Skip to Content
物联网设备安全
book

物联网设备安全

by Nitesh Dhanjani
March 2017
Intermediate to advanced
262 pages
5h 26m
Chinese
China Machine Press
Content preview from 物联网设备安全
熄灯
——
攻击无线灯泡致使持续性停电
19
Vary: Accept-Encoding
Date: Sun, 05 May 2013 23:04:19 GMT
Server: Google Frontend
Content-Length: 41
{"code":200,"message":"ok","result":"ok"}
message
result
对应的代码都是
ok
这意味着命令执行成功,灯泡都关闭了。
1.2.1
信息泄露
将照明系统网站与网桥关联起来的
Web
服务器(网桥也有一个
Web
服务器在
TCP
80
端口监听信息)在对请求做出响应时,包含如下头信息:
Access-Control-Allow-Origin: *
基于浏览器的跨域策略(
cross-origin policy
),该信息头允许因特网上任何网站的
JavaScript
代码都可以获取运行照明系统网站的服务器及网桥的信息。这也导致了外部
的实体有能力获取安装了照明系统的网段内的用户信息,同样也可以获取网桥的
id
MAC
地址和内部
IP
地址。
为了描述这种情况,我们来看看如下
HTML
代码:
<HTML>
<SCRIPT>
// Create the XHR object.
function find_hue()
{
varurl = 'https://www.meethue.com/api/nupnp';
varxhr = new XMLHttpRequest(); ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

数据科学之编程技术:使用R进行数据清理、分析与可视化

数据科学之编程技术:使用R进行数据清理、分析与可视化

迈克尔 弗里曼, 乔尔 罗斯
手把手教会你linux

手把手教会你linux

桑德.范.乌格特
C语言核心技术(原书第2版)

C语言核心技术(原书第2版)

Peter Prinz, Tony Crawford
机器学习设计模式

机器学习设计模式

Valliappa Lakshmanan, Sara Robinson, Michael Munn

Publisher Resources

ISBN: 9787111558668