--- title: "Aaron Guzman — IoTGoat" url: https://appsecpodcast.com/aaron-guzman-iotgoat/ date: 2020-06-23 duration_seconds: 2165 guests: ["Aaron Guzman"] topics: ["Security Testing"] audio: https://www.buzzsprout.com/1730684/episodes/8122601-aaron-guzman-iotgoat.mp3 video: https://www.youtube.com/watch?v=z60KKPRycVs transcript: true --- # Aaron Guzman — IoTGoat *June 23, 2020 · 36 min* with [Aaron Guzman](https://appsecpodcast.com/guests/aaron-guzman/) on [Security Testing](https://appsecpodcast.com/topics/security-testing/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122601-aaron-guzman-iotgoat.mp3) · [Video](https://www.youtube.com/watch?v=z60KKPRycVs) ## Show notes Aaron Guzman specializes in IoT, embedded, and automotive security. Aaron is the Co-Author of “IoT Penetration Testing Cookbook”. He helps lead both OWASP’s Embedded Application Security and Internet of Things projects; providing practical guidance for addressing top security vulnerabilities to the embedded and IoT community. Aaron joins us to explore IoTGoat. IoTGoat is a deliberately insecure firmware created to educate software developers and security professionals with testing commonly found vulnerabilities in IoT devices. He describes what it is, where it comes from, and does a demo for us on how to put it to use. Aaron joins us to explore IoT Goat. IoT Goat is a deliberately insecure firmware created to educate software developers and security professionals with testing commonly found vulnerabilities in IoT devices. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Aaron Guzman specializes in IoT, embedded, and automotive security. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Aaron Guzman: → [IoTGoat](https://github.com/OWASP/IoTGoat) → [OWASP IoT Project](https://www.owasp.org/index.php/OWASP_Internet_of_Things_Project) Mentioned in this episode: → [IoTGoat](https://github.com/OWASP/IoTGoat) → [OWASP IoT Project](https://www.owasp.org/index.php/OWASP_Internet_of_Things_Project) → [OWASP IoT Top 10](https://owasp.org/www-project-internet-of-things/) → [OWASP Juice Shop](https://owasp.org/www-project-juice-shop/) → [OWASP Web Security Testing Guide (WSTG)](https://owasp.org/www-project-web-security-testing-guide/) → [OWASP ISVS](https://github.com/OWASP/IoT-Security-Verification-Standard-ISVS) → [Cloud Security Alliance (CSA)](https://cloudsecurityalliance.org/) → [CSA IoT Working Group](https://cloudsecurityalliance.org/research/working-groups/internet-of-things/) → [ENISA](https://www.enisa.europa.eu/) Chapters: 00:00 Meet Aaron Guzman: Aaron Guzman — IoTGoat 02:09 All right, and our guest today is Aaron Guzman, who is 07:34 Aaron, I understand you are working on the project IoT Goat 10:15 Aaron, when I think about vulnerable apps, I think about like 11:51 Curious, where did it come from 14:48 March of what year 18:33 You mentioned the relationship to OWASP IoT, or at least it 21:55 Now if we kind of switch gears and get more practical 27:04 Just let me summarize to make sure I'm understanding correctly. So 28:40 As far as the future of IoT Goat, where do you 32:12 Yeah, definitely. Most definitely. So if you want to leave our ## Transcript *5,684 words · assemblyai* **0:00 Chris Romeo:** Aaron Guzman specializes in IoT, embedded, and automotive security. Aaron is the co-author of IoT Penetration Testing Cookbook. He helps lead both OWASP's Embedded Application Security and Internet of Things projects, providing practical guidance for addressing top security vulnerabilities to the embedded and IoT community. Aaron joins us to explore IoT Goat. IoT Goat is a deliberately insecure firmware created to educate software developers and security professionals with testing commonly found vulnerabilities in IoT devices. He describes what IoT Goat is, where it comes from, and then does a demo for us on how to put it to use. For season 7 and beyond, we've launched our YouTube channel, Application Security Podcast, where we post the video feeds from all the episodes. You want to check it out, as many interviews now have demos included where we capture screen during the interview. For this conversation with Aaron, he actually did a live demo for us of how to use IoT Goat. We hope you enjoy this conversation with Aaron Guzman. Are you trying to build a security champions program? Everyone is these days. One challenge of rolling out security champions is, how do we educate all these new folks? Security Journey has your answer. We provide a security dojo environment with level-based security education that gives your newfound champions a path to follow. And the best part? It's It requires almost zero administration by you. Visit www.securityjourney.com to set up a demo and learn how you can use the Security Dojo to connect with your security champions. Hey folks, welcome to this episode of the Application Security Podcast. This is Chris Romeo, CEO of Security Journey and co-host of the Application Security Podcast. I'm joined by Robert Hurlbut as well. Hey, Robert. **2:04 Robert Hurlbut:** Hey, Chris. Yeah, it's Robert Hurlbut. Good to be here. Threat modeling architect. **2:08 Chris