Skip to content

IoT Companion Application Man-in-the-Middle Scripts described in our paper: "Through the Spyglass: Towards IoT Companion App Man-in-the-Middle Attacks"

Notifications You must be signed in to change notification settings

tj-oconnor/Spyglass

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

6 Commits
 
 
 
 
 
 

Repository files navigation

"SpyGlass" Mitmproxy scripts

This repository contains the scripts used in our paper, "Through the Spyglass: Towards IoT Companion App Man-in-the-Middle Attacks" [bib] [pdf]

Installation

These scripts rely on mitmrpoxy. See https://docs.mitmproxy.org/stable/overview-installation/ for installing mitmproxy.

Usage

Start a script with the (-s) option for either mitmproxy or mitmweb

mitmweb -s <script.py>

Example impacts of lack of SSL-Pinning

hiding users on the devices:

clearing logs on the devices:

revealing sensitive information:

manipulating integrity of images:

controlling state of devices:

About

IoT Companion Application Man-in-the-Middle Scripts described in our paper: "Through the Spyglass: Towards IoT Companion App Man-in-the-Middle Attacks"

Topics

Resources

Stars

Watchers

Forks

Languages