Security News IoT Devices Enslaved Via 12-Year-Old OpenSSH Flaw

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
Attackers are enslaving Internet of Things (IoT) devices to remotely mount DDoS campaigns, by using a 12-year old vulnerability in OpenSSH.

Akamai Technology researchers Ory Segal and Ezra Caltum have dubbed the issue theSSHowDowN Proxy.

It’s not a new type of vulnerability or attack technique, but rather a continued weakness in many default configurations of internet-connected devices. But a broad range of devices are being exploited in mass-scale attack campaigns, including CCTV devices for video surveillance, DVRs, satellite antenna equipment, routers, Wi-Fi access points, cable and ADSL modems, internet-connected Network Attached Storage (NAS) devices and more.

This malicious network is mounting attacks against a multitude of internet targets and internet-facing services, such as HTTP, SMTP and network scanning, and against internal networks that host the connected devices. Once malicious users access the web administration console, they have been able to compromise the device’s data and, in some cases, fully take over the machine.

Full Article. http://www.infosecurity-magazine.com/news/iot-devices-enslaved-via-12yearold/
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top