{"id":395,"date":"2009-10-21T10:45:03","date_gmt":"2009-10-21T14:45:03","guid":{"rendered":"http:\/\/www.willhackforsushi.com\/?p=395"},"modified":"2009-10-21T10:45:03","modified_gmt":"2009-10-21T14:45:03","slug":"toorcon-11-killerbee-practical-zigbee-exploitation-framework","status":"publish","type":"post","link":"https:\/\/www.willhackforsushi.com\/?p=395","title":{"rendered":"ToorCon 11: KillerBee &#8211; Practical Zigbee Exploitation Framework"},"content":{"rendered":"<p>On Saturday at <a href=\"http:\/\/sandiego.toorcon.org\/index.php?option=com_content&#038;task=view&#038;id=18&#038;Itemid=9\" target=\"_blank\">ToorCon 11<\/a> I&#8217;m presenting my work in designing a framework and tools to exploit and manipulate ZigBee and IEEE 802.15.4 networks.  KillerBee has been about 9 months in development, written in Python, leveraging the <a href=\"http:\/\/search.digikey.com\/scripts\/DkSearch\/dksus.dll?lang=en&#038;site=US&#038;WT.z_homepage_link=hp_go_button&#038;KeyWords=RZUSB&#038;x=0&#038;y=0\" target=\"_blank\">AVR RZUSB Stick<\/a> as the interface to interact with these low-power networks.<\/p>\n<p>ZigBee is a interesting wireless technology, not due to any particularly innovative design mechanisms (and certainly not from a robust security perspective) but because it interfaces with the kinetic world more than any other wireless protocol I&#8217;ve run into.  It would be unheard of to use WiFi as a mechanism to control gas valves in distribution mains, and you would never see Bluetooth controlling a flood release main, yet ZigBee and IEEE 802.15.4 seem to fit in with these scenarios, often with little in the way of mature security testing.<\/p>\n<p>My hope is that people evaluating ZigBee and IEEE 802.15.4 technology will be able to leverage KillerBee as a platform to test third-party products (and, for vendors, to test their own products) for vulnerabilities.  In my presentation on Saturday, I&#8217;ll detail several examples of how I&#8217;ve been using KillerBee for this purpose, and how you can as well.<\/p>\n<p>After the conference I&#8217;ll post my slides here, so stay tuned.  If you are coming to ToorCon, please be sure to stop by and say &#8220;Hi&#8221;.<\/p>\n<p>-Josh<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On Saturday at ToorCon 11 I&#8217;m presenting my work in designing a framework and tools to exploit and manipulate ZigBee and IEEE 802.15.4 networks. KillerBee has been about 9 months in development, written in Python, leveraging the AVR RZUSB Stick &hellip; <a href=\"https:\/\/www.willhackforsushi.com\/?p=395\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-395","post","type-post","status-publish","format-standard","hentry","category-zigbee"],"_links":{"self":[{"href":"https:\/\/www.willhackforsushi.com\/index.php?rest_route=\/wp\/v2\/posts\/395","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.willhackforsushi.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.willhackforsushi.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.willhackforsushi.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.willhackforsushi.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=395"}],"version-history":[{"count":3,"href":"https:\/\/www.willhackforsushi.com\/index.php?rest_route=\/wp\/v2\/posts\/395\/revisions"}],"predecessor-version":[{"id":398,"href":"https:\/\/www.willhackforsushi.com\/index.php?rest_route=\/wp\/v2\/posts\/395\/revisions\/398"}],"wp:attachment":[{"href":"https:\/\/www.willhackforsushi.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=395"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.willhackforsushi.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=395"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.willhackforsushi.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=395"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}