13 ms·
Port scanning /0 using insecure embedded devices
- agnokapathetic 14y agoWould be awesome if this was an S3 public dataset (http://aws.amazon.com/datasets http://aws.amazon.com/datasets)!
- jstanley 14y agoVery awesome. I have some concerns about the legality of this. Has anyone tried to sue you?
- EvanAnderson 14y agoThis is technically interesting and clearly a cool hack, but it leaves a really bad taste in my mouth. It would be one thing to report on the large number of insecure embedded devices attached to the Internet, but it's another thing to actually use other peoples' devices without their permission-- especially at this kind of scale. HD Moore's DerbyCon presentation last year (http://www.youtube.com/watch?v=b-uPh99whw4 http://www.youtube.com/watch?v=b-uPh99whw4) showed that scanning the entire Internet without resorting to using other peoples' devices to perform the scanning is technically feasible and produces good results. The dataset for scanning for even a fairly large set of applications isn't tremendously large.
- jervisfm 14y agoThis is some interesting research. I am wondering though: Does anyone know whether there are any potential legal issues with scanning devices / networks that do not belong to you ? Is it possible for you to get into trouble in engaging in this activity?
- awda 14y agoAs someone who has scanned e.g. all of 24.0/8 from a work machine, you do get angry emails to abuse@<your-reverse-dns-name>. I don't think there are legal issues here -- these are all public services on the internet. But installing software like the author did is legally problematic.
- achillean 14y agoIt's legal to port scan networks you don't own (from a US perspective), though logging in and/ or performing changes to the device are definitely not. As another person has mentioned, you will get a lot of abuse emails but there's nothing illegal about port scanning by itself. Source: I run Shodan (http://www.shodanhq.com http://www.shodanhq.com)
- trotsky 14y agoIt's almost always against the terms of your provider's AUP.
- wmf 14y agoThat's why you do the scanning from someone else's router. :-)
- epoxyhockey 14y agoEthics discussion aside, it is really cool to hear about a massive project that a single person performed in secret. I see all of these job listings for "big data" projects with hot startups and here is 1 guy generating a billion records in 1 hour, for fun. It kind of reminds me of the MIT students' Stealing Profits from Stock Market Spammers presentation, because they waited 3 years before talking about it. Source: http://defcon.org/images/defcon-17/dc-17-presentations/defcon-17-grant_jordan-stock_market_spam.pdf http://defcon.org/images/defcon-17/dc-17-presentations/defco... (video is also on the website)
- GFischer 14y agoThat presentation makes for really interesting reading, thanks for sharing.
- joosters 14y ago"We had no interest to interfere with default device operation" ... "After a reboot" ... How does rebooting someone's computer not count as 'interfering'? Let's hope none of those machines were doing anything important.
- zerd 14y agoThey didn't say they rebooted any devices. They said that they didn't make the binary persist through reboots. They probably installed their binary in /tmp/ or similar which would get wiped if the device happened to reboot.
- joosters 14y agoThat's unclear. From their use of the past tense, it certainly implies that the machines had been rebooted.
- uribs 14y agoInteresting, maybe we should revoke IPv4 assignations to Apple, Ford, HP, Prudential etc. who aren't using anything close to the 16 million IP addresses they have.
- ISL 14y agoIt's probably easier to switch to IPv6; then everyone wins.
- wmf 14y agoIn some cases those addresses are used but they are NATed behind different public IP addresses. (No, we can't use 10/8.) But now that each /8 is worth almost $200M, just wait for a slow quarter and those addresses may find their way to people who need them.
- Hoff 14y agoSure, NAT and a few more blocks will help. For a while... With the recent IPv4 address burn rate — the allocation rate the last remaining addresses block were issued — reclaiming a half-dozen /8 blocks would be a rearguard action at most, and an effort and a hassle that would detract from IPv6. For data, select the column with the IANA date sort here: http://en.wikipedia.org/wiki/List_of_assigned_/8_IPv4_address_blocks http://en.wikipedia.org/wiki/List_of_assigned_/8_IPv4_addres... and then consider how long a few more added /8 blocks would really last. By my count, fourteen /8 blocks since 2009. And the rate that network-connected devices are arriving isn't slowing.
- deleted 14y ago[deleted]
- joosters 14y agoI wonder how many of the 420,000 machines they ran their code on got screwed up by them? As anyone who's tried to manage a cluster of machines knows, it's a pain to get everything working. Even when you have complete control over the hardware, software and network, distributing code to the cluster and making the cluster send stuff back is difficult. So much can go wrong and it is easy to take out servers with what seems like the most trivial of mistakes. Now try doing this with almost half a million machines, of unknown hardware, already running unknown software, and operating in network conditions that you have no idea about. Do you think they did it perfectly and nothing went wrong? They undoubtedly broke or disrupted many computers and systems here, and they know it. They can write all the weasel-words they like about how nice and kind they were, but I am sure they broke a lot of people's systems (some of them, by their own admission, running important services).
