Game of Hide-and-Seek: Exposing Hidden Interfaces in Embedded Web Applications of IoT Devices
Wei Xie, Jiongyi Chen, Zhenhua Wang, Chao Feng, Enze Wang, Yifei Gao, Baosheng Wang, Kai Lu
Abstract
Recent years have seen increased attacks targeting embedded web applications of IoT devices. An important target of such attacks is the hidden interface of embedded web applications, which employs no protection but exposes security-critical actions and sensitive information to illegitimate users. With the severity and the pervasiveness of this issue, it is crucial to identify the vulnerable hidden interfaces, shed light on best practices and raise public awareness. In this paper, we present, a new approach that automatically exposes hidden web interfaces of IoT devices. Specifically, constructs probing requests through firmware analysis to test physical devices, and narrows down the scope of identification by filtering out irrelevant requests and interfaces through differential analysis. It pinpoints hidden interfaces by attaching various device-setting parameters in the probing requests and matching keywords of sensitive information. Evaluated on 17 IoT devices, successfully identified 44 vulnerabilities, including 43 previously unknown ones. also demonstrates surprising efficiency: on average, it delivered 151438 probing requests, taking only 47 minutes on each target device.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 79f82397-466f-4a8d-b371-86fcc35854b5Cited by top-tier papers5
- Leveraging Semantic Relations in Code and Data to Enhance Taint Analysis of Embedded SystemsJiaxu Zhao, Yuekang Li, Yanyan Zou, Zhaohui Liang et al.USENIX Security 2024 · 16 citations
- FirmCross: Detecting Taint-style Vulnerabilities in Modern C-Lua Hybrid Web Services of Linux-based FirmwareRunhao Liu, Jiarun Dai, Haoyu Xiao, Yuan Zhang et al.NDSS 2026 · 1 citation
- Faster and Better: Detecting Vulnerabilities in Linux-based IoT Firmware with Optimized Reaching Definition AnalysisZicong Gao, Chao Zhang, Hangtian Liu, Wenhou Sun et al.NDSS 2024
- PANGOLIN: Fuzzing Multilingual IoT Firmware with LLM-Driven Code AnalysisZhipeng Jia, Xiaokang Yin, Shuitao Gan, Chao Zhang et al.USENIX Security 2026
- EAGLEYE: Exposing Hidden Web Interfaces in IoT Devices via Routing AnalysisHangtian Liu, Lei Zheng, Shuitao Gan, Chao Zhang et al.NDSS 2025
Related papers
- FalconScope: Effective and Efficient Detection of Hidden Web Interfaces in IoT DevicesJiaming Guo, Haoran Yang, Kuihao Yan, Jiekang Hu et al.WWW 2026
- IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based FuzzingJiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo et al.NDSS 2018 · 311 citations
- InnerChecker: Discovering Vulnerabilities in Underexplored Internal Services of IoT FirmwareYeqi Mou, Runhao Liu, Bo Yu, Jiarun Dai et al.CCS 2026
- Scalable analysis of interaction threats in IoT systemsMohannad Alhanahnah, Clay Stevens, Hamid BagheriISSTA 2020 · 63 citations
- SoK: Security Evaluation of Home-Based IoT DeploymentsOmar Alrawi, Chaz Lever, Manos Antonakakis, Fabian MonroseS&P 2019 · 411 citations
