Slashdot Mirror


A Massive Botnet of CCTV Cameras Involved In Ferocious DDoS Attacks (softpedia.com)

An anonymous reader writes: "A botnet of over 25,000 bots is at the heart of recent DDoS attacks that are ferociously attacking businesses across the world with massive Layer 7 DDoS attacks that are overwhelming Web servers, occupying their resources and eventually crashing websites," reports Softpedia. This botnet's particularity is the fact that attacks never fluctuated and the attackers managed to keep a steady rhythm. This is not a classic botnet of infected computers that go on and off, but of compromised CCTV systems that are always on and available for attacks. The brands of CCTV DVRs involved in these attacks are the same highlighted in a report by a security researcher this winter, who discovered a backdoor in the firmware of 70 different CCTV DVR vendors. These companies had bought unbranded DVRs from Chinese firm TVT. When informed of the firmware issues, TVT ignored the researcher and the issues were never fixed, leading to crooks creating this huge botnet.

7 of 79 comments (clear)

  1. Owned by Anonymous Coward · · Score: 2, Funny

    by the Chinease. What's new?

  2. I'm curious by Okian+Warrior · · Score: 2, Insightful

    So TVT, despite being chinks, are actually a bunch of big lipped stinking nasty chocolatey worthless nigger jigaboo porch monkeys!!

    I'm curious.

    Does anyone know why these posts keep appearing? It seems like there's one at the top of every discussion.

    I can't imagine a real purpose for this.

    Does anyone know what the goal or intent is? Can anyone explain how this benefits the poster in any way?

  3. Once in a while is OK by Okian+Warrior · · Score: 2

    If you don't respond to it, then people browsing at >=1 will never know it exists. That is the good thing about this mod system. Plus, I don't think porch monkey is a racist term. My grandmother used to call me and my sister porch monkeys all the time.

    Yeah - In that definition I'm probably a porch monkey as well. Similar to "couch potato".

    I think a lot of people are responding "don't respond" as a reflex action from political correctness. That's fine, and we shouldn't respond, but...

    It also prevents us from talking about it. I've noticed these in a *lot* of posts, they always seem to get first post, and they're blatantly garbage.

    It doesn't hurt to start a discussion once-in-a-while, and I'm not promoting his view by quoting and asking "WTF?".

    We have a lot of smart people on this forum, many of which know a fair bit about psychology (armchair or otherwise).

    I'd be very interested to hear an [serious] analysis of the person that posts these things.

  4. Network Design Flaw by rtb61 · · Score: 2

    A piece of hardware still provides that connection, from network to network. So why are those pieces of hardware designed to allow naughty unnecessary communications. There is no reason why that hardware should be capable of executing a DDOS attack, a simple timing issue, that should be hardware locked.

    --
    Chaos - everything, everywhere, everywhen
    1. Re: Network Design Flaw by JustAnotherOldGuy · · Score: 2

      So why are those pieces of hardware designed to allow naughty unnecessary communications.

      The problem is not that they're designed to allow naughty unnecessary communication, the problem is that they're not designed not to.

      It's like designing a door with a knob but no lock- there was no thought given to keeping the bad guys out.

      This is going to be a bigger and bigger problem with the advent of IoT crap (the Internet Of Trash).

      --
      Just cruising through this digital world at 33 1/3 rpm...
  5. TFT selling Botnet time. by Hylandr · · Score: 2

    I wonder how much money TFT is making by selling access to the Botnet they got other people to purchase and deploy for them.

    Pretty ingenious really.

    --
    ~ People that think they are better than anyone else for any reason are the cause of all the strife in the world.
  6. List of affected brands by Anonymous Coward · · Score: 4, Informative

    Since it's buried 2-3 links in.

    (Extra characters to get past slashdot's minimum characters per line filter. Who the hell thought it would be a good idea to make a filter which basically prohibits lists, and also prevents you from putting the padding out of the way at the end of the post? Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum. Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.)

    Ademco
    ATS Alarmes technolgy and ststems
    Area1Protection
    Avio
    Black Hawk Security
    Capture
    China security systems
    Cocktail Service
    Cpsecured
    CP PLUS
    Digital Eye'z no website
    Diote Service & Consulting
    DVR Kapta
    ELVOX
    ET Vision
    Extra Eye 4 U
    eyemotion
    EDS
    Fujitron
    Full HD 1080p
    Gazer
    Goldeye
    Goldmaster
    Grizzly
    HD IViewer
    Hi-View
    Ipcom
    IPOX
    IR
    ISC Illinois Security Cameras, Inc.
    JFL Alarmes
    Lince
    LOT
    Lux
    Lynx Security
    Magtec
    Meriva Security
    Multistar
    Navaio
    NoVus
    Optivision
    PARA V