43. IoT and OT Security – Cameras, Smart Devices, Plant Networks
43.6 Internet Exposure Awareness – Your Lab Only
Search engines and scanners exist that map banners on the public internet (Shodan-class services). Exam / Blue use: check whether YOUR company / YOUR lab EIP accidentally published a camera or MQTT. Banned: mass-querying strangers, building target lists, "for fun" screenshots of random hospitals.
Safe habit:
- Know your own public IPs (AWS Elastic IP, home WAN – with permission)
- From outside (phone mobile data), try to reach your own management ports – expect fail
- If something answers that should not – close it, rotate creds, review UPnP/NAT
- Never paste other people's device IPs into class WhatsApp
| Red team (attacker) does | Blue team (defender) detects / stops |
|---|---|
| Uses public search to find open 554/1883/502 | Asset inventory + periodic own-IP exposure check |
| Screenshots random cams for clout | Illegal / unethical; Blue reports exposure to owner only |
| Assumes "obscure port = safe" | Assume scan; require auth + VPN even on odd ports |
Ravindra Bagale's Tip
Students Shodan free account kadhun neighbour scan kartat. He out of scope. Interview: "I use exposure search against assets I am authorized to review." Aata pudhe jaauya.
Lab
Write a 5-step "own EIP check" runbook for Sahyadri's AWS lab (ports 22, 80, 1883, 502, 554). Mark each expected closed on WAN. Do not query third-party ranges.