Security News Smart Light Bulb Worm Hops from Lamp to Lamp

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
That connected light bulb you just installed could flip the switch, as it were, on a hacker’s ability to take over your smart home.

Using the Philips Hue smart light bulb as a platform, researchers from Dalhousie University in Canada and the Weizmann Institute of Science in Israel identified a flaw that could potentially give hackers control over not just the lights themselves, but also connected switches, locks and thermostats on the same home network.

The researchers developed a computer worm that could be easily spread to other devices, jumping directly from one lamp directly to another using the built-in ZigBee short-range wireless connectivity.

They managed to take over lamps in two different attack scenarios. In the first, conducted at the Weizmann Institute, the researchers did a drive-by hack using a vehicle, and found they were able to manipulate the lights from up to 70 meters away.

In the second, the target was an office building in the city of Be’er Sheva in Israel, which hosts several well-known security companies and also the Israeli Computer Emergency Response Team (CERT). Several Philips Hue lights were installed on one floor of the building, and an attack kit was installed on a drone. As the drone got closer to building, lights were able to be manipulated to spell out "S.O.S." in Morse code.

There are further implications, of course. Once hackers have control of the lights, they can also pivot within the home (or office) network to attack other unsecured endpoints. And, the compromised devices could be used to jam wireless networks, attack the electrical grid or steal information.

Dalhousie researcher Colin O’Flynn, a PhD student in Dal’s Department of Electrical & Computer Engineering, kicked off the study during his research on re-purposing low-cost Phillips Hue bulbs by re-programming them with new code.

He noted that the lateral device connections are in and of themselves of interest.

“Hopefully we'll start to take security of all 'connected' devices seriously, and not just those connected to the internet,” says O’Flynn. “A big part of our research was showing how such a worm could spread between the light-bulbs themselves wirelessly, independent of any internet or network connection.”

Other researchers added that the study is just further proof of the widening scope of the internet of things (IoT) attack vector.

Read More. Smart Light Bulb Worm Hops from Lamp to Lamp
 

tim one

Level 21
Verified
Honorary Member
Top Poster
Malware Hunter
Jul 31, 2014
1,086
Thanks for the info, I read with pleasure because I'm passionate even about home automation and it is possible that a cyber criminal can exploit this weakness...they do not know what to attack today.
What will be the next step? :oops:
 

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
Thanks for the info, I read with pleasure because I'm passionate even about home automation and it is possible that a cyber criminal can exploit this weakness...they do not know what to attack today.
What will be the next step? :oops:
And to think that this just the beginning of IoT who knows the future will hold. So far only my Laptops are the only devices that can connect to the scary world out there and i feel reasonably secure with them. :)
 

soccer97

Level 11
Verified
May 22, 2014
517
The IoT attacks have become ridiculous. Sometimes it makes you consider reverting to the old offline model. I haven't adopted any IoT tech yet b/c I know that it is not hardened and ready for 'production' IMHO. How do you push updates to a lightbulb? Use a USB to update a refrigerators software? Wow. Time for some serious design and code review.

Hopefully in a few years, things will be treated with the seriousness of PC security - well you know what I mean.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top