Researcher Scans All IP Addresses of Austria, Finds a Ton of Things That Shouldn't Be Online (haschek.at)
Christian Haschek scanned the entire Austrian IP space and found IP cameras, printers, and industrial control systems and a range of other devices that should not be online.
IT professionals around the world were shocked by this discovery. Not in the slightest.
If I had a DeLorean... I would probably only drive it from time to time.
Austria has 11 million IPv4 addresses. 11.170.487 to be exact
You know you've been in the continent too long when you put periods in the middle of an integer, but not at the end of a sentence. ... na ... never mind.
Sorry to be such a grammar n
but if its done in the name of "research'?
You'd think they'd be more careful, ya know, with all them dingos eating the babies and stuff
They hooked up - let us just call it something very large, handling a lot of energy - to the public internet via a ADSL connection.
I went home and demonstrated I had direct read/write access to everything from home without using any of the passwords (and I could just change them.)
They put in a firewall on that site, but making the product secure was out of the question. That was 15 years ago, they have changes to a OS with some security since then.
Then someone told him about Shodan.
shh.
I used to think that people were smart.
Then came the Internet, and I started thinking that people were getting dumber, not smarter, over time.
Then came Internet 2.0, and the Real Truth finally hit me: people have been dumb as a fencepost all along. The Internet just made it obvious.
Look around you: the utter stupidity of our own species will be our undoing.
HELP STAMP OUT STUPIDITY!
In IPv6 every atom (at least - possible even the sub-atomic particles) can have an IP address, right?
DNS servers that actually serve DNS requests. Yes DDOS attacks are a problem, but so are DNS servers that don’t d anything. Agian, very few that appear to be a real problem.
Cameras are an issue, but it s pleasantly surprising there are only two public.
A few people have pen printers. One can imagine use cases security by obscurity might be the best option. Who is going to print on a random printer. And the up address for my printer cycles way too often.
It is unclear why a website that answers to get request is a problem. That is what websites should do. A functional website should never return a 404.
"She's a scientist and a lesbian. She's not going to let it slide." Orphan Black
I hope that discovery wasn't shocking enough to give him a palpitation. If he scanned the rest of the world, his heart might shoot out the back of his underwear.
I really wonder how these things end up online, given that most consumer routers don't accept incoming connections by default. Are people really going out of their way to put this stuff on the open internet, or is something else going on here?
"First they came for the slanderers and i said nothing."
Seriously why the fuck is this an article? There are no revelations in this and this is nothing that anyone with half a clue is already fully aware of.
At a defcon talk in 2014 (talk slides) they scanned the whole IPv4 space live, looking for VNC instances. At least, anything that responded to a SYN packet.
Then they took a couple months to connect to each VNC instance, if no password was required, grab a screen shot.
Leading to a series of talks of things that shouldn't be on the internet.
09F91102 no, 455FE104 nope, F190A1E8 uh-uh, 7A5F8A09 that's not it, C87294CE no. Ah! 452F6E403CDF10714E41DFAA257D313F.
I am an American. Geographically challenged.
IT Professionals should know better.
It isn't the open DNS that causes the problem, (attack vector, attacker sends query to DNS with faked IP address, DNS sends back large packet of data 100 times bigger than query to faked IP, denial of service attack on faked IP address)... it's lack of DOS protection on the receiving IP address.
Open DNS is a good thing and should be encouraged.
We definitely only use the 1.000,000 (=1000) variant.
Also, our country name is written Luxemburg (or Letzebuerg with two dots above the e, in our native language). Not Luxembourg!
You have to understand our history to know why you can also use the other variant.
See, we are a tiny country that always was the firs to get overrun by enemy forces. And then we started hating them and bannning everything related to them.
And the last ones happened to be the Nazis. Which drove us a bit into a schizophrenic situation. Since we ourselves are a germanic country that just happened to not become part of Germany because it always used to be a tax haven, even back in the times of kings and queens.
We picked French as our new beloved dominant language and culture. Which is also silly because the French were what we hated before the Nazis, since Napoleon had invaded is before them.
But for those "reasons" we had French dominating here for decades. In parliament, i the press, in court, and at the supermarket checkouts.
It only started to get better in the late 80s. But French still dominates courts and is generally very fashionable and upper class. So of course the upper class likes everyone to use the French spelling of our country's name and the French decimal symbol and so on.
But in reality, every actually luxemburgish person on the street is still speaking a germanic language called luxemburgish (letzeburgesch). And English is of Germanic origin too. So we all should and do use the germanic version, no matter what the officials say.
Oh and fun fact: We have 50% immigrants now(!!!), and our country is working fine, with everyone getting along. Also if you have any clue as a company, you can manage to pay zero taxes, yet the budget is positive.
So it's not those things per se that ruin a country. It's how you deal with them.
In prison. Ask for a guy name Ripper. Every prison has a dude like that. And every pedo gets an introduction.
Tell him ole Ollie_Copter sent ya. You'll get a discount on your first five ... eh ... "pics and/or vids", oh and a 100% guaranteed reduction in the length of your prison stay. All free of charge of course because Ripper, he do like that!
Researcher uses shodan, news at 11
Fuck Off APK. No one wants to see a life size reproduction of your dick
These faggots seem to be at least 25 years behind the curve. These neophytes think they actually contributed something useful hahahaah
TRYING & FAILING @ "FRAMING ME", loser? That's not I you replied to but you KNOW that you pussy ass little freak punk, don't you!
* You're a SAD little nobody loser & you STALKING me by UNIDENTIFIABLE anonymous proves it.
APK
P.S.=> You're lucky I can't get ahold of you in the REAL WORLD fucker - you'd be one sorry fuckhead... apk
See my subject: I'll kick YOUR FUCKING ASS for stalking & harassing me you unidentifiable little cowardly cunt - tell me your REAL name, address, & phone # so I can verify it's REALLY you & we can settle this once & for all, fucker...
APK
P.S.=> Everyone SEES you constantly stalking & harassing me bitch, so WHO ARE YOU FOOLING but yourself - & IF I ever get to you? You'll WISH you were dead cocksucker... I shit you not! apk