Ready to Start Your Career?

By: chiheb chebbi
August 25, 2016
"HEATHEN" IoT Pentesting Framework is Released

By: chiheb chebbi
August 25, 2016


- Now, you can scan all your web interfaces to ensure that any web interface in the product has been tested for XSS, SQLi and CSRF vulnerabilities
- Ensure all devices do not make network ports and/or services available to the internet via UPnP, for example

- Ensure all communication between system components is encrypted as well as encrypting traffic between the system or device and the internet
- Use recommended and accepted encryption practices and avoid proprietary protocols
- Ensure SSL/TLS implementations are up to date and properly configured

- Ensure all system devices have update capability and can be updated quickly when vulnerabilities are discovered
- Ensure update files are encrypted and that the files are also transmitted using encryption
- Ensure that update files are signed and then validated by the device before installing
- Ensure update servers are secure
- Ensure the product has the ability to implement scheduled updates


