Sign inSign up

ek2000/coap-server

By ek2000

•Updated 10 months ago

IoT CoAP Vulnerable Test Server

Image
Networking
Security
0

961

ek2000/coap-server repository overview

⁠IoT CoAP Vulnerable Test Server

Docker Pulls Image Size Version Status Lab Only

A lightweight and intentionally vulnerable CoAP server designed for IoT security research, protocol analysis, vulnerability scanning, and cybersecurity education.

This image is widely used in:

  • IoT security courses & labs
  • University-level testbed environments
  • MQTT/CoAP vulnerability scanners
  • Exploit development exercises
  • Proof-of-concept demos

⁠🔧 Features

  • Vulnerable CoAP service built with aiocoap
  • Exposed .well-known/core endpoint (information disclosure)
  • Unauthenticated /sensor endpoint returning fake sensor data
  • Extremely lightweight (≈48 MB)
  • Works on Windows, macOS, Linux (via Docker)
  • Ideal for IoT scanners, testbeds, and exploit tools

⁠🚀 Run the Server

docker run -d -p 5683:5683/udp ek2000/coap-server:latest

The server listens on:

  • UDP 5683 (default CoAP port)

⁠📡 Endpoint Testing

⁠1. Resource Discovery

coap-client -m get coap://localhost:5683/.well-known/core

⁠2. Fake Sensor Data

coap-client -m get coap://localhost:5683/sensor

Expected Output: temperature=25;humidity=60


⁠📦 Docker Compose Example

services: coap_server: image: ek2000/coap-server:latest container_name: coap_server ports:

  • "5683:5683/udp"

⁠🎯 Intended Use Cases

  • IoT security education and cybersecurity labs
  • MQTT/CoAP vulnerability scanner development
  • Penetration testing research
  • Protocol analysis and fuzzing
  • Exploit PoC creation
  • Training environments and demos

⁠⚠️ Security Warning

This container is intentionally vulnerable.

Do NOT use it in:

  • Production systems
  • Public-facing environments
  • Any network requiring security

Use only in isolated lab, offline, or controlled research environments.


This image is typically used within a 3-layer IoT security testbed:

  1. Infrastructure Layer
    Vulnerable MQTT & CoAP services (including this container)

  2. Protocol Analysis Layer
    IoT scanner that checks MQTT/CoAP misconfigurations

  3. IoT Device Layer
    Vulnerable simulated IoT devices (door lock, thermostat, etc.)


⁠👨‍💻 Maintainer

Maintainer: Emre K.
Docker Hub: https://hub.docker.com/r/ek2000/coap-server⁠
GitHub: https://github.com/tahsinsoyak/iotsecurityproject⁠

For academic use, lab integration, or issue reporting, feel free to reach out.


⁠❤️ Acknowledgements

This project supports IoT security education by providing safe, reproducible, hands-on environments for real-world protocol testing and scanning research.

Tag summary

Content type

Image

Digest

sha256:d6539d9b7…

Size

48.1 MB

Last updated

10 months ago

docker pull ek2000/coap-server