Romeo:** All right, and our guest today is Aaron Guzman, who is one of the project leads of the OWASP IoT GOAT project. And so we're going to get into all the details about what that is, how it works, what it could do for you. But Aaron, our audience is always on the edge of their seats wanting to hear our guests' security origin story. So if your security career was a comic book, what does episode 1 or release number 1 look like in your history? **2:41 Aaron Guzman:** Yeah, absolutely. So my origin story starts really when just pursuing IT in general, like I went for my A+ certification. I didn't want to go to a 4-year and I didn't have money to do that. Essentially, I had a scholarship, baseball scholarship that dropped, and I was like, I always wanted to do something in computers or electronics. I didn't know, I had no idea what. So I delved straight headfirst into certifications. I knew I needed a base foundation, so I went with A+, Network+. And then throughout those courses, I had class members who— this is back in Backtrack 4— who came back and like, hey, yeah, I just hacked my neighbor's Wi-Fi. And I was like, what, you hacked your neighbor's Wi-Fi? And at the time too, uh, the place I was living, uh, there wasn't any internet. Um, so I was spending time at McDonald's when they had free Wi-Fi at the time, and at libraries. And so he told me how to buy this, uh, this card that you can, uh, inject, uh, packets into access points in order to even, uh, start hacking Wi-Fi. So I kind of went down the rabbit hole Uh, and essentially get that started with Aircrack-ng, got an alpha card, um, and then went, uh, straight for the security path, uh, and that path was Security+. And back when CEH, uh, was okay, uh, at least at a high level, like in 2011, 2012, um, and I got my foot in the door, um, uh, working— at first I was at a voice over IP company That was originally owned by Sandy Kempkar, which is the funny part. And it's a, you know, a Linux shop. But what I did was, in order for me to kind of get that position, I was still working like a level 3 support for that company, but I was attending OWASP Los Angeles meetings around the block at Symantec in Culver City here in Los Angeles. And the director of security, they saw that I was attending, I was being active in the community, going to meetups for not only OWASP but SOC Security Alliance, going to forensics meetups with the High Tech Crimes Investigation Association, just kind of getting involved in the community and trying to contribute in some way. So I got lucky, landed my first position as an application security engineer for that voice over IP company, and the journey started from there. Um, so hacking Wi-Fi and finding out I can do more inside an internal network and get paid for it, I was like, no way, this is like the coolest career I could even think of. Uh, but I had no idea where I'd land up, what type of focus. Uh, I was just like a sponge, uh, taking everything in and realizing the more you know, the more you can prove you know, the more you're worth. Um, and ever since, uh, you know, I've been giving back to the community, doing the best I can to lead projects I was on the board of OWASP Los Angeles for 5 years, Cloud Security Alliance for 5 years. So that's kind of my origin story at a high level. **5:46 Chris Romeo:** So you were somebody that was at some of the OWASP events, and that actually led to you being able to get that, that first kind of AppSec job. And so I think that's some advice for those out there who might be trying to get into security. And I know I say this all the time, but it's good to hear an actual case study of someone who attended OWASP meetups, got some attention, Obviously you did some other things too to better yourself or prepare yourself for a new role, but OWASP paid a part or played a part in getting you into that, that, that first big AppSec opportunity. That's awesome. **6:18 Aaron Guzman:** Yeah, absolutely. Totally give credit to OWASP and all the other groups as well. And Los Angeles is a pretty active community, so everyone kind of cross-pollinates. We even went like ISSA, I would attend those as well. So networking with folks who are from the area and then moved out and maybe saw around conferences It really, you know, paid forward at the end, but it was more of just having the passion, right, and being involved and wanting to learn more, you know, as far as what folks are doing in the industry, some of the talks, and also getting free dinner. So that was cool. **6:52 Chris Romeo:** Almost guaranteed. It's not a guarantee you get a free dinner at OWASP, but almost guaranteed. Every chapter I've ever been to around the world has had free food available. **7:02 Robert Hurlbut:** Mostly pizza. **7:04 Chris Romeo:** It seems like it's pizza everywhere. **7:06 Aaron Guzman:** No, Olaf LA catered dinner. **7:08 Robert Hurlbut:** Oh, nice. **7:09 Aaron Guzman:** And different types, Italian, Greek, the list goes on. But they're probably one of the most successful chapters though, so that's the reason why. And because of conferences like AppSec California, where