Detecting Hardcoded Login Information from User Input
Minami Yoda, Shuji Sakuraba, Yuichi Sei, Yasuyuki Tahara, Akihiko Ohsuga · 2022
Internet of Things (IoT) for smart homes provides high levels of convenience, but it introduces the risk of private data leakage. There were reports in 2020 of some firmware containing hardcoded login information that allows anyone to access the firmware via the Internet. According to OWASP 2018, the most common IoT vulnerability is “weak, guessable, or hardcoded passwords. “ In this paper, we proposed a method for detecting hardcoded login information (username and password) in IoT devices using static analysis with a focus on the user input value. An attacker enters values when attempting to log into IoT devices. As a result, we believe that tracing user input value is an effective method for detecting hardcoded login information. To the best of our knowledge, our method is the first method focusing on user input. This method is also effective to protect from the first vulnerability from the OWASP's ranking. We tested the method's capability by searching six real-world firmware files that contained hardcoded login information. The results showed that the method found the target information within a smaller candidate list than the previous study, implying that our method is more accurate than other searches.