Abusing the Internet of Things

(Rick Simeone) #1

FIGURE 1-14. User is asked to authorize iOS app


Once the user selects Yes, the browser sends the following GET request to http://www.meet
hue.com:


GET /en-US/api/getaccesstokenpost HTTP/1.1
Host: http://www.meethue.com
Referer: https://www.meethue.com/en-US/api/getaccesstokengivepermission
Proxy-Connection: keep-alive
Accept-Encoding: gzip, deflate
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Cookie: [DELETED]
Accept-Language: en-us
Connection: keep-alive
User-Agent: Mozilla/5.0 (iPhone; CPU iPhone OS 6_1_4 like Mac OS X)
AppleWebKit/536.26 (KHTML, like Gecko) Version/6.0 Mobile/10B350 Safari/8536.25

CONTROLLING LIGHTS USING THE IOS APP 23
Free download pdf