6 ms·
A Rogue Raspberry Pi Let Hackers Into JPL Network
- kevin_b_er 7y agoIt would be nice to know what this specific "Raspberry Pi" vulnerability is, considering the software stack is almost entirely Debian.
- blacksmith_tb 7y agoNot impossible to imagine the credentials were the unchanged default pi/raspberry... (I imagine quite a few people who haven't done much w/ a Pi don't even run raspi-config) I assume you can scan for similar exposed RPis with Shodan etc.
- jeroenhd 7y ago> The comprehensive federal review of JPL’s systems stemmed from an April 2018 incident when someone at JPL attached the Raspberry Pi to the network there for an unknown purpose Basically, someone plugged in a computer to the corporate network that happened to be a Raspberry Pi. Might as well have been a Beaglebone, a Banana Pi or an Intel NUC for that matter.
- jvanderbot 7y agoJPL builds robots and robots are made from SBCs.
- chaboud 7y agoIf JPL is using a Pi off of Earth, they're doing it wrong. Stability in space requires a little more care (it's hot, cold, particle-y, etc).
- BubRoss 7y agoNo one said anything even remotely close to that.
- jvanderbot 7y agoAs TRL progresses, the hardware changes. Nobody buys RAD750 for each of their new ideas.
- syn0byte 7y agoThere is no RPi vulnerability(in this article). The RPi was just used as a bastion into the internal network. It could have been any SBC. Once your already inside the internal network things get stupid lax. EG. I can't see your Windows shared folders from the internet, but the PC in the next room can. Someone sneaked an RPi into JPL to be that PC in the next room. See Also; Season 1 Mr Robot had this exact scenario as a plot point.
- giancarlostoro 7y agoI was thinking Mr. Robot the whole time.
- jvanderbot 7y agoNo, they infiltrated a Rpi already on the network (e.g. a research SBC) which itself was also able to access other machines.
- inamberclad 7y agoProbably just ssh enabled with the default credentials. IIRC, raspberry pis have their own MAC address prefix, so it's pretty obvious when you find one.
- deleted 7y ago[deleted]
- fortran77 7y agoMy guess is this pi was connecting _out_, tunneling the network over ssh. Or one of these things: https://blog.haschek.at/2018/the-curious-case-of-the-RasPi-in-our-network.html https://blog.haschek.at/2018/the-curious-case-of-the-RasPi-i...
- NikkiA 7y ago> If, however, they represented an adversarial nation, the data could be extremely valuable. Yes, heaven knows that data on manned spaceflight shouldn't be shared with all of mankind, only america and it's allies.
- exabrial 7y agoOr you know, lobbing ballistic warheads at some other country you've been at war with for literally centuries.
- astazangasta 7y agoWhat country is that?
- ashildr 7y agoEastasia.
- drivingmenuts 7y agoIt would probably be more along the lines of altering the re-entry characteristics of a manned space flight, you know, for lulz. Or nationalism. Or it’s Tuesday. Or whatever other Hal-baked rationale they can come up with. Guaranteed there’s someone out there jackass enough to do that.
- jascii 7y agoThe actual OIG report: https://oig.nasa.gov/docs/IG-19-022.pdf https://oig.nasa.gov/docs/IG-19-022.pdf I only did the briefest of scans, but the recommendations seem pretty basic best practices stuff. In my experience, research labs tend to be creative spaces with a focus on collaboration and information security is not foremost on peoples mind. I guess that will have to change.
- jascii 7y agoIt's kind of interesting to read in the report how the JPL was not compliant with several NIST guidelines (800-53 and others) what it does not mention is how this situation persisted despite the required audits for federal organizations..
- molecule 7y agoThere’s a significant distinction between federal organizations and federally-funded organizations— JPL is the latter.
- ozim 7y agoRecommendations suck, they just write couple of times that administrators should update "Information Technology Security Database" and that they failed to do that. That should be automated. They have all those "CISO", "SAISO", "OCIO" and "CIO" but there is no one who knows how to setup automated nmap scan for a network range? Then trigger someone and add it to some inventory like "hey there is some new raspberry pi in network" should you maybe check it?
- Avamander 7y agoIt's not like you can easily detect a rogue RPi with just nmap. It's trivial not to respond to anything sent to you. You have to start looking at ARP, but that's not iron-clad either.
- emilburzo 7y agoarpwatch worked pretty flawlessly when I needed something like that https://en.wikipedia.org/wiki/Arpwatch https://en.wikipedia.org/wiki/Arpwatch
- Canadauni 7y agoThe article mentions that the hackers stole 500MB? The number seems small given the scale of storage in modern computers but I guess 500MB could account for a large number of documents that contain confidential info.
- Kenji 7y ago500MB of leaked credit card information is a lot. 500MB of leaked video is little. It all depends on the contents.
- kryogen1c 7y ago>5,406 unresolved SPLs—about 86 percent of which were rated high or critical >JPL did not effectively address a known software vulnerability, first identified in 2017, with a critical score of 10. This software flaw can be used by cyberattackers to remotely execute malicious code >one of the projects has a waiver of JPL IT security requirements to change passwords every 90 days. Instead, the project relies on a designated application and team accounts to share password files, group files, host tables, and other files over the network There seems to be a fair amount of filler in the report (review access logs, out of date inventory, etc) but these points seem pretty damning.
- blantonl 7y agoIf I was a betting man, I'd bet that there are some old dusty areas of NASA facilities where there are open NFS exports, NIS providing security, and Sun workstations doing work. I bet someone could fire up a SATAN scanning instance with a Mosaic browser and find some open stuff on some of those old and crusty computers. :)
- carroccio 7y agoThanks for making me remember Saint and Satan times! Also Nessus was open source.
- Something1234 7y agoCan we get more details about this Satan thing?
- dredmorbius 7y agoSecurity Administrator Tool for Analyzing Networks (Or, if you repent, SANTA.) https://en.wikipedia.org/wiki/Security_Administrator_Tool_for_Analyzing_Networks https://en.wikipedia.org/wiki/Security_Administrator_Tool_fo...
- Something1234 7y ago
- Mbaqanga 7y agoThe articles says if the hackers were some jokers on the internet then the data isn’t terribly useful, but if it was an adversarial nation then it is very useful. Why? Can’t the jokers sell it to other nations?
- DataJunkie 7y agoI am surprised this doesn't happen more often.
- noir-york 7y agoThe report doesn't mention how the intrusion was discovered. Someone just noticed the RPi one day? 500mb traffic to a Chinese IP?