Slashdot Mirror


Compromised CCTV and NAS Devices Found Participating In DDoS Attacks (incapsula.com)

chicksdaddy writes: The parade of horribles continues on the Internet of Things, with a report from the security firm Incapsula that its researchers discovered compromised closed circuit cameras as well as home network attached storage (NAS) devices participating in denial of service attacks. The compromised machines included a CCTV at a local mall, just a couple minutes from the Incapsula headquarters.

According to the report, Incapsula discovered the infections as part of an investigation into a distributed denial of service attack on what it described as a "rarely-used asset" at a "large cloud service." The attack used a network of 900 compromised cameras to create a flood of HTTP GET requests, at a rate of around 20,000 requests per second, to try to disable the cloud-based server. The cameras were running the same operating system: embedded Linux with BusyBox, which is a collection of Unix utilities designed for resource-constrained endpoints.

The malware in question was a variant of a self-replicating program known as Lightaidra, which targets systems running BusyBox and exploits vulnerable Telnet/SSH services using so-called "brute force dictionary attacks" (aka "password guessing"). Given that many Internet connected devices simply use the default administrator credentials when deployed, calling it a "brute force" attack is probably a stretch.

64 comments

  1. You can burn out the motor coils in the cameras by Joe_Dragon · · Score: 1

    You can burn out the motor coils in the cameras by hacking the software and over driving them?

    1. Re:You can burn out the motor coils in the cameras by thedonger · · Score: 2

      You can burn out the motor coils in the cameras by hacking the software and over driving them?

      Maybe the cameras burned themselves out because they were tired of being our slaves?

      --
      Help fight poverty: Punch a poor person.
    2. Re:You can burn out the motor coils in the cameras by Anonymous Coward · · Score: 0

      It would be strange for there to be a software limit on the operation of the motors. That is to say, a properly designed system would size the motors will some safety factor, so that there would be no way to "over drive" them from software. Of course, depending on the mechanics of the thing, you might try to drive them into a stall position and hope that doing so for long enough would cause them to reach the end of life faster (or overheat, but again that should have been accounted for during sizing).

    3. Re:You can burn out the motor coils in the cameras by Mashiki · · Score: 1

      Wouldn't surprise me in the least, and seems very probable. You used to be able to destroy CRT monitors by telling a program to run the refresh, or horizontal or vertical alignments out of spec or sync too, for the longest time you could do it with ansi codes. Kinda like how you could destroy the old HDD's that needed a parking utility by telling the heads to slam into the spindle while the drive was still running.

      --
      Om, nomnomnom...
    4. Re:You can burn out the motor coils in the cameras by Joe_Dragon · · Score: 1

      You can have the software forget about the limit switches / run the motor 24/7 at full power / speed.

    5. Re:You can burn out the motor coils in the cameras by JustAnotherOldGuy · · Score: 3, Funny

      Man, I just can't wait until everything fucking I own is vulnerable and requires daily/weekly patching.

      Upgrade toilet? CHECK....DONE.
      Upgrade refrigerator? CHECK....DONE.
      Upgrade toaster? CHECK....DONE.
      Upgrade alarm clock? CHECK....DONE.
      Upgrade gas stove? CHECK....DONE.
      Upgrade TV? CHECK....DONE.
      Upgrade ink pen? CHECK....DONE.
      Upgrade couch? CHECK....DONE.
      Upgrade desk lamp? CHECK....DONE.
      Upgrade front door? CHECK....DONE.
      Upgrade coffee table? CHECK....DONE.
      Upgrade soap dispenser? CHECK....DONE.
      Upgrade wife's vibrator? CHECK....DONE.
      Upgrade the upgrade manager? CHECK....DONE.
      Upgrade kitchen light? CHECK....DONE.
      Upgrade lawnmower? CHECK....DONE.
      Upgrade sink? CHECK....DONE.

      --
      Just cruising through this digital world at 33 1/3 rpm...
    6. Re:You can burn out the motor coils in the cameras by JustAnotherOldGuy · · Score: 1

      It would be strange for there to be a software limit on the operation of the motors.

