{"id":35710804,"url":"https://github.com/oussamaelmessaoudi/securing-mqtt","last_synced_at":"2026-01-06T04:08:17.869Z","repository":{"id":326266154,"uuid":"1104813166","full_name":"oussamaelmessaoudi/securing-mqtt","owner":"oussamaelmessaoudi","description":"Security Audit and Hardening of MQTT Protocol using Mosquitto Broker on Ubuntu/WSL. This repository documents vulnerabilities, exploitation, and secure configuration of MQTT with authentication, ACLs, TLS/SSL, and firewall rules.","archived":false,"fork":false,"pushed_at":"2025-11-27T10:29:12.000Z","size":18,"stargazers_count":1,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2025-11-29T15:12:29.848Z","etag":null,"topics":["acl","firewall","iot","mosquitto","mqtt","security","ssl","tls","ubuntu","wsl"],"latest_commit_sha":null,"homepage":"","language":"Shell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/oussamaelmessaoudi.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2025-11-26T18:14:28.000Z","updated_at":"2025-11-27T10:29:16.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/oussamaelmessaoudi/securing-mqtt","commit_stats":null,"previous_names":["oussamaelmessaoudi/securing-mqtt"],"tags_count":null,"template":false,"template_full_name":null,"purl":"pkg:github/oussamaelmessaoudi/securing-mqtt","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/oussamaelmessaoudi%2Fsecuring-mqtt","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/oussamaelmessaoudi%2Fsecuring-mqtt/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/oussamaelmessaoudi%2Fsecuring-mqtt/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/oussamaelmessaoudi%2Fsecuring-mqtt/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/oussamaelmessaoudi","download_url":"https://codeload.github.com/oussamaelmessaoudi/securing-mqtt/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/oussamaelmessaoudi%2Fsecuring-mqtt/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28221564,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2026-01-06T02:00:07.049Z","response_time":56,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["acl","firewall","iot","mosquitto","mqtt","security","ssl","tls","ubuntu","wsl"],"created_at":"2026-01-06T04:08:17.133Z","updated_at":"2026-01-06T04:08:17.863Z","avatar_url":"https://github.com/oussamaelmessaoudi.png","language":"Shell","funding_links":[],"categories":[],"sub_categories":[],"readme":"# 🔐 MQTT Security Audit \u0026 Hardening Project\n\n\u003cdiv align=\"center\"\u003e\n\n![MQTT Security](https://img.shields.io/badge/MQTT-Security%20Audit-red?style=for-the-badge\u0026logo=mqtt)\n![Status](https://img.shields.io/badge/Status-Complete-success?style=for-the-badge)\n![License](https://img.shields.io/badge/License-Academic-blue?style=for-the-badge)\n\n**A comprehensive security assessment and hardening guide for Mosquitto MQTT Broker**\n\n*From vulnerable to fortress: Securing IoT communication one topic at a time*\n\n[📖 Report](#-project-report) • [🎯 Demo](#-live-demonstration) • [🛠️ Setup](#-quick-start) • [🔒 Results](#-security-improvements)\n\n\u003c/div\u003e\n\n---\n\n## 🎯 Project Overview\n\nThis project exposes critical vulnerabilities in default MQTT broker configurations and demonstrates professional-grade hardening techniques to secure IoT communications. Through systematic penetration testing and defense implementation, we transform an insecure message broker into a production-ready secure system.