Hybrid Security Consult
696 posts

Hybrid Security Consult
@HSC_Consult
Affordable Cybersecurity Training & Services | Pentesting • OSINT • Forensics • Audits | 🌍 Building Africa’s Cyber Defenders
127.0.0.1 Katılım Mart 2025
24 Takip Edilen3K Takipçiler
Sabitlenmiş Tweet

During the HSC Cybersecurity Internship, students ran a simulated MQTT IoT security lab showing how devices without authentication or TLS can be quickly compromised.
Hands-on training like this builds real-world security skills.
📢 New HSC internship cohort starts April
#Cyber




English
Hybrid Security Consult retweetledi

Today I led a simulated MQTT exploitation lab for my students to show the structural failures in typical IoT devices.
The lab involved a demo smart device connected to a public broker with zero authentication and no TLS encryption. The logs confirm a total system compromise within minutes.
The technical breakdown:
Information Leakage: Because the device used a predictable topic scheme, a basic wildcard subscription granted access to everything. We extracted the owner email, the local WiFi SSID, and the firmware version without effort.
Identity Hijacking: We moved from observation to takeover. By publishing a poisoned retained message to the status topic, we replaced the legitimate owner info with an attacker email. This change persists on the broker, misdirecting any future clients that connect.
Unauthenticated Control: The device obeyed every command without question. A single JSON payload was enough to remotely trigger the "unlock_door" command. Without cryptographic signatures or anti-replay timestamps, the virtual door state flipped from LOCKED to OPEN instantly.
Security is not a feature for the roadmap. It is the foundation of the product. Shipping unhardened hardware is building a brand on a liability. Next Class we will be looking at a more secure IoT device.
You will be shocked the IoT devices in your home that can be easily hacked like this.
#CyberSecurity #IoT #InfoSec #HardwareHacking #TechEducation #MQTT




English
Hybrid Security Consult retweetledi
Hybrid Security Consult retweetledi

It's been an amazing journey for me with @TechSphereAcad and @HSC_Consult. Solid foundation's been laid to carry what's ahead, and I look forward to keeping my hands on the keyboard to perform magic.
H4RUK7 KIRA 🇯🇵🇨🇵@h4ruk7
Quote this post now and state how your Cybersecurity journey is going and what you need to get or know to keep pushing 😜 in your journey
English


We will be launching a Linux content bundle with @hack_ademy soon a video content based interaction with real world exploration of Linux
English

@MuradCyberPent IT IS OPEN FOR REGISTRATION SEND A DM
English
Hybrid Security Consult retweetledi

Had an amazing networking session today in Kali Linux! Successfully changed my IP, MAC address, and even nameserver. It was so much fun with my colleague @thewilddreams_ and our tutor @h4ruk7 @HSC_Consult
#Networking #Cybersecurity
English

Congratulations 👏🎉🎉🎉
fahad azam@fahadaz60851621
Thrilled to share that I've got selected for an internship in Digital Forensics! Excited to dive into the world of Digital Forensics. Grateful for this opportunity to grow and contribute! @AishaBelloB @HSC_Consult @h4ruk7 @ireteeh @elormkdaniel #DigitalForensics #Internship
English










