Penetration Testing of Mobile IoT Apps and Smart Security Cameras

Penetration Testing of Mobile IoT Apps and Smart Security Cameras

Industry
Software products
Technologies
IoT

Summary

A US-based IoT provider wanted to confirm that its products — two types of smart security cameras and the iOS and Android apps that remotely control them — had no security vulnerabilities, and specifically that all data traffic to the AWS cloud was routed exclusively through US servers, excluding any risk of cross-border data leaks. INNERLUXES ran black-box and gray-box penetration testing in just five working days, confirming the US-only data routing and surfacing only minor vulnerabilities with remediation guidance.

About the Client

The Client is a US-based IoT provider whose market offering includes a proprietary IoT development platform and a wide range of IoT smart devices, serving major electronics and industrial brands among its key clients.

The Challenge

The Client wanted to make sure that its products — two types of security cameras, as well as iOS and Android apps enabling the remote control of IoT devices — had no security vulnerabilities. They specifically wanted to confirm that when both the apps and the cameras connect to the AWS cloud, all data traffic is communicated via US servers only, thereby excluding the risk of data leaks to other countries.

The Solution

The Client turned to INNERLUXES to run penetration testing using black-box and gray-box offender models. INNERLUXES assembled a team of a project manager, two penetration testing engineers, and a senior security testing engineer. The team performed comprehensive penetration testing in accordance with the best practices and recommendations from the OWASP Mobile Testing Guide, NIST 800-86, and NIST 800-115.

While the tests confirmed that the IoT apps and security cameras communicated with the AWS cloud solely via US servers, they also uncovered some minor vulnerabilities in the Client's software and smart devices. The threat classification INNERLUXES's engineers used in the final test protocol was based on the Common Vulnerability Scoring System (CVSS) and OWASP Mobile Top 10.

The team completed penetration testing in just five working days.

The Results

  • INNERLUXES delivered a final report with the revealed minor vulnerabilities and recommendations on how to handle them.
  • As the overall security level of the apps and devices was estimated as quite high, the Client could confidently continue to provide its services.

Technologies and Tools

Wireshark, Nessus, tcpdump, Burp Suite, Nmap, Mobile Security Framework (MobSF), custom scripts (based on Python, C, and Perl) to exploit vulnerabilities.