\n\n### 🚨 The Problem\n\n```\n❌ Anonymous access enabled          ✅ Password-based authentication\n❌ Unencrypted communications        ✅ TLS 1.3 encryption\n❌ No access control                 ✅ Topic-based ACL\n❌ Exposed to network attacks        ✅ Firewall-protected\n```\n\n### 🎓 Academic Context\n\n- **Course**: CyberSecurity - Computer Engineering \u0026 Embedded Systems\n- **Institution**: Université Ibn Zohr, Faculté des Sciences d'Agadir\n- **Program**: IISE (Ingénierie Informatique et Systèmes Embarqués)\n- **Professor**: Monsef Boughrous\n- **Academic Year**: 2025/2026\n\n---\n\n## 📋 Table of Contents\n\n- [Project Phases](#-project-phases)\n- [Attack Surface](#-attack-surface-discovered)\n- [Arsenal](#-security-arsenal)\n- [Quick Start](#-quick-start)\n- [Exploitation Demo](#-exploitation--defense)\n- [Results](#-security-improvements)\n- [Documentation](#-documentation)\n- [Team](#-team)\n\n---\n\n## 🔄 Project Phases\n\n### Phase 1️⃣ : Reconnaissance \u0026 Setup\n```bash\n🔍 Network scanning with Nmap\n📡 Service enumeration\n🌐 Traffic baseline analysis\n📊 Default configuration audit\n```\n\n### Phase 2️⃣ : Vulnerability Assessment\n```bash\n🚪 Authentication bypass testing\n🔓 Encryption analysis\n🎯 Access control evaluation\n⚠️ Security misconfiguration identification\n```\n\n### Phase 3️⃣ : Exploitation \u0026 Proof of Concept\n```bash\n💥 Anonymous connection attacks\n🕵️ Credential interception\n📨 Unauthorized message publishing\n🎭 Man-in-the-middle demonstrations\n```\n\n### Phase 4️⃣ : Hardening \u0026 Verification\n```bash\n🔐 Password authentication implementation\n🔒 TLS/SSL certificate deployment\n🛡️ Access Control Lists (ACL) configuration\n🧱 Firewall rule enforcement\n✅ Post-hardening validation\n```\n\n---\n\n## 🎯 Attack Surface Discovered\n\n| Vulnerability | Severity | CVSS Score | Status |\n|--------------|----------|------------|---------|\n| Anonymous Access | 🔴 **CRITICAL** | 9.8 | ✅ Fixed |\n| Plaintext Communication | 🔴 **CRITICAL** | 8.2 | ✅ Fixed |\n| No Topic Authorization | 🟠 **HIGH** | 7.5 | ✅ Fixed |\n| Exposed Management Port | 🟠 **HIGH** | 6.8 | ✅ Fixed |\n| Default Configuration | 🟡 **MEDIUM** | 5.3 | ✅ Fixed |\n\n---\n\n## 🛠️ Security Arsenal\n\n\u003ctable\u003e\n\u003ctr\u003e\n\u003ctd width=\"50%\"\u003e\n\n### Offensive Tools\n```yaml\nReconnaissance:\n  - Nmap 7.94\n  - Wireshark 4.0+\n  \nExploitation:\n  - Mosquitto Clients\n  - MQTT Explorer\n  - Custom Python Scripts\n```\n\n\u003c/td\u003e\n\u003ctd width=\"50%\"\u003e\n\n### Defensive Tools\n```yaml\nHardening:\n  - OpenSSL 3.0\n  - Mosquitto 2.0.x\n  - UFW / Windows Firewall\n  \nConfiguration:\n  - ACL Files\n  - Password Database\n  - TLS Certificates\n```\n\n\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/table\u003e\n\n---\n\n## 🚀 Quick Start\n\n### Prerequisites\n```bash\n# Linux (Ubuntu/Debian)\nsudo apt update\nsudo apt install mosquitto mosquitto-clients wireshark nmap openssl\n\n# Verify installation\nmosquitto -h\n```\n\n### 1. Clone the Repository\n```bash\ngit clone https://github.com/oussamaelmessaoudi/securing-mqtt.git\ncd securing-mqtt\n```\n\n### 2. Initial Setup (Vulnerable State)\n```bash\n# Start with insecure configuration\nsudo cp config/mosquitto.conf.vulnerable /etc/mosquitto/mosquitto.conf\nsudo systemctl restart mosquitto\n\n# Verify vulnerability\nmosquitto_sub -h localhost -t '#' -v  # No authentication required! 🚨\n```\n\n### 3. Run Security Audit\n```bash\n# Network reconnaissance\nsudo nmap -sV -p 1883,8883 localhost\n\n# Traffic capture\nsudo wireshark -i lo -f \"tcp port 1883\"\n\n# Exploit demo\n./scripts/exploit_demo.sh\n```\n\n### 4. Apply Hardening\n```bash\n# Generate certificates\n./scripts/generate_certs.sh\n\n# Create password database\nsudo mosquitto_passwd -c /etc/mosquitto/passwd iotuser\n\n# Apply secure configuration\nsudo cp config/mosquitto.conf.secure /etc/mosquitto/mosquitto.conf\nsudo cp acl/acl.conf /etc/mosquitto/\n\n# Restart and verify\nsudo systemctl restart mosquitto\n./scripts/verify_hardening.sh\n```\n\n---\n\n## 💥 Exploitation \u0026 Defense\n\n### Before Hardening: Easy Access\n```bash\n# Anyone can subscribe to ALL topics\n$ mosquitto_sub -h localhost -t '#' -v\nsensor/temperature 23.5\nsensor/humidity 65\nhome/lights/bedroom ON\ncamera/stream rtsp://192.168.1.100  # 😱 Privacy breach!