they get some of the kickback from hosting the conference and co-organizing with the other chapters. So that's part of the reason why they have some of that funding to provide food and sneakers as well. **7:33 Robert Hurlbut:** So Aaron, I understand you are working on the project IoT Goat. Tell us about that and what can you do with IoT Goat? **7:42 Aaron Guzman:** Yeah, so IoT Goat is a deliberately vulnerable piece of firmware, at least for version 1, and we'll get to some of the roadmaps in a bit. But the idea is to provide a platform, an education platform, to help shed the light on some of the top IoT security vulnerabilities that are normal in the field and that developers, security professionals, hobbyists, or anyone who's really interested in learning on how these vulnerabilities are tested and also how to remediate the vulnerabilities, which is something that will be discussed in a bit. But essentially, when we first kicked off the project, back in— it was actually last March. There wasn't anything with similar goals, but in the process, within the year, we just released late March, there have been a couple that have propped up, different, complementing to the same idea of open source and education. But I think we still have our own vision that differs from some of these. I'll say, for example, there's, there's one, it's a good project. It's called DVID, Damn Vulnerable IoT Device, and it's based on 8-bit AVR, which could be very applicable to some people who come across AVR platforms and maybe things with ATmega chips. But let's be real, you know, the majority of IoT devices, at least commercial or medical or consumer are ARM-based, ARM64, ARM32, even x86 for that matter. But like I said, they all complement each other in some way, shape, or form. And as far as the overall, you know, goal that the project, you know, aside from education and also providing someone to have a testbed But also, I think we really want to focus on the mitigation pieces. I think for version 1 right now, when we released it, it's riddled with vulnerabilities from the IoT Top 10 2018. Aside from number 10, which is hardware-based and something that we will release in future versions, but there are several other vulnerabilities that kind of fulfill the top 10. A lot of them directly and some even indirectly. **10:15 Chris Romeo:** Aaron, when I think about vulnerable apps, I think about like Juice Shop, for example. It's kind of like the reference model I have in my head. And with Juice Shop, Juice Shop right now is all about just finding vulnerabilities. They've talked about in the future they're going to have a mitigation portion where you're actually going to fix the things and then confirm that they're fixed. You mentioned, I think once or twice here, about kind of mitigations and things like that. Is there— with IoT GO, I get there's a vulnerability There's a vulnerable version of software that you could test against. Is there something from the mitigation perspective as well to help you learn how to fix pieces? **10:52 Aaron Guzman:** That's something we're working on. I think we want to provide quality write-ups, and I think that's also something that would differentiate us for the project from others. I've come across even commercial vulnerable devices that the lab manuals or the walkthroughs, they skip a lot of steps. They're not explicit on some of the, some of the things you should look for, some of the things that you should keep in mind, considerations. So I think that's something that we want to emphasize on. And it's— we're working on it right now. We do have a section in the wiki where the challenge solutions will be, although it is a work in progress. But hopefully soon, in the coming months, we can have something that will have clear steps, not only in how to exploit, but how to also remediate the vulnerabilities, even if that has to require recompiling firmware, which would be an exercise in itself. **11:50 Robert Hurlbut:** So curious, where did it come from? Where was that idea that got it started? You know, its origin story. Where did IoT Goat come from? **11:59 Aaron Guzman:** Yeah, so it is actually a funny story. Uh, well, I wouldn't say necessarily funny. We have folks who are contributing who are wrapping up a book for No Starch Press on IoT hacking. And, uh, I wrote a book in 2017 on penetration testing, uh, IoT as well for packet publishing. And they asked me, hey, uh, what did you use throughout your book for examples on IoT devices for firmware? We don't want to cross any legal boundaries. We don't want to worry about that. Um, and my response was, well, the vulnerabilities I discussed in the book that I wrote, I discovered those, I reported those, they're fixed. Uh, so I was able to talk about them. Um, and then they weren't really comfortable with that. They didn't want to spend the time, uh, which, you know, they shouldn't have to. Uh, and we kind of did the market research and we saw that There's Damn Vulnerable Router, which is another project that's focused on memory corruption vulnerabilities for MIPS platform. And then there's