loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Authors: Davide Bonaventura 1 ; Sergio Esposito 2 and Giampaolo Bella 1

Affiliations: 1 Dipartimento di Matematica e Informatica, Università di Catania, Catania, Italy ; 2 Information Security Group, Royal Holloway, University of London, Egham, U.K.

Keyword(s): IoT, Tp-Link, Smart Homes, Smart Devices, Smart Bulb, Smart Plug, Smart Camera, Penetration Test, Vulnerability Assessment.

Abstract: Despite their apparent simplicity, devices like smart light bulbs and electrical plugs are often perceived as exempt from rigorous security measures. However, this paper challenges this misconception, uncovering how vulnerabilities in these seemingly innocuous devices can expose users to significant risks. This paper extends the findings outlined in previous work, introducing a novel attack scenario. This new attack allows malicious actors to obtain sensitive credentials, including the victim’s Tapo account email and password, as well as the SSID and password of her local network. Furthermore, we demonstrate how these findings can be replicated, either partially or fully, across other smart devices within the same IoT ecosystem, specifically those manufactured by Tp-Link. Our investigation focused on the Tp-Link Tapo range, encompassing smart bulbs (Tapo L530E, Tapo L510E V2, and Tapo L630), a smart plug (Tapo P100), and a smart camera (Tapo C200). Utilizing similar communication pro tocols, or slight variants thereof, we found that the Tapo L530E, Tapo L510E V2, and Tapo L630 are susceptible to complete exploitation of all attack scenarios, including the newly identified one. Conversely, the Tapo P100 and Tapo C200 exhibit vulnerabilities to only a subset of attack scenarios. In conclusion, by highlighting these vulnerabilities and their potential impact, we aim to raise awareness and encourage proactive steps towards mitigating security risks in smart device deployment. (More)

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 18.191.200.223

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Bonaventura, D.; Esposito, S. and Bella, G. (2024). The IoT Breaches Your Household Again. In Proceedings of the 21st International Conference on Security and Cryptography - SECRYPT; ISBN 978-989-758-709-2; ISSN 2184-7711, SciTePress, pages 475-482. DOI: 10.5220/0012767700003767

@conference{secrypt24,
author={Davide Bonaventura. and Sergio Esposito. and Giampaolo Bella.},
title={The IoT Breaches Your Household Again},
booktitle={Proceedings of the 21st International Conference on Security and Cryptography - SECRYPT},
year={2024},
pages={475-482},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0012767700003767},
isbn={978-989-758-709-2},
issn={2184-7711},
}

TY - CONF

JO - Proceedings of the 21st International Conference on Security and Cryptography - SECRYPT
TI - The IoT Breaches Your Household Again
SN - 978-989-758-709-2
IS - 2184-7711
AU - Bonaventura, D.
AU - Esposito, S.
AU - Bella, G.
PY - 2024
SP - 475
EP - 482
DO - 10.5220/0012767700003767
PB - SciTePress