\n\n# Wireshark shows credentials in plaintext\nMQTT Payload: username:admin password:admin123  # 🚨 Exposed!\n```\n\n### After Hardening: Access Denied\n```bash\n# Connection without credentials fails\n$ mosquitto_sub -h localhost -t '#'\nConnection error: Not authorized\n\n# TLS encryption required\n$ mosquitto_sub -h localhost -p 8883 -t 'sensor/#' \\\n  --cafile certs/ca.crt \\\n  -u iotuser -P SecurePass123!\nsensor/temperature 23.5  # ✅ Encrypted \u0026 Authenticated\n\n# Wireshark shows encrypted traffic\nTLSv1.3 [Application Data]  # 🔒 Cannot be decrypted!\n```\n\n---\n\n## 📊 Security Improvements\n\n\u003cdiv align=\"center\"\u003e\n\n### Vulnerability Remediation\n\n| Metric | Before | After | Improvement |\n|--------|--------|-------|-------------|\n| **Open Ports** | 1883 (unsecured) | 8883 (TLS only) | 🔒 100% encrypted |\n| **Authentication** | ❌ None | ✅ Password + ACL | 🛡️ Full protection |\n| **Encryption** | ❌ Plaintext | ✅ TLS 1.3 | 🔐 Military grade |\n| **Access Control** | ❌ Global access | ✅ Topic-based | 🎯 Granular control |\n| **Attack Surface** | 🔴 Critical | 🟢 Minimal | ⬇️ 95% reduction |\n\n\u003c/div\u003e\n\n### 🎬 Visual Evidence\n\n```\n📸 Screenshots included:\n├── nmap_scan_before.png       # Port 1883 open, no encryption\n├── nmap_scan_after.png        # Only port 8883, TLS enabled\n├── wireshark_plaintext.png    # Captured passwords\n├── wireshark_encrypted.png    # Encrypted traffic\n├── attack_success.png         # Unauthorized access demo\n└── attack_blocked.png         # Hardened system blocks attack\n```\n\n---\n\n## 📚 Documentation\n\n### 📄 Project Report (15-20 pages)\nComprehensive security audit documentation following professional standards:\n- Executive Summary\n- Vulnerability Analysis\n- Exploitation Results\n- Hardening Implementation\n- Before/After Comparison\n- Actionable Recommendations\n\n📥 **[Download Full Report](docs/MQTT_Security_Report.pdf)**\n\n### 🎤 Presentation (10-15 slides)\nProfessional presentation covering:\n- Problem Statement\n- Attack Demonstrations\n- Defense Implementation\n- Live Demo\n- Key Findings\n\n📥 **[View Presentation](presentation/MQTT_Security_Slides.pdf)**\n\n---\n\n## 📁 Repository Structure\n\n```\nsecuring-mqtt/\n├── 📁 config/\n│   ├── mosquitto.conf.vulnerable    # Insecure baseline\n│   ├── mosquitto.conf.secure        # Hardened configuration\n│   └── README.md                    # Configuration guide\n│\n├── 📁 acl/\n│   ├── acl.conf                     # Topic-based access rules\n│   └── examples/                    # ACL patterns\n│\n├── 📁 certs/\n│   ├── ca.crt                       # Certificate Authority\n│   ├── server.crt                   # Server certificate\n│   ├── generate_certs.sh            # Certificate generation script\n│   └── .gitignore                   # (Private keys excluded)\n│\n├── 📁 scripts/\n│   ├── setup_vulnerable.sh          # Deploy vulnerable broker\n│   ├── exploit_demo.sh              # Demonstrate attacks\n│   ├── apply_hardening.sh           # Secure the broker\n│   ├── verify_security.sh           # Post-hardening tests\n│   └── mqtt_test_client.py          # Python testing tool\n│\n├── 📁 scans/\n│   ├── nmap_results/\n│   ├── wireshark_captures/\n│   └── vulnerability_reports/\n│\n├── 📁 docs/\n│   ├── MQTT_Security_Report.pdf     # Full technical report\n│   └── Hardening_Checklist.md       # Step-by-step guide\n│\n├── 📁 presentation/\n│   └── MQTT_Security_Slides.pdf     # Project presentation\n│\n└── README.md                        # You are here! 