时间:2025-06-17 10:35:12 来源:网络整理编辑:百科
It sounds like a sci-fi movie. Over 5,000 connected devices, including light bulbs and vending machi
It sounds like a sci-fi movie. Over 5,000 connected devices, including light bulbs and vending machines, were hacked to slow internet service at a university to a crawl.
Poorly secured internet of things (IoT) devices have become gold mines for hackers looking to launch DDoS attacks to take websites and services offline. But this latest case, detailed in Verizon's Data Breach Digest 2017, is the rare example of gadgets attacking their own network.
SEE ALSO:Your smart fridge is about to make our IoT security nightmare so much worseThe devices were making hundreds of Domain Name Service (DNS) lookups every 15 minutes, causing the university's network connectivity to become unbearably slow or even inaccessible.
Weirdly enough, the majority of the searches "showed an abnormal number of sub-domains related to seafood," the report said.
Here's an abstract from the Digest'ssneak peek:
The firewall analysis identified over 5,000 discrete systems making hundreds of DNS lookups every 15 minutes. Of these, nearly all systems were found to be living on the segment of the network dedicated to our IoT infrastructure.
With a massive campus to monitor and manage, everything from light bulbs to vending machines had been connected to the network for ease of management and improved efficiencies.
While these IoT systems were supposed to be isolated from the rest of the network, it was clear that they were all configured to use DNS servers in a different subnet.
It's very unlikely, to use an understatement, that thousands of students at the university had a sudden and simultaneous urge to eat seafood.
Instead, what did happen was that cheeky hackers instructed the IoT devices to make DNS lookups related to seafood every 15 minutes.
Here's what Verizon's RISK (Research, Investigations, Solutions and Knowledge) team told the university after they were summoned to investigate the attack:
The RISK Team had provided me with a report detailing known indicators found in the firewall and DNS logs that I had sent over earlier. Of the thousands of domains requested, only 15 distinct IP addresses were returned. Four of these IP addresses and close to 100 of the domains appeared in recent indicator lists for an emergent IoT botnet.
So here's the case of vending machines and lamp posts compulsively searching for seafood and overwhelming the network with requests with the aim of taking it down.
If this isn't creepy/dystopian/fascinating, we don't know what is.
Luckily for the guys at the university, there was no need to replace "every soda machine and lamp post".
The Verizon's RISK team explained that the botnet "spread from device to device by brute forcing default and weak passwords".
To solve the massive hack, the university intercepted a clear-text malware password for a compromised IoT device and then used "that information to perform a password change before the next malware update".
Easy, right?
Overall, it doesn't look like this problem is going away anytime soon. There are more than 6 billion IoT devices currently running, according to Gartner Research. That number could reach more than 20 billion by 2020.
TopicsCybersecurity
Snapchat is about to explode in popularity, report says2025-06-17 10:07
波切蒂諾不滿在巴黎實際權力過小 非常向往去曼聯2025-06-17 09:14
名宿:姆巴佩是巴黎一哥 他未得到比肩梅西的認可2025-06-17 08:54
記者 :C羅是曼聯問題所在?他多次拯救了球隊!2025-06-17 08:53
Pokémon Go is so big that it has its own VR porn parody now2025-06-17 08:52
植入6塊鈦板18個螺釘 !官方:那不勒斯鋒霸將傷缺90天2025-06-17 08:31
名宿:姆巴佩是巴黎一哥 他未得到比肩梅西的認可2025-06-17 08:25
巴薩進攻端乏力仍雪藏庫鳥+鋒霸 哈維用人遭質疑2025-06-17 08:22
Katy Perry talks 'Rise,' her next batch of songs, and how to survive Twitter2025-06-17 08:17
皇馬客場大勝完成複仇 連續19年進16強曆史第一隊2025-06-17 08:02
This 'sh*tpost' bot makes terrible memes so you don't have to2025-06-17 10:31
名記談凱西續約 :米蘭的態度明確 俱樂部高於球員2025-06-17 10:29
巴薩進攻端乏力仍雪藏庫鳥+鋒霸 哈維用人遭質疑2025-06-17 09:54
索帥失敗原因:執教能力是硬傷 砸大錢反而挨毒打2025-06-17 09:44
PlayStation Now game streaming is coming to PC2025-06-17 09:24
皇馬前瞻 :複仇魚腩+晉級之戰 本澤馬衝歐冠4連斬2025-06-17 09:04
繼續前進 !C羅:我們是曼聯人 為球隊而戰永不停歇2025-06-17 08:53
英冠球員比賽中突然暈倒 謝菲聯 :他已經恢複意識2025-06-17 08:32
Samsung Galaxy Note7 teardown reveals the magic behind the phone's iris scanner2025-06-17 08:25
國米前瞻:藍黑軍再遇苦主 戰殘陣礦工欲提前出線2025-06-17 07:50