      Thank goodness a software exploit couldn't interfere with a software limit! Oh, wait....

      --
      Just cruising through this digital world at 33 1/3 rpm...
    7. Re:You can burn out the motor coils in the cameras by Anonymous Coward · · Score: 1

      You know you want to let your toilet become part of a zombie bot network so it can DDoS someone.

    8. Re:You can burn out the motor coils in the cameras by Anonymous Coward · · Score: 0

      Upgrade wife's vibrator? CHECK....DONE.

      Some of those items should just be self-sufficient with their upgrade processes...

    9. Re:You can burn out the motor coils in the cameras by MrL0G1C · · Score: 1

      You forgot to upgrade the cats pacemaker, it got hit by a worm made by cat hating hacker and died.

      And the toilet update failed, the toilet is now in an endless reboot-crash loop.

      --
      Waterfox - a Firefox fork with legacy extension support, security updates and better privacy by default.
    10. Re:You can burn out the motor coils in the cameras by MrL0G1C · · Score: 1

      Oh and don't even think of trying to re-flash the toilet yourself, that's illegal under both health and safety and DMCA laws and your hair dryer will report you to the police if you try.

      --
      Waterfox - a Firefox fork with legacy extension support, security updates and better privacy by default.
    11. Re:You can burn out the motor coils in the cameras by Tyrannicsupremacy · · Score: 1

      They probably trip somehow when they draw too much current for a prolonged period. I suppose over time it could potentially shorten the life of the power supply or motors, but fortunately the majority of property owners that install cameras go for the bottom shelf non-articulated cameras. Moving cameras are a luxury usually reserved to a certain few large buildings or stores.

      --
      http://i.cubeupload.com/T6cyLu.png
  2. Thanks, but no thanks Linux by Anonymous Coward · · Score: 1

    That's why when it comes to my Internet of Things, I only trust the Genuine® Advantage©® of Certified® Microsoft©® Windows®© Internet© of© Things©® Soft®ware®.

    ©

    1. Re:Thanks, but no thanks Linux by invictusvoyd · · Score: 1

      Yeah true .. It's so fucked up that the exploits will crash. Very safe.

  3. Slashdot submission style by Anonymous Coward · · Score: 1

    Is anyone else getting annoyed at the writing style of recent Slashdot submissions ?

    They are being written in a dumbed down folksy style with idiotic mannerisms designed to explain things to idiots, not the geek readership around here.

    1. Re:Slashdot submission style by Grishnakh · · Score: 1

      What geek readership? The true geeks all left a long time ago. The dumbed-down folksy style is a perfect fit for the wannabe geeks and Teatards who still largely inhabit this place.

    2. Re:Slashdot submission style by gstoddart · · Score: 3, Informative

      The true geeks all left a long time ago. The dumbed-down folksy style is a perfect fit for the wannabe geeks and Teatards who still largely inhabit this place

      Hmmmm ... if not A, then (B|C) ... so which of 'wannabe geeks' or Teatards are you including yourself in?

      Or are you just saying small values of A?

      --
      Lost at C:>. Found at C.
    3. Re: Slashdot submission style by Anonymous Coward · · Score: 0

      Exactly. When this place started worshipping the Republicans, logical people of course left.

    4. Re: Slashdot submission style by Anonymous Coward · · Score: 0

      And drove off all of the women with their support of rape.

    5. Re: Slashdot submission style by Anonymous Coward · · Score: 0

      Normal people always recoil from Xians.

    6. Re:Slashdot submission style by Anonymous Coward · · Score: 0

      that damn black kettle!

    7. Re: Slashdot submission style by Anonymous Coward · · Score: 0

      When the Republicans took over this site, smart people fled. Smart people fled.

    8. Re: Slashdot submission style by Anonymous Coward · · Score: 0

      > ...smart people fled. Smart people fled.

      Why do liberals so often repeat themselves?

    9. Re: Slashdot submission style by Anonymous Coward · · Score: 0

      They hate us and want us to die. Want us to die.