🎯\n```\n\n---\n\n## 🎓 Key Learnings\n\n### 🧠 Technical Skills Acquired\n- ✅ MQTT protocol analysis and security assessment\n- ✅ TLS/SSL certificate generation and management\n- ✅ Network traffic analysis with Wireshark\n- ✅ Firewall configuration and port security\n- ✅ Access Control List (ACL) design\n- ✅ Penetration testing methodology\n- ✅ Security hardening best practices\n\n### 🔍 Cybersecurity Principles Applied\n- **Defense in Depth**: Multiple security layers\n- **Least Privilege**: Topic-based access control\n- **Encryption at Rest \u0026 Transit**: TLS implementation\n- **Authentication \u0026 Authorization**: Password + ACL\n- **Security by Default**: Hardened configurations\n\n---\n\n## 🛡️ Hardening Checklist\n\n- [x] **Authentication**\n  - [x] Disable anonymous access\n  - [x] Implement password authentication\n  - [x] Use strong password policies\n\n- [x] **Encryption**\n  - [x] Generate TLS certificates\n  - [x] Enable TLS 1.3\n  - [x] Disable insecure protocols (TLS 1.0/1.1)\n\n- [x] **Access Control**\n  - [x] Configure topic-based ACL\n  - [x] Implement read/write separation\n  - [x] Test authorization rules\n\n- [x] **Network Security**\n  - [x] Close unencrypted port (1883)\n  - [x] Configure firewall rules\n  - [x] Restrict broker to localhost/VPN\n\n- [x] **Monitoring \u0026 Logging**\n  - [x] Enable security logging\n  - [x] Monitor failed connection attempts\n  - [x] Set up alerting\n\n---\n\n## 🎯 Demonstration Highlights\n\n### 🔴 Attack Phase\n```bash\n✓ Successful anonymous connection\n✓ Captured credentials via Wireshark\n✓ Unauthorized topic subscription\n✓ Message interception and modification\n✓ Privacy breach demonstration\n```\n\n### 🟢 Defense Phase\n```bash\n✓ Connection attempts blocked\n✓ Encrypted traffic (Wireshark verification)\n✓ ACL preventing unauthorized access\n✓ Firewall blocking external connections\n✓ Security monitoring active\n```\n\n---\n\n## 👥 Team\n\n**IISE Students - Cybersecurity Project**\n\nOussama ELMESSAOUDI\n\nYassine EL ATIKI\n\nAbdessamad ASKLOU\n\nNourreddine AIT MOULAY BRAHIM\n\n*Université Ibn Zohr, Faculté des Sciences d'Agadir*\n\n\u003e 💡 **Note**: This project was conducted in a controlled lab environment. All security testing was performed ethically on systems owned and operated by the project team.\n\n---\n\n## 📜 License \u0026 Ethics\n\nThis project is for **educational purposes only**. \n\n⚠️ **Ethical Guidelines:**\n- All testing performed in isolated lab environment\n- No unauthorized network scanning\n- No attacks on production systems\n- Compliant with academic integrity policies\n\n---\n\n## 🔗 References \u0026 Resources\n\n- [MQTT Protocol Specification](http://mqtt.org)\n- [Mosquitto Documentation](https://mosquitto.org/documentation/)\n- [OWASP IoT Security](https://owasp.org/www-project-internet-of-things/)\n- [NIST Cybersecurity Framework](https://www.nist.gov/cyberframework)\n\n---\n\n## 📞 Contact \u0026 Feedback\n\nFor questions about this project:\n- 📧 Email: [oussama.elmessaoudi.39@edu.uiz.ac.ma]\n- 🎓 Course: CyberSecurity - Prof. Monsef Boughrous\n\n---\n\n\u003cdiv align=\"center\"\u003e\n\n### ⭐ If you found this project helpful, please star the repository!\n\n**Built with 🔒 by IISE Cybersecurity Team**\n\n*Securing the IoT, one broker at a time*\n\n\u003c/div\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Foussamaelmessaoudi%2Fsecuring-mqtt","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Foussamaelmessaoudi%2Fsecuring-mqtt","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Foussamaelmessaoudi%2Fsecuring-mqtt/lists"}