时间:2025-11-07 00:47:20 来源:网络整理编辑:百科
It sounds like a sci-fi movie. Over 5,000 connected devices, including light bulbs and vending machi
It sounds like a sci-fi movie. Over 5,000 connected devices, including light bulbs and vending machines, were hacked to slow internet service at a university to a crawl.
Poorly secured internet of things (IoT) devices have become gold mines for hackers looking to launch DDoS attacks to take websites and services offline. But this latest case, detailed in Verizon's Data Breach Digest 2017, is the rare example of gadgets attacking their own network.
SEE ALSO:Your smart fridge is about to make our IoT security nightmare so much worseThe devices were making hundreds of Domain Name Service (DNS) lookups every 15 minutes, causing the university's network connectivity to become unbearably slow or even inaccessible.
Weirdly enough, the majority of the searches "showed an abnormal number of sub-domains related to seafood," the report said.
Here's an abstract from the Digest'ssneak peek:
The firewall analysis identified over 5,000 discrete systems making hundreds of DNS lookups every 15 minutes. Of these, nearly all systems were found to be living on the segment of the network dedicated to our IoT infrastructure.
With a massive campus to monitor and manage, everything from light bulbs to vending machines had been connected to the network for ease of management and improved efficiencies.
While these IoT systems were supposed to be isolated from the rest of the network, it was clear that they were all configured to use DNS servers in a different subnet.
It's very unlikely, to use an understatement, that thousands of students at the university had a sudden and simultaneous urge to eat seafood.
Instead, what did happen was that cheeky hackers instructed the IoT devices to make DNS lookups related to seafood every 15 minutes.
Here's what Verizon's RISK (Research, Investigations, Solutions and Knowledge) team told the university after they were summoned to investigate the attack:
The RISK Team had provided me with a report detailing known indicators found in the firewall and DNS logs that I had sent over earlier. Of the thousands of domains requested, only 15 distinct IP addresses were returned. Four of these IP addresses and close to 100 of the domains appeared in recent indicator lists for an emergent IoT botnet.
So here's the case of vending machines and lamp posts compulsively searching for seafood and overwhelming the network with requests with the aim of taking it down.
If this isn't creepy/dystopian/fascinating, we don't know what is.
Luckily for the guys at the university, there was no need to replace "every soda machine and lamp post".
The Verizon's RISK team explained that the botnet "spread from device to device by brute forcing default and weak passwords".
To solve the massive hack, the university intercepted a clear-text malware password for a compromised IoT device and then used "that information to perform a password change before the next malware update".
Easy, right?
Overall, it doesn't look like this problem is going away anytime soon. There are more than 6 billion IoT devices currently running, according to Gartner Research. That number could reach more than 20 billion by 2020.
TopicsCybersecurity
These glasses hide a fitness tracker on your face2025-11-07 00:29
翟天臨竟回複網友 :接受被罵 ,我也承受很多 ,我去死你改論文加油2025-11-07 00:22
《才不要和老板談戀愛》殺青 黃子韜宋祖兒上演高概念穿越尋愛之旅2025-11-07 00:05
為什麽人人都要改編東野圭吾 ?2025-11-07 00:00
Here's George Takei chilling in zero gravity for the 'Star Trek' anniversary2025-11-06 23:54
複古臻藝,演繹紳士魅力丨王一博攜 MTG2025-11-06 23:06
雪花秀天貓超級品牌日攜新品來襲,進階演繹亞洲肌膚緊致美學2025-11-06 22:42
模特世安;走出屬於自己的電商拍攝之路2025-11-06 22:42
Tourist survives for month in frozen New Zealand wilderness after partner dies2025-11-06 22:34
挖掘明星價值,品牌如何玩轉“泛娛樂”營銷?2025-11-06 22:29
Australian football makes history with first LGBT Pride Game2025-11-07 00:16
“密封記憶”揭開頭條謎底,《獨家頭條》發布中文主題曲2025-11-06 23:54
獻禮劇也可以不一樣!迷霧劇場先導片《再見那一天》新視角致敬人民警察2025-11-06 23:25
第15屆FIRST青年影展落幕 ,《棒 !少年》的故事在繼續2025-11-06 23:24
Airbnb activates disaster response site for Louisiana flooding2025-11-06 23:14
歐陽娜娜化身“使命動員官” 快來pick你沒見過的硬核甜妹!2025-11-06 23:09
爆款品牌大爆發,為什麽不能是你?!2025-11-06 22:49
中國視效行業更新“工作手冊” 倍視傳媒助影視後期標準2025-11-06 22:32
Make money or go to Stanford? Katie Ledecky is left with an unfair choice.2025-11-06 22:17
翟天臨竟回複網友 :接受被罵 ,我也承受很多,我去死你改論文加油2025-11-06 22:03