Abusing the Internet of Things

(Rick Simeone) #1

FIGURE 4-5. SmartThings App interface for viewing and adding locations


To get the list of locations associated with the user, the app sends the following request:

GET /api/locations HTTP/1.1
Host: graph.api.smartthings.com
Accept: application/json
Authorization: Bearer [DELETED]
Proxy-Connection: keep-alive
X-ST-Client-DeviceModel: iPhone
X-ST-Api-Version: 2.1
Accept-Encoding: gzip, deflate

SMARTTHINGS 91
Free download pdf