2 ms·
Generally the devices poke holes in the firewall with UPnP. There are also other vectors (ZeroConf, STUN, CWMP). The problem is that, once past the firewall, m
by s_q_b 10y ago
Generally the devices poke holes in the firewall with UPnP. There are also other vectors (ZeroConf, STUN, CWMP).
The problem is that, once past the firewall, many of these devices have weak to no security, e.g. open telnet daemons, root:root default user/password, and other trivial vulnerabilities.
- rudolf0 10y agoThe real confusing part is why this didn't happen earlier. Or, more likely, it did happen earlier but the attackers weren't properly weaponizing or "botkilling" / patching the devices?
- s_q_b 10y agoThere were some worms spreading through IoT devices, lots of foreshadowing. The Hajime and Mirai worms, combined with the utter lack of response, were a pretty good indication some shit was about to go down. I've been Cassandra yelling into the wind on this one for a while, so there is some schadenfreude involved for me.