IoT: Not Even Your Bed Is Safe

DerbyCon 8.0 - Evolution

Presented by: Darby Mullen
Date: Sunday October 07, 2018
Time: 11:00 - 11:50
Location: Marriott VII, VIII, IX, X
Track: Track 2

During this talk we will discuss the tips, tools and techniques needed to identify and reverse engineer the command and control protocols required to remotely manipulate an industry leading “smart bed”. Starting with identifying the location of two roque access points, the talk will discuss how to capture wireless frames and dissect them in Wireshark. After determining the protocol, the talk will demonstrate a custom Python tool for controlling multiple beds simultaneously. Additionally, the talk will deep dive into identifying the attack surface of the bed’s administrative interface, as well as describing privacy issues with the software.

Darby Mullen

A self-described developer, infosec nut, & Crossfit addict - Darby Mullen has worked on both the blue and the red sides of infosec, most recently running a team building a secure browsing platform.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats