Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

The Insecure IoT Cloud Strikes Again: RCE on All Ruijie Cloud-Connected Devices

Black Hat via YouTube

Overview

Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Discover how vulnerability researchers executed a remote code execution attack on Ruijie access points in this 38-minute Black Hat conference talk. Learn about an attack chain that begins simply by sniffing WIFI beacons and escalates to full device control and network infiltration. Follow the researchers' journey as they extract Ruijie's firmware, analyze cloud-communication binaries, and uncover critical vulnerabilities—including one that allowed generating MQTT passwords for all Ruijie devices. See how they impersonated Ruijie cloud services to exploit an "execute-command-as-a-service" feature, gaining complete control over tens of thousands of devices. Gain insights into research techniques and common IoT cloud security pitfalls that can lead to fleet-wide device exploitation.

Syllabus

The Insecure IoT Cloud Strikes Again: RCE on all Ruijie Cloud-Connected Devices

Taught by

Black Hat

Reviews

Start your review of The Insecure IoT Cloud Strikes Again: RCE on All Ruijie Cloud-Connected Devices

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.