DVAR, which is focused memory corruption vulnerabilities on ARM platform. So we thought their goals, again, complementing in what they're offering and what they want to Or what they want the audience to learn. Again, we were walking through stacks from different platforms, different gotchas. And, but for us, we wanted to go from the full spectrum of hardware to application layer and things that you commonly see throughout even business logic. So the project leaders, and it was Fotis and And, uh, I can't— this tag is, uh, his Twitter is Calderbone. Calderbone, I think, uh, they, they helped push the idea of, hey, let's get this started. They created a proposal of what type of vulnerabilities they want to include, things like UPnP that you— that we've seen for years, uh, things like command injections, secret pages. Um, so we got to it. Um, we got to it, like I said, starting in March. We applied for Google Summer of Code, and we had a couple of students working on the project. One, one of the students dropped out mid-through, so we had a hard time, kind of had a setback during those 3 months, but it was a learning experience for all of us to put some more time in and put some more effort, and that's what the whole project team is about, people picking up. when things die off, and especially in the summer. Okay, and that was March of— **14:47 Robert Hurlbut:** March of what year? **14:48 Aaron Guzman:** Last year. **14:50 Robert Hurlbut:** So March of 2019. Okay. **14:52 Aaron Guzman:** Yeah, we spoke about it. We met actually at B-Side San Francisco where we discussed the idea, and then we officially kicked it off late March in 2019. **15:03 Robert Hurlbut:** Okay. **15:03 Aaron Guzman:** And how we kicked it off is just we hosted a meeting, we posted the details on on the OWASP IoT Security Channel, and folks who were interested joined. We posted a recording on— and there's around like 400 to 500 people on that group. And then, yeah, I think we had about 7 or 8 people who joined at first, but, you know, open source projects, things go on. That's fine. **15:31 Chris Romeo:** I would argue, or I would consider, you may have the record for the fastest project at OWASP to ever get to a 1.0 style release. I'm trying— I was trying to think, like, is there anything else that I could think of that would— that I could say definitively they started in March and by January they had a 1.0, they had a live kind of release out there? And I couldn't think of anything that had moved that fast. And our audience may correct me, maybe my OWASP lore is not where it needs to be, but that certainly is— it's an achievement to get anything done anywhere that's a technological-style project in the amount of time that you had between March and January. So that's, that's a, that's a big achievement. **16:15 Aaron Guzman:** Yeah, it was a lot of work. We actually made a lot of progress. I thought we were ready to launch in October, honestly, because we also had a vulnerable firmware over-the-air service that worked standalone. We wanted to— we wanted it to be built as far as part of the firmware itself. We wanted the client and the server. or create a microservice, but we had some OpenWrt compatibility issues with one of the libraries we were using, and it was like libssl or openssl, of course, something like that, that wasn't compatible. So we spent a lot of time trying to figure that out, and it turns out we just decided to cut it for this one. And we have 2 other vulnerable firmware configurations that are within OpenWrt, so we're going to keep continuing working on that. I think at a certain point you have to figure out, do we keep waiting on this or do we want to cut the release now and then keep working on how can we mature our approach and how can we work on the documents and process and so forth. So after that standpoint, we wanted to ensure that there's certain configurations that IoT Goat needs in order to exploit things like UPnP and DNSMasq vulnerabilities. And those are both— DNSMasq is— the vulnerabilities that it contains are stack overflows and heap overflows. And there's different parts of DNSMasq, like DHCPv6, for example. One of them is a heap overflow, and you need to have 2 network interfaces virtual network interfaces, or if you're using a Raspberry Pi, or if you want to configure— being that the project is based on OpenWRT, if you have a supported piece of hardware, and it could be even an old Wi-Fi Pineapple, an old TP-Link router, or whatever it may be, you can load it onto that piece of hardware if you want. So we essentially had to write some walkthroughs and some scripts in order to change the network configurations in order to be able to carry out that exercise. **18:32 Robert Hurlbut:** So you mentioned the relationship to OWASP IoT, or at least it was on that channel. What is the relationship between IO-Goat and OWASP IoT officially, I guess? **18:43 Aaron Guzman:** So Daniel Mesler and Craig Smith first started the project, the IoT project, in I think 2014. And in 2018, I was on the IoT Top 10 as a contributor, and Daniel decided to make me a lead