A Year After Mirai: DVR Torture Chamber Test Shows Two Minutes Between Exploits (sans.edu)
UnderAttack writes: Over two days, the Internet Storm Center connected a default configured DVR to the internet, and rebooted it every 5 minutes in order to allow as many bots as possible to infect it. They detected about one successful attack (using the correct password xc3511) every 2 minutes. Most of the attackers were well known vulnerable devices. A year later, what used to be known as the "Mirai" botnet has branched out into many different variants. But it looks like much hyped "destructive" variants like Brickerbot had little or no impact.
Wouldn't it have just been simpler to create a honey pot that answered to the correct password?
DVR doesn't mean what he thinks it means. He's talking about IP cameras. He says it's an "Anrai" in one place, an "Anrain" in another, Google says it's probably an "Anran."
He claims "Traffic from the DVR outbound was blocked by the firewall to prevent it from infecting other systems." But, of course, if that were true then the camera wouldn't be able to create a telnet session.
This, from someone claiming to be "Ph.D., Dean of Research, SANS Technology Institute?" A quick search says "The SANS Technology Institute is regionally accredited by the Middle States Commission on Higher Education...", which is itself a DBA for a corporation created in 2013.
OK, so they're the successor to ITT Tech, but without the reputation.
"National Security is the chief cause of national insecurity." - Celine's First Law
The Virus Aquarium
https://xkcd.com/350/
You know when things say "just port-forward" and people just do that?
There ya go.
One of the reasons that I look upon any port-forward as incredibly suspicious, professionally, and only like doing it if it goes via a device capable of connection-limiting, rate-limiting and performing intrusion-protection and sanitisation for the exact protocol in question.
"Hey, just bash a hole in your house so the postman can deliver your parcels. Hey, just bash another hole so the gas man can read your meter. Hey, just bash another hole so your lightbulbs can talk out."... at the point it starts sounding silly, that's the point it already is silly.
UPNP: Hay, just let anyone who wants access to your house bash a hole in the wall!
const int one = 65536; (Silvermoon, Texture.cs)
SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC