install libglib2.0-dev
  • $ Install pyspiflash/pyftdi dependency => libusb1 $ sudo apt-get install libusb-1.0
  • Download the repo $ git clone https://github.com/expliot-framework/expliot.git
  • cd expliot
  • $ sudo python3 setup.py install

Run

  • $ efconsole

Copyright (C) 2018

Anastasis Vasileiadis

PC Technical || Penetration Tester || Ethical Hacker || Cyber Security Expert || Cyber Security Analyst || Information Security Researcher || Malware analyst || Malware Investigator || Reverse Engineering

SC ProDefence SRL - Cyber Security Services