on the project. I was kind of taking the lead for some of the things that he didn't have the bandwidth for, so he kind of took a step back from that perspective while I continued working on— we have a number of active projects going on. that I'm also leading in addition to IoT Go. We released the firmware security testing methodology back in October, and now we have a GitBook of that. It's online now, and these are all on the OWASP IoT page. If you go on OWASP.org, you'll see the projects. There's an IoT project, we have a landing page there. Well, and the third project I was going to mention that's forthcoming is the Internet Security verification standard. **19:46 Robert Hurlbut:** Uh-huh. **19:47 Aaron Guzman:** Similar approach to mobile security verification standard or application security verification standard and the web version as well. So we're actively working on that and requirements, and we're hoping to have kind of a full-fledged perspective of IoT from the educational standpoint, from the testing standpoint with the firmware methodology. In addition, I released a companion virtual machine preloaded with testing, embedded testing tools and how to emulate firmware for different platforms, ARM and MIPS. And then also loaded up the, on the desktop, a copy of the methodology. We're trying to make it as easy, lower the barrier as possible. **20:31 Robert Hurlbut:** Yeah, absolutely. I remember being at an AppSec USA conference a few years ago and there were a few talks, but it was still somewhat in its infancy as far as approaches and ideas and, and so on. And so it's good to see this progression, especially so quickly in the last couple years or so. So fantastic. **20:53 Aaron Guzman:** I think all around in the industry there's a lot going on within IoT, and I think that can also be an issue, and what it's becoming is an issue. Everyone's doing their own workflow and not really collaborating, and that's also something that the IoT project is focusing on in addition to the projects that we have internally, working with ENISA, for example, cross-collaborating on their publications, as well as the Cloud Security Alliance, working on the IoT working group. I'm a co-chair there, and I invite folks to peer review some of our work and vice versa as well. So we cross-collaborate, send out on how we can work together. Even with the ISVS, there's plans to incorporate some of the IoT controls framework that the Cloud Security Alliance put out last March, which some of the requirements have originated from there. But anyhow, that's again, that's probably one of the goals of the project from a high level. **21:55 Chris Romeo:** So now if we kind of switch gears and get more practical with IoT Goat, so let's say I'm somebody that's listening and I want to try out IoT Go. So I go to the GitHub site, or I guess it's the GitHub site. What am I downloading? Like, what do I do next? What's my next step? **22:17 Aaron Guzman:** Yeah, great question. So yeah, how do you get started? How does it work? And we have a few methods you can try depending on what your goal is and what you want to practice. And I say that because people, let's say you want to download firmware from the internet, from support site. You go to their download page or their support page and you download that firmware for that particular product or hardware. So for us, we have a Raspberry Pi image that you can download, which is an ARM-based piece of firmware, and we have an x86 version that we've— that we have on our release page, as well as a VMDK and VDI And the VMDK and VDI are probably the easiest and quickest way to get started. What you do is you load it up into VirtualBox, or if you have VMware, the VMDK, and create a custom virtual machine, select a 3.x or 4.x Linux kernel, and And then from there, just start up the virtual machine and you'll be greeted with the— you have to press Enter. Everyone always forgets to press Enter. There's no— it's not password protected. And you'll be greeted with the command line interface. And the virtual machine should grab an IP address via DHCP by default, just to make it easier. Usually, if you would download you say OpenWrt and you want to play with it, it would have a network interface of .1, for example. It's used to being a router. In this case, we're not pigeonholing the project as being a router. We want it to be an embedded device. So there is some confusion there. People are like, oh, the IoT is not a router, it's not a network device. But because we're using OpenWrt, it could be a little bit confusing. But one of the main choices why we wanted to use OpenWrt is to provide that flexibility to use different hardware and practice on different platforms. You know, if you don't want to practice on ARM or x86, you can practice with MIPS, and building from source really isn't that difficult. We provided some walkthroughs as well in order to do so. It just takes a little bit more time, but it also gives you a better idea on how firmware is really built, how you can modify firmware, how you modify configurations and settings and how some of these problems arise within development teams and manufacturers in the market. So one is loading up the virtual machine. That's the x86 version. 