Evaluating IoT device security through penetration testing with Flipper Zero : methods, exploits, and countermeasures
Αξιολόγηση ασφάλειας συσκευών IoT μέσω δοκιμών διείσδυσης με το Flipper Zero : μέθοδοι, επιθέσεις και αντίμετρα

Master Thesis
Author
Karanikas, Georgios
Καρανίκας, Γεώργιος
Date
2026-07Advisor
Xenakis, ChristosΞενάκης, Χρήστος
View/ Open
Keywords
IoT security ; Penetration testing ; Flipper Zero ; Perception layer ; Wireless protocols ; Ασφάλεια IoT ; Δοκιμές διείσδυσης ; Επίπεδο αντίληψης ; Ασύρματα πρωτόκολλαAbstract
The proliferation of Internet of Things (IoT) devices has expanded the attack
surface of everyday environments, concentrating much of the risk at the perception layer
— the sensors, actuators, and short-range radios that connect the digital and physical
worlds. Traditionally, assessing the security of these diverse wireless protocols required
an array of specialized, expensive instruments, each dedicated to a single technology.
This thesis tests a different proposition: that a single, commercially available, sub-$200
multi-tool — the Flipper Zero — can now perform this cross-protocol assessment, and
that this accessibility represents a meaningful shift in the threat model itself.
The research follows a structured, four-phase penetration testing methodology
(reconnaissance, enumeration, exploitation, and post-attack analysis) applied within a
controlled, permission-based laboratory environment. Ten empirical case studies were
conducted against representative perception-layer devices, spanning fixed- and rolling-
code Sub-GHz systems, RFID and NFC access credentials, Wi-Fi networks, infrared
appliances, Bluetooth Low Energy devices, and a workstation targeted through USB HID
injection. Where certain advanced attacks could not be safely or legally reproduced, they
were examined through open-source intelligence (OSINT).
The results demonstrate that the majority of successful compromises did not
require breaking cryptography; they exploited its absence, its misconfiguration, or the
implicit trust systems place in unauthenticated input. Fixed-code systems, default
credentials, and weak passphrases fell readily, while correctly implemented defenses —
protected management frames, a properly configured rolling code — resisted the same
attacks. The experimental findings were synthesized into a set of countermeasures
organized by root cause rather than by technology.
The principal contribution of this work is empirical evidence for a reframed threat
model: cross-protocol, cyber-physical attacks once confined to well-funded specialists are
now accessible to a broad population using inexpensive, portable hardware. The central
conclusion is that the insecurity of the perception layer is, for the most part, not an
absence of solutions but a backlog of unapplied ones.