- MertsA 14y agoBut honestly it would be pretty hard to break it beyond what a reboot would fix. Most of those embedded devices probably don't have a persistent /tmp directory and even if they did the only chance of really screwing it up would be if that 45 - 60 kb binary took up enough space to break something. It seems pretty unlikely and even then I'd consider it a net positive because then someone notices the device with root exposed to the world.
- pixl97 14y agoWhile the researchers have no moral high ground to stand on here, neither do the 420,000 people (or whatever division of that is owned by separate groups) that are running insecure devices. I've messed up and put insecure stuff on the internet before. I'd rather have it go down and break in a fire rather then having it quietly ship personal information to (feared country of choice). If you put an insecure device on the internet, the damage that ensues is your fault. Ignorance cannot be an excuse. Default passwords and no passwords are just unacceptable. Yes, by some twisted logic you can blame the hacker, but as time goes on we see more and more state sponsored attacks. It is their job to hack in to equipment of other nations for various reasons. It is your job to keep that from happening. TL;DR There is no such thing as a trivial mistake on a public network.
- jbuzbee 14y agoInteresting, but let's see. Where have I heard about how the Feds (over)react to gaining unauthorized access to someone else's computer? Hmm... http://www.wired.com/threatlevel/2013/03/att-hacker-gets-3-years/ http://www.wired.com/threatlevel/2013/03/att-hacker-gets-3-y...
- tlrobinson 14y agoThis is awesome and terrifying. What would happen if (when?) someone with more evil intentions decides they would like a 420,000 device botnet of their own? Or how much damage could one do by shutting off all these devices simultaneously?
- hcarvalhoalves 14y ago> What would happen if (when?) someone with more evil intentions decides they would like a 420,000 device botnet of their own? You think massive botnets don't exist already? > How much damage could one do by shutting off all these devices simultaneously? The only reason this haven't happened so far is because there's no profit in this. There's more money to be made keeping a low profile and spamming / phishing.
- duskwuff 14y ago> What would happen if (when?) someone with more evil intentions decides they would like a 420,000 device botnet of their own? If you read into the details, you'll realize someone else already did: the Aidra botnet. The author spotted them pretty quickly, and took some steps to prevent their spread.
- BoyWizard 14y agoUploading and running executable code on other people's devices without their permission is absolutely illegal, regardless if it's exposed or not. I would be pissed if someone did this on any of my devices.
- pixl97 14y agoI'd be pissed at myself for running an no password/default password on the global internet that is connected to nations that we (as in my nation) consider enemies.
- contingencies 14y agoNationalism is an infantile disease, the measles of mankind. - Albert Einstein Pro tip: Get with the post-nationalist, internet-enabled program and give up on this line of thinking.
- pixl97 14y agoThe world is full of fundamentalists that are not, trufax.
- Retric 14y agoIt's only by growing up in a county that does an amazing job that you end up with the stupid idea that countries are unemportent. Hint other people want your stuff and somebody needs to protect it. PS: Some people where shocked that Greece defaulted ignoring. "Greece faced economic hardships and defaulted on its loans in 1826, 1843, 1860 and 1893." Why? Because as nation they can get away with it do why not?
- contingencies 14y agoAcknowledging that nations still have political, legal and economic significance is common sense and is not nationalism. Worldview from some assumed national perspective = nationalism. For example, viewing the entirety of the global internet in terms of the fact that certain other countries (that may be nominal enemies of 'your' (hah!) country) are connected to it.
- est 14y agohttp://internetcensus2012.bitbucket.org/images/clientmap_16to9_small.jpg http://internetcensus2012.bitbucket.org/images/clientmap_16t... Next time if a Chinese IP hacks you, it a botnet node in China hacked you.
- nonamegiven 14y agoJudging from the map it looks like North Korea has managed to protect itself quite nicely.
- scotty79 14y agoUSA has strangely different usage patterns. Usage decreases in the evening so peek seems to be during work hours. Americans work a lot, I'm sure almost all of that internet use is productive and they just prefer having fun outside after work.
- metalruler 14y agoThis is a way cool idea. Probably not the best thing to happen to the internet on a daily basis, but an amazing project nevertheless. Just waiting for someone to start mining bitcoins on 420,000 slightly underpowered CPUs... (Ok, seriously now.) The traceroute data could be used to build an interesting map of the internet. I'm sure there's lots of cool things that can be done with what has been released.
- pak 14y agoIsn't this exactly what rtm did in 1988? The only difference is that this worm took pains to behave more nicely. Funny to see that the proportion of relatively unsecure devices on the internet has not gone down since that time.