2 is if you just want to statically analyze the firmware, you can download the Raspberry Pi, use something like binwalk to extract the firmware file system, And from there analyze the file system contents for vulnerabilities, look at the configurations, check for, you know, any web pages that let's say maybe aren't directly accessible. Things that you would probably do in a normal assessment, statically analyze before you want to dynamically assess a target in this case, so you gather as much information as much reconnaissance about versioning, Google whether there are vulnerabilities for that particular version, if there are any walkthroughs, you know, a traditional standpoint of how you would perform a penetration test. Although one of the things that we do have noted in the Getting Started is referencing things like the former security testing methodology, which has each of those stages laid out as well as walkthroughs on how to perform certain attacks. In addition, for things that are centric towards web, not sure if you know, the Web Security Testing Guide released yesterday after 6 years, I think 4.1. So we defer to the Web Security Testing Guide for other areas for help. If you're doing dynamic testing when you have the device loaded up, So other than statically analyzing, if you want to, other than the VM, you could also install the image on a Raspberry Pi, Raspberry Pi 2 and 3. 4 is not yet supported by OpenWrt, but I know it's coming in future versions. And then the last method is building from source and modifying the target to whatever board that you have maybe laying around. **27:04 Chris Romeo:** So just let me summarize to make sure I'm understanding correctly. So a couple different ways I can interact and use IoT Goat. One way would be to download the VirtualBox or virtual VMware version of the image, run that, set up a virtual machine on my computer, start it, and then effectively that virtual machine is emulating what an IoT device would look like. if it was sitting on the network. Okay. And then the second way is I can download the binaries and I can statically analyze the binaries, extract file system just of the binary file. Just like if I was gonna go to a website of a company and download a new version of IoT software, I could do the same analysis. And then the last one was, well, there was the compile from source, but I don't— most people are probably not gonna get to that level early in the process. But the other one was you can, so you can run it on a Raspberry Pi And then that Raspberry Pi is emulating its— in hardware, it's pretending to be an IoT device so that I'm then attacking the Raspberry Pi as if it was a thermostat or a smart refrigerator or something along the way. Is that a fair summary of kind of how this all comes together? **28:14 Aaron Guzman:** Yep, that's fair. And one thing to note when you're loading up the firmware on a Raspberry Pi, all the network interface changes that I mentioned earlier, they only apply to the VM, to the virtual machine approach, because there's already interfaces set up for Raspberry Pi. So it makes it that much easier to use something like that. **28:39 Robert Hurlbut:** Cool. **28:40 Chris Romeo:** So as far as the future of IoT Goat, where do you see this going for future versions? Kind of what does your roadmap look like? into, you know, 1, 2, 5 years into the future for the IoT Goat? **28:56 Aaron Guzman:** Yeah, so certainly we want to nail down— I mean, we have some hardware candidates that we want to provide. And even, you know, we've talked to silicon vendors to see if they may be interested in sponsoring hardware. We've had some interest, although the majority of them would require us to move to their type of build system. modify the project in a big way where you'd have to use their development tools and something that would just, you know, be more of a pain, wouldn't be as simple to work with or even for contributors. So we have a few candidates that we want to nail down. We want to include— I mentioned some hardware, meaning vulnerabilities that pertain to UART, which is a hardware serial protocol, as well as JTAG for debugging, attaching to processor cores, dumping memory, dumping firmware. **29:52 Chris Romeo:** So you would, you would just leave a JTAG interface— that sometimes happens in production, unfortunately— you would leave that JTAG interface there. So then as someone who's using IoT Goat, I plug into it and I'm getting a view just like I had found a JTAG in a smart refrigerator. **30:11 Aaron Guzman:** Yep, yeah, exactly, yeah. And then exercise on how to dump firmware. And in addition to the hardware, we want to introduce wireless vulnerabilities, things with Bluetooth Low Energy and maybe some Wi-Fi, but we don't want to get too much in the weeds to— in the protocols. We want to focus on the application layer. With hardware, there is still applications that run at the serial level, the data that communicates over cleartext, and