    10. Re:Slashdot submission style by drinkypoo · · Score: 1

      It's a false dichotomy, anyway. There's also blowhards, diehards, refugees when 4chan or reddit is down, motorheads, geeks, sluts, bloods, wastoids, dweebies, dickheads...

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    11. Re:Slashdot submission style by Anonymous Coward · · Score: 0

      There are sluts? This reactionary site is starting to look better.

    12. Re: Slashdot submission style by Anonymous Coward · · Score: 0

      The smart people were long gone by the time the remaining fools turned into right-wing lunatics. Slashdot peaked many years ago.

    13. Re:Slashdot submission style by OzPeter · · Score: 1

      Is anyone else getting annoyed at the writing style of recent Slashdot submissions ?

      They are being written in a dumbed down folksy style with idiotic mannerisms designed to explain things to idiots, not the geek readership around here.

      Remember that Slashdot is up for sale, so "broadening" the audience is going to help Dice recoup what it paid for Slashdot.

      --
      I am Slashdot. Are you Slashdot as well?
    14. Re:Slashdot submission style by Anonymous Coward · · Score: 0

      and righteous dudes

    15. Re:Slashdot submission style by gstoddart · · Score: 1

      LOL .. crap. So, it's high school all over again?

      --
      Lost at C:>. Found at C.
  4. Doesn't surprise me by 0123456 · · Score: 2

    My Webcam came with an open root telnet port. Just connect to port XXXX (whatever it was, I forget) and you were automatically logged in to a root shell.

    There's a reason I kept it completely firewalled from the Internet.

  5. Distance matters now? by xxxJonBoyxxx · · Score: 2

    >> compromised machines included a CCTV at a local mall, just a couple minutes from the Incapsula headquarters

    Clearly, the correct thing to do is move the HQ further away from the mall, right?

    1. Re:Distance matters now? by wonkey_monkey · · Score: 1

      Minutes are a measure of time. They'll have to move the HQ into the past or future.

      --
      systemd is Roko's Basilisk.
    2. Re:Distance matters now? by phantomfive · · Score: 1

      Maybe they can move it 12 parsecs into the future.

      --
      "First they came for the slanderers and i said nothing."
    3. Re:Distance matters now? by radarskiy · · Score: 1

      The alternative is to preemptively take over the mall's CCTV.

    4. Re:Distance matters now? by Anonymous Coward · · Score: 0

      No, but dramatic effect is more important, sadly.

  6. Re: And this is why the Republicans... by Anonymous Coward · · Score: 0

    They contentstenntlie rape us so this is nothin. Is nothin.

  7. Interesting by ArchieBunker · · Score: 2

    A few years ago I got curious and started scanning the local subnets on my ISP for open telnet ports. Found one DVR type of device with four cameras and four hard drives running with disks 100% filled. The default logins worked and found myself at a busybox prompt. What was interesting was there was always a few others logged in from countries over seas. I managed to tftp a fragment of a video file but couldn't recognize the area. There is no reason for multiple telnet logins to a DVR box.

    --
    Only the State obtains its revenue by coercion. - Murray Rothbard
    1. Re:Interesting by KGIII · · Score: 2

      I'm not admitting to anything but there's someone who will answer to my name, if called, who may have a hobby of finding online printers and sending them a (single) printed piece of paper telling them of the fault. Why they've got them online or with forwarded ports is beyond me. But, you know... Sometimes there are easily accessed routers and whatnot. I don't know anything about anything, of course, but they all *probably* have the default passwords still. If I were to do something like that then I'd obviously update their firmware, I'd be nice like that.

      --
      "So long and thanks for all the fish."
  8. Funny by imp7 · · Score: 1

    It's funny reading this today, because yesterday my smtp server was getting attacked by a Samsung DVR.

    1. Re:Funny by thedonger · · Score: 2

      It's funny reading this today, because yesterday my smtp server was getting attacked by a Samsung DVR.

      I'm fairly certain my Xbox is bullying my PS3.

      --
      Help fight poverty: Punch a poor person.
    2. Re:Funny by KGIII · · Score: 1

      That's because your PS3 is racist and deserves it.

