时间:2025-11-07 03:29:29 来源:网络整理编辑:百科
It sounds like a sci-fi movie. Over 5,000 connected devices, including light bulbs and vending machi
It sounds like a sci-fi movie. Over 5,000 connected devices, including light bulbs and vending machines, were hacked to slow internet service at a university to a crawl.
Poorly secured internet of things (IoT) devices have become gold mines for hackers looking to launch DDoS attacks to take websites and services offline. But this latest case, detailed in Verizon's Data Breach Digest 2017, is the rare example of gadgets attacking their own network.
SEE ALSO:Your smart fridge is about to make our IoT security nightmare so much worseThe devices were making hundreds of Domain Name Service (DNS) lookups every 15 minutes, causing the university's network connectivity to become unbearably slow or even inaccessible.
Weirdly enough, the majority of the searches "showed an abnormal number of sub-domains related to seafood," the report said.
Here's an abstract from the Digest'ssneak peek:
The firewall analysis identified over 5,000 discrete systems making hundreds of DNS lookups every 15 minutes. Of these, nearly all systems were found to be living on the segment of the network dedicated to our IoT infrastructure.
With a massive campus to monitor and manage, everything from light bulbs to vending machines had been connected to the network for ease of management and improved efficiencies.
While these IoT systems were supposed to be isolated from the rest of the network, it was clear that they were all configured to use DNS servers in a different subnet.
It's very unlikely, to use an understatement, that thousands of students at the university had a sudden and simultaneous urge to eat seafood.
Instead, what did happen was that cheeky hackers instructed the IoT devices to make DNS lookups related to seafood every 15 minutes.
Here's what Verizon's RISK (Research, Investigations, Solutions and Knowledge) team told the university after they were summoned to investigate the attack:
The RISK Team had provided me with a report detailing known indicators found in the firewall and DNS logs that I had sent over earlier. Of the thousands of domains requested, only 15 distinct IP addresses were returned. Four of these IP addresses and close to 100 of the domains appeared in recent indicator lists for an emergent IoT botnet.
So here's the case of vending machines and lamp posts compulsively searching for seafood and overwhelming the network with requests with the aim of taking it down.
If this isn't creepy/dystopian/fascinating, we don't know what is.
Luckily for the guys at the university, there was no need to replace "every soda machine and lamp post".
The Verizon's RISK team explained that the botnet "spread from device to device by brute forcing default and weak passwords".
To solve the massive hack, the university intercepted a clear-text malware password for a compromised IoT device and then used "that information to perform a password change before the next malware update".
Easy, right?
Overall, it doesn't look like this problem is going away anytime soon. There are more than 6 billion IoT devices currently running, according to Gartner Research. That number could reach more than 20 billion by 2020.
TopicsCybersecurity
Nate Parker is finally thinking about the woman who accused him of rape2025-11-07 03:29
30日賠率:曼聯客場難贏熱刺 拜仁大勝回歸正軌2025-11-07 03:23
沒對比沒傷害 !尤文鋒線集體啞火 C羅卻獨造兩球2025-11-07 03:09
30日賠率 :曼聯客場難贏熱刺 拜仁大勝回歸正軌2025-11-07 03:04
Man stumbles upon his phone background in real life2025-11-07 02:41
國足前4場控球率41%比肩阿曼 把握機會能力定勝負2025-11-07 02:04
國足確定11月3日連戰深圳浙江兩隊 或分兩套陣容熱身2025-11-07 01:22
國米前瞻 :藍黑軍衝擊連勝 哲科盼5連斬“烏雞”2025-11-07 01:14
You will love/hate Cards Against Humanity's new fortune cookies2025-11-07 01:12
防線如紙糊 !利物浦13場丟13球 範迪克跌落神壇 ?2025-11-07 01:04
U.S. pole vaulter skids to a halt for national anthem2025-11-07 03:28
曼城罪人!拉波爾特開場送禮致丟球 抱摔認領紅牌2025-11-07 03:10
泰山戰河南費萊尼全力恢複盼複出 對手陣容提升值得重視2025-11-07 03:05
西甲前瞻:瓦倫西亞大區德比上演 巴薩力爭勝利重振士氣2025-11-07 02:40
Carlos Beltran made a very interesting hair choice2025-11-07 02:25
阿曼公布對陣國足25人名單 兩主力缺陣新召一人2025-11-07 02:09
深足全場強攻無力逆轉 申花欲衝冠需做多方調整2025-11-07 01:46
陝西省通報一例新增輸入病例 疑似國安參加亞冠賽事球員2025-11-07 01:21
Did our grandparents have the best beauty advice?2025-11-07 01:09
阿圭羅賽中突發心跳過速就醫 巴薩傷病名單已9人2025-11-07 00:51