even some interfaces like I2C is another serial protocol where there isn't any authentication. So as long as you're able to sniff the bus, you can see the traffic. So things like that we're trying to incorporate in the future. It all heavily depends on the hardware candidates, but I think once we nail down what we want that supports what we want, with the Bluetooth and the hardware interfaces, um, I think we'll be on a pretty good, uh, pretty good way forward, uh, to be able to push the project, uh, in a way that has more of a focus. Because right now it's kind of like we're in the middle ground. We don't want to put too much effort, um, because we need hardware drivers in order to talk to those devices. **31:24 Chris Romeo:** Mm-hmm. **31:25 Aaron Guzman:** Um, we don't want any, uh, any gray areas, I guess, From the bug standpoint. But the idea of providing hardware is providing it cheap, cheap hardware. And even if we can provide it free at some point, if we gather some sponsors who can help out the project for the fabrication piece. The alternative to using hardware that's already already in production, already in use, is finding a chipset that's compatible with OpenWRT and making our own version of hardware, which I think would be fun. But again, it takes time. Everyone has, you know, day jobs. **32:12 Chris Romeo:** Yeah, definitely. Most definitely. So if you want to leave our audience with something like a conclusion or a key takeaway, What would that statement be? What would you want to leave this audience with? **32:26 Aaron Guzman:** That's a good question. I mean, if you're looking to, you know, kind of take your first steps into IoT security testing, I think it's a great testing ground to get started. And I think once we have some good candidates for hardware and we're working on the walkthroughs, which should come in the next couple of months, then I think, you know, we'll set ourselves apart as far as our project's concerned and even try to build a more mature process around the way we build firmware and have a build system, which is different for embedded devices than it is for web, the way it works. But I think at the end of the day, we want to enable and arm anyone who is interested in getting started in IoT security testing with the tools to do so. And IoT Goat is just one tool or platform to accomplish that goal, in addition to, you know, the test— the firmware security testing guide and also the Security Verification Center we're working on. And hopefully some of the vulnerabilities that we incorporate within IoT Goat can be automated, can be tested in an automated fashion with the verification standard later on, which it's kind of already being used indirectly by some commercial vendors. But at the end of the day, we just want to be able, like I said, to arm and educate anyone who's interested in getting started in IoT security. **33:56 Chris Romeo:** I like how you use that there, arm. That's a fun arm, arm and engine. When you're talking hardware, that's a funny connection there. Aaron, thank you for— Frank, thanks for First of all, for all you do in the OWASP community, helping to, you know, I got a chance to go to AppSec California for the first time this past year and had a great experience. Thought it was an awesome conference. Thank you for what you're doing with IoT Goat, and please thank the rest of the team. It's folks like you who are making stuff happen in the world of OWASP that are so crucial to, you know, solving this or working towards this goal that we all have of improving software security. across the entire industry. So thank you very much for everything that you're doing, and also thank you for taking the time and helping us to understand IoT Go today. **34:41 Aaron Guzman:** Thanks, Chris. I definitely want to give credit to a couple of the project contributors, Paraj and Abhinav, who really helped push towards the end of the first release. They are students out in North Carolina, so I think they did a wonderful job. And one thing I want to plug is 2 of the 0-days that they found in OpenWRT while developing challenges. There were cross-site scripting vulnerabilities and CSRF amongst others. So I really want to congratulate them and give them, give them some credit. **35:11 Chris Romeo:** Yeah, that's very cool. So not only are you creating a vulnerable IoT firmware image, but you're actually finding vulnerabilities, the team's finding vulnerabilities in OpenWRT and giving back to the community by way of ensuring that those things get fixed. So that's very, very cool to hear. **35:29 Aaron Guzman:** Thanks again, Chris. I really appreciate it. Thanks for the opportunity. **35:31 Chris Romeo:** Thanks for listening to the Application Security Podcast. You'll find the show on Twitter @AppSecPodcast or on the web at www.securityjourney.com/application-security-podcast. You can also find Chris on Twitter @edgeroute and Robert @RobertGould. **35:50 Robert Hurlbut:** Robert Hurlbut. **35:51 Chris Romeo:** Remember, security is a journey, not a destination. --- Source: https://appsecpodcast.com/aaron-guzman-iotgoat/