      --
      "So long and thanks for all the fish."
    3. Re:Funny by thedonger · · Score: 1

      #AllGamingPlatformsMatter

      --
      Help fight poverty: Punch a poor person.
  9. Re: And this is why the Republicans... by Anonymous Coward · · Score: 0

    They are not whole people.

  10. Re: And this is why the Republicans... by Anonymous Coward · · Score: 0

    There is no evidence that they are allowed to add security and lack of evidence is strong evidence.

  11. Re: And this is why the Republicans... by Anonymous Coward · · Score: 0

    They hate us. That is why they won't allow us to have security.

  12. The Wikipedia of Things, where any by Anonymous Coward · · Score: 1

    The Wikipedia of Things, where any dipshit on the internet can edit your refrigerator.

  13. And this is what you get... by Anonymous Coward · · Score: 0

    ...for opening up all those Linux boxen to the world.

    It's like Windows 3.11 all over again.

  14. Is this really news?! by aaarrrgggh · · Score: 1

    I have no idea why people allow outside access to their NAS device or webcams. At a minimum, require VPN access, but ideally put them in a VLAN "jail".

    Someone is going to need to get much more savvy when it comes to securing this "IoT" monster.

    1. Re:Is this really news?! by schitso · · Score: 1

      It's more likely "professionally" installed systems that are the problem. Most physical security companies have no freaking idea what they're doing on a network, even 10+ years after IP cameras were introduced. I should know, I clean up after them all the time at my own physical security company. Add that to all the problems that "Hackvision" (Hikvision) has had, and it's a recipe for disaster.

    2. Re:Is this really news?! by Anonymous Coward · · Score: 0

      I ended up doing a fair amount of camera work for exactly that reason, I am a network guy. I COULD have made the systems much more secure, even with HIKs track record. But doing that was more expensive, or complicated, or annoying so whatever.

      The customers are their own worse enemy. Why are you paying my contracting fee and ignoring everything I just said? Even companies that should know better and had the resources. "Wait, so you want to isolate the cameras from the rest of the network? we ain't paying for more switches and IT won't let you touch the VLAN settings. Just do whatever works. Oh and Exec Z wants to check it from his ipad so make sure that VPN clients can access the central DVR, No we don't want a proxy service between them, thats just more shit to break and fix later"

    3. Re:Is this really news?! by Anonymous Coward · · Score: 0

      Uh, because one wants file access outside of one's lan?
      Because one wants to see one's cameras when on vacation from their tablet or phone?
      Not saying you don't have a point, but there are certainly reasons why IoT devices may need internet access.... If one really thinks one needs an IoT device.
      Me, I'm just pissed that other tenants in our building who have absolutely no need for WiFi printing nevertheless leave their printers' WiFi on.

  15. Re: You can burn out the motor coils in the camera by Anonymous Coward · · Score: 0

    Yep, I blew a monitor in my early days of Linux by getting the refresh rates wrong.

  16. Is CCTV the right term? by Geste · · Score: 1

    From the article, it seems like the exploited cameras are IP-addressable/reachable. That does not sound like Closed Circuit TV as I think of it, with non-ethernet coax-and-like connected cameras connected to a monitoring station in a true closed circuit. I am no expert, but should we be talking about an exploit of "IP-enabled security cameras" or something like that instead?

  17. The malware in question .. by nickweller · · Score: 1

    Dear $public $relations $firm, please generate 'reports' about DDOS attacks that don't mention that vast pool of compromised Microsoft Windows desktops out there on the Internet.

    'Incapsula is a cloud-based security and acceleration service that makes websites safer, faster, and more reliable'

  18. Hacked Linux by Anonymous Coward · · Score: 0

    I installed KDE 64 Sabayon Latest from USA Mirror. Inside of 3 min it was taken over.
    Installed stopped to pet dog, mouse took off and opened menus. I killed the power.

