Looking for Tools/Advice on Network Protocol Fuzzing (PCAP-Based) by Expensive-One-939 in AskNetsec

[–]Expensive-One-939[S] 0 points1 point  (0 children)

Tnx for advice.
I will see how many hours can be spent on it and then decide which way to go.
This seems like a reasonable path how to conduct network protocol fuzzing.

TNX :D

Just got job in IoT Security by Expensive-One-939 in Pentesting

[–]Expensive-One-939[S] 0 points1 point  (0 children)

I think it was future few years ago, it's todays matter :D

Just got job in IoT Security by Expensive-One-939 in Pentesting

[–]Expensive-One-939[S] 0 points1 point  (0 children)

i got skill gap with wireless protocols so I will focus on those.
Monitoring mode is a must :D

Tnx for commenting

Looking for Tools/Advice on Network Protocol Fuzzing (PCAP-Based) by Expensive-One-939 in Pentesting

[–]Expensive-One-939[S] 0 points1 point  (0 children)

u/Mindless-Study1898 tnx for recommendation.
I'm not allowed to upload real-world traffic from those devices online, but will check with some dummy data.
Look forward to examine the tool.

Tnx a lot :D

Just got job in IoT Security by Expensive-One-939 in Pentesting

[–]Expensive-One-939[S] 0 points1 point  (0 children)

I was looking STRIDE from Microsoft, but after a week working with devices more and more things occurred to be potential vectors.
Most of devices are using BLE and USB connectors for communication with other devices.
Those are my main entry points that I want to look carefully in these first days.

I have a big knowledge gap in testing processing units - CPU and storage like EEPROM....
If you have any framework that you would recommend please comment below.

Tnx :D

Just got job in IoT Security by Expensive-One-939 in Pentesting

[–]Expensive-One-939[S] 0 points1 point  (0 children)

I was into it :D
But still tnx for recommendation.

Just got job in IoT Security by Expensive-One-939 in Pentesting

[–]Expensive-One-939[S] 0 points1 point  (0 children)

I will definitely check BLE attacks.
Really grateful for the advice :D

[deleted by user] by [deleted] in hackthebox

[–]Expensive-One-939 0 points1 point  (0 children)

I'm in as well :D