时间:2025-05-01 18:04:03 来源:网络整理编辑:百科
It sounds like a sci-fi movie. Over 5,000 connected devices, including light bulbs and vending machi
It sounds like a sci-fi movie. Over 5,000 connected devices, including light bulbs and vending machines, were hacked to slow internet service at a university to a crawl.
Poorly secured internet of things (IoT) devices have become gold mines for hackers looking to launch DDoS attacks to take websites and services offline. But this latest case, detailed in Verizon's Data Breach Digest 2017, is the rare example of gadgets attacking their own network.
SEE ALSO:Your smart fridge is about to make our IoT security nightmare so much worseThe devices were making hundreds of Domain Name Service (DNS) lookups every 15 minutes, causing the university's network connectivity to become unbearably slow or even inaccessible.
Weirdly enough, the majority of the searches "showed an abnormal number of sub-domains related to seafood," the report said.
Here's an abstract from the Digest'ssneak peek:
The firewall analysis identified over 5,000 discrete systems making hundreds of DNS lookups every 15 minutes. Of these, nearly all systems were found to be living on the segment of the network dedicated to our IoT infrastructure.
With a massive campus to monitor and manage, everything from light bulbs to vending machines had been connected to the network for ease of management and improved efficiencies.
While these IoT systems were supposed to be isolated from the rest of the network, it was clear that they were all configured to use DNS servers in a different subnet.
It's very unlikely, to use an understatement, that thousands of students at the university had a sudden and simultaneous urge to eat seafood.
Instead, what did happen was that cheeky hackers instructed the IoT devices to make DNS lookups related to seafood every 15 minutes.
Here's what Verizon's RISK (Research, Investigations, Solutions and Knowledge) team told the university after they were summoned to investigate the attack:
The RISK Team had provided me with a report detailing known indicators found in the firewall and DNS logs that I had sent over earlier. Of the thousands of domains requested, only 15 distinct IP addresses were returned. Four of these IP addresses and close to 100 of the domains appeared in recent indicator lists for an emergent IoT botnet.
So here's the case of vending machines and lamp posts compulsively searching for seafood and overwhelming the network with requests with the aim of taking it down.
If this isn't creepy/dystopian/fascinating, we don't know what is.
Luckily for the guys at the university, there was no need to replace "every soda machine and lamp post".
The Verizon's RISK team explained that the botnet "spread from device to device by brute forcing default and weak passwords".
To solve the massive hack, the university intercepted a clear-text malware password for a compromised IoT device and then used "that information to perform a password change before the next malware update".
Easy, right?
Overall, it doesn't look like this problem is going away anytime soon. There are more than 6 billion IoT devices currently running, according to Gartner Research. That number could reach more than 20 billion by 2020.
TopicsCybersecurity
Twitter grants everyone access to quality filter for tweet notifications2025-05-01 17:58
數據解析利物浦可持續發展道路 曼城真是一生之敵2025-05-01 17:42
廣州城官宣葉楚貴左膝關節前交叉韌帶撕裂 傷缺8個月2025-05-01 17:25
新豪門?官方:捷克億萬富豪已收購西漢姆27%股份2025-05-01 17:25
PlayStation Now game streaming is coming to PC2025-05-01 17:00
利物浦官宣複興英雄賽季後離隊 他帶來薩拉赫範迪克2025-05-01 16:44
中超之父寄語國足:寧可被打死不能嚇死 不能輸得窩窩囊囊2025-05-01 16:32
太懶 ?C羅每90分鍾跑動距離排曼聯倒三 卡瓦尼居首2025-05-01 15:57
New Zealand designer's photo series celebrates the elegance of aging2025-05-01 15:26
媒體人:金球獎已墮落成粉圈人氣獎 可惜了萊萬和若鳥2025-05-01 15:25
This chart shows just how high Simone Biles can jump2025-05-01 17:14
太懶 ?C羅每90分鍾跑動距離排曼聯倒三 卡瓦尼居首2025-05-01 17:09
數據解析利物浦可持續發展道路 曼城真是一生之敵2025-05-01 16:32
阿曼主帥:中國隊積分和實力不匹配 我們目標是戰勝所有對手2025-05-01 16:31
Olympian celebrates by ordering an intimidating amount of McDonald's2025-05-01 16:29
曝曼聯下場首發:桑喬改右邊翼衛 青木繼續配C羅2025-05-01 16:20
裏皮:足球曾在中國發展到頂峰 因缺乏青訓基礎而衰退2025-05-01 16:06
哈維夠硬!禁止皮克參加脫口秀 皮克:我想退役!2025-05-01 16:02
One of the most controversial power struggles in media comes to a close2025-05-01 15:49
廣州城官宣葉楚貴左膝關節前交叉韌帶撕裂 傷缺8個月2025-05-01 15:43