  19. Brute force by invictusvoyd · · Score: 1

    admin admin
    admin admin
    I said admin you dumb camera!
    admin admin

    1. Re:Brute force by Tyrannicsupremacy · · Score: 1

      I occasionally install windows embed DVR units. Not quite admin, admin, but they usually stay 'i3admin, i3admin' for their operational lives.

      --
      http://i.cubeupload.com/T6cyLu.png
  20. chaussure nike tn requin 2015 by senfanjuo · · Score: 1

    the Nike Air Ralston Mid nike tn requin ool Grey,makes good on the air yeezy shoes stylish design, adding a creamy grey suede upper to a white midsole, orange accents, and a sport-inspired pad-like outsole. Hit the jump for a few more looks, and hit spots like MrRSportsMiami.com for a pair today. Yesterday brought a glimpse of one of the simpler Hachi colorways wee seen to date, eschewing the standard Sting-inspired two-color (or at least two-tone) look in favor of a more uniform coloring. And as the counterpoint to that, today brings some of the more unique looks, although no less impressive. The Nike Hachi Gingham pack, designed specifically for women, each sport the air yeezy pink vintage-inspired silhouette but forgo leather in favor of a gingham textile, three different colors in total. Check out each under the cut, and look for these in Asia now, with a US release still up in the air. While a rather scarce one, the Coast Classic is nevertheless a great summer look, with a classically simple construction that lends itself to colorways both subtle and complex. In fact the latest version, the Nike Coast Classic nike Free Run SP Black/White Gingham, goes for subtle and complex on the same shoe, with black suede on the toe and heelcap sitting atop a classic vulc rubber sole,

  21. Re: And this is why the Republicans... by Anonymous Coward · · Score: 0

    You should seek help. Seek help.

  22. ipv6 is a weapon - by Anonymous Coward · · Score: 0

    Idiots bought every 'tech' the 'smart' bs all the 'wireless' bs the 'ipv6' 'internet of things' is a Weapon, they have been spraying us with nano chip chemtrails, you have been far more than just 'chipped', You are now on the 'internet of things' you breath the nano chips the myriad particulate designed to self assemble into 'morgellons' fiber optics inside of you. Done. Don't bother looking it up all the bullshit sites run by them, 'morgellons' was proven in study, they pointed to one fraction similar to lyme, lyme was made in a lab same with their other weapons. It is far more than 'lyme' disease. So called ipv6 is brain rape, already test attached to the auto 'ai' kill system. Idiots get off your ass, see -fake acting - post above.
    Add these with others in post above
    -archive.org/details/DontTalkAboutTheWeather_451 The haze in the air is nano chips, other content- www.willthomasonline.net/Nano_Chemtrails.html - the contents far more than described, we're breathing the nano chips, other content. For 'wireless' brain surveillance and control by 'smart grid' and control of those leftover from virus kill.
    They also sprayed a virus that's going to kill other races but not jews. newworldwar.org/chemical.htm - ignore notes at bottom, skip rest of site.
    http://67.225.133.110/~gbpprorg/judicial-inc/Jews_and_KKK.htm
    And of course this already in first post though to slam it in your Face again-
    http://67.225.133.110/~gbpprorg/judicial-inc/Coure_d_Arlene.htm fake 'neo nazis'
    http://balder.org/judea/Hate-Speech-Laws-Immigration-Jewish-Influence-USA.php
    -mass destruction by mass immigration while jew rule and kill everyone.

    The jew bullshit 'conspiracy theory' meem to distract from their tribe, idiots parroted 'wel if I'm not doin anything wrong then...' idiots, now you're being brain raped, soon to be slaughtered, that's the POINT of privacy is so you have prvacy to plan and stop those who are planning to kill you. Now you're being SPRAYED. The jews have all the resources all the weapons they don't need your useless ass anymore. They will cull race by race until none left but the jews and their chinese 'morgellons' transhuman' slaves.
    Don't bother searching, you just waste time on fake 'jew truther' sites run by jews. The links I've given are the cleanest there are and even so some are jew sites that put up the info so you 'follow' and waste time. copy the info, get off the web, give links to others, put links on notes hand out to meet people. No one will do it for you, grow up, make your own tribes