时间:2025-07-06 03:01:03 来源:网络整理编辑:百科
It sounds like a sci-fi movie. Over 5,000 connected devices, including light bulbs and vending machi
It sounds like a sci-fi movie. Over 5,000 connected devices, including light bulbs and vending machines, were hacked to slow internet service at a university to a crawl.
Poorly secured internet of things (IoT) devices have become gold mines for hackers looking to launch DDoS attacks to take websites and services offline. But this latest case, detailed in Verizon's Data Breach Digest 2017, is the rare example of gadgets attacking their own network.
SEE ALSO:Your smart fridge is about to make our IoT security nightmare so much worseThe devices were making hundreds of Domain Name Service (DNS) lookups every 15 minutes, causing the university's network connectivity to become unbearably slow or even inaccessible.
Weirdly enough, the majority of the searches "showed an abnormal number of sub-domains related to seafood," the report said.
Here's an abstract from the Digest'ssneak peek:
The firewall analysis identified over 5,000 discrete systems making hundreds of DNS lookups every 15 minutes. Of these, nearly all systems were found to be living on the segment of the network dedicated to our IoT infrastructure.
With a massive campus to monitor and manage, everything from light bulbs to vending machines had been connected to the network for ease of management and improved efficiencies.
While these IoT systems were supposed to be isolated from the rest of the network, it was clear that they were all configured to use DNS servers in a different subnet.
It's very unlikely, to use an understatement, that thousands of students at the university had a sudden and simultaneous urge to eat seafood.
Instead, what did happen was that cheeky hackers instructed the IoT devices to make DNS lookups related to seafood every 15 minutes.
Here's what Verizon's RISK (Research, Investigations, Solutions and Knowledge) team told the university after they were summoned to investigate the attack:
The RISK Team had provided me with a report detailing known indicators found in the firewall and DNS logs that I had sent over earlier. Of the thousands of domains requested, only 15 distinct IP addresses were returned. Four of these IP addresses and close to 100 of the domains appeared in recent indicator lists for an emergent IoT botnet.
So here's the case of vending machines and lamp posts compulsively searching for seafood and overwhelming the network with requests with the aim of taking it down.
If this isn't creepy/dystopian/fascinating, we don't know what is.
Luckily for the guys at the university, there was no need to replace "every soda machine and lamp post".
The Verizon's RISK team explained that the botnet "spread from device to device by brute forcing default and weak passwords".
To solve the massive hack, the university intercepted a clear-text malware password for a compromised IoT device and then used "that information to perform a password change before the next malware update".
Easy, right?
Overall, it doesn't look like this problem is going away anytime soon. There are more than 6 billion IoT devices currently running, according to Gartner Research. That number could reach more than 20 billion by 2020.
TopicsCybersecurity
Darth Vader is back. Why do we still care?2025-07-06 02:26
中超延長關窗市場依然冷清 津蘇兩隊球員優勢並不明顯2025-07-06 02:07
莫拉塔大戰軟腳!兩次打丟必進球 應為出局負責2025-07-06 02:02
老當益壯!38歲佩佩扛起波爾圖防線 貢獻18次解圍2025-07-06 01:59
Carlos Beltran made a very interesting hair choice2025-07-06 01:38
塔利斯卡健身房訓練保持狀態 何時歸隊仍未知(GIF)2025-07-06 01:26
埃裏克日夫科維奇建功亞泰22025-07-06 01:03
李昂吳曦聘用同一經紀人 聯手加盟上海海港並不意外2025-07-06 01:02
More than half of women in advertising have faced sexual harassment, report says2025-07-06 00:55
胡爾克巴甲隊首秀即送助攻 中超連線塔爾德利破門2025-07-06 00:34
Richard Branson 'thought he was going to die' in bike accident2025-07-06 02:30
10日賠率:巴黎拒絕遭巴薩逆轉 利物浦雙殺晉級2025-07-06 02:00
卡拉格:利物浦如今像精神層麵的侏儒 前四很遙遠2025-07-06 01:49
羅比尼奧強奸案維持原判 踏上歐洲土地就會被捕2025-07-06 01:44
More than half of women in advertising have faced sexual harassment, report says2025-07-06 01:34
曝皇馬今夏欲挖角馬赫雷斯 他比齊祖愛將強百倍2025-07-06 01:29
吳曦本人仍在抉擇下家 最快月底才會有明確指向2025-07-06 01:25
詹俊:單獨批評C羅躲球不公平 責任不該由一人承擔2025-07-06 01:24
Richard Branson 'thought he was going to die' in bike accident2025-07-06 00:55
專家:梅西留隊可能達到60%2025-07-06 00:42