WS7 - Attacking Cloud APIs from the IoT Edge
Description
Instructed by: Rodney “BenevolentWorm” Beede
Level of Difficulty: Intermediate, Advanced, Expert
Abstract:
This four-hour, hands-on workshop teaches intermediate-to-expert practitioners how to pivot from a single compromised IoT device into the cloud tenant it reports to. Rather than covering initial device access, we assume an existing foothold (via UART, JTAG, or firmware extraction) and focus on what happens next: recovering credentials from device storage, abusing cloud REST and MQTT interfaces, and demonstrating controlled lateral movement within an isolated lab environment.
Students work through a self-contained lab stack (Docker Compose on a pre-built Ubuntu guest VM) that simulates a realistic IoT product: a mock cloud REST API, an MQTT broker, a simulated device with an assumed-RCE foothold, and a fleet of tenant devices publishing live telemetry. The attack chain mirrors how a real engagement unfolds across six progressive labs:
1. Firmware recon — Probe a firmware image for credentials and cloud endpoints.
2. Traffic interception — Intercept and analyze device-to-cloud REST traffic using Burp Suite CE.
3. Identity extraction — Recover device credentials from on-device storage, including both secure enclave and RTOS flash partitions.
4. REST API abuse — Exploit authorization flaws to enumerate and harvest credentials across the device fleet.
5. MQTT fuzzing — Use stolen credentials to explore the broker's topic namespace and surface cross-tenant data.
6. Lateral movement — Leverage harvested access to send commands to a target device in a separate tenant.
A 25–30 minute concept briefing precedes the labs, covering IoT architecture layers, HTTP vs. MQTT (and what that means for Burp Suite CE), CoAP/DTLS, device authentication models (mTLS, pre-shared keys, SigV4, OAuth), the cloud shared-responsibility model, and the OWASP API Security Top 10 vulnerabilities most commonly found in IoT-to-cloud deployments. Defensive counterpoints are addressed so attendees leave able to advise as well as attack.
Students work in groups of 2–3 and are expected to execute every exploit themselves. Minimal slide time is used; the majority of the four hours is spent at the keyboard. Each lab produces a capture-the-flag style flag, giving immediate feedback on successful exploitation. All activity is confined to the isolated lab tenant — no internet access is required or used.
This workshop builds on the instructor's DEF CON 33 session ("Pen-testing Cloud REST APIs") and adds the IoT device foothold as the starting point, covering firmware extraction, Zephyr NVS credential recovery, MQTT ACL abuse, and device-to-device lateral movement — content not present in the prior year.
Takeaway: attendees leave with a repeatable, tool-backed methodology compromised edge device to cloud tenant, and a clear understanding of the customer-owned misconfigurations (over-broad ACLs, BOLA, shared/long-lived credentials, verify=False TLS) that make the chain possible.
Pre-Requisites:
· Comfortable with Linux CLI
· Basic Python scripting
· Familiar with HTTP, MQTT, and cloud REST API fundamentals
· Able to run an x86_64 guest VM and attach USB pass-through
Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity


