Showing posts with label IoT Danger. Show all posts
Showing posts with label IoT Danger. Show all posts

This Anti-Mirai Tool Makes Your IoT Device Hack Proof

In October, we reported a story about how IoT device owners all around the world needed to be beware of Mirai, the malware, that had single-handedly been responsible for causing one of the worst distributed denial of service (DDoS) cyberattacks that the world had experienced in the last few years, and how it had now managed to spread and infect internet-connected devices in over 177 countries all around the world.

Mirai is so powerful a malware that it had successfully managed to take down Spotify, Twitter, and a number of other so-called high security websites. And since October, there has been no stopping Mirai's growing pace. But now, a new security tool has been developed that has the potential of letting IoT devices owners know if their devices are vulnerable to Mirai's vicious attack.

In the past, the malware has been used in distributed denial of service (DDoS) attacks. Mirai is basically works by scouting for insecure Internet of Things devices, and once that is done, it uses them as bot-nets to do its bidding. And since the malware’s source code has already been leaked, it can used by basically anyone to use/misuse.

Mirai was successful in causing massive outrage in October when it targeted Dyn, a major name in the domain name service (DNS) provider sector. The case saw Internet of Things being put to use to break the internet.

Seeing the havoc that Mirai had managed to achieve and was still causing, Imperva decided to do something about the situation and was successful in determining a way to know if the IoT devices were vulnerable to malwares like Mirai. The best thing is, one doesn't have to buy or install anything to use it -- all that one has to do is to visit the scanner website on the device that you want to check. The scanner then comes to action and analyses the IP address, smart products details used for internet access.

This is how the Mirai scanner works:

this-is-how-the-scanner-works

1) Initiate a scan request.
2) Once scan request is initiated, the scanner comes to action and looks for connected devices on ports 22/23.
3) The third step involves the scanner testing if a device can be accessed with passwords from Mirai's dictionary.
4) The scan results are finally furnished.

The main issue here is that the scanner can’t do much about the affected devices themselves. If during a scan, one of your connected devices comes out to be vulnerable to Mirai, an immediate step that you should take is change its login credentials from the ones set by the manufacturer by default. If somehow that isn’t possible, or if you don’t know how to do it on your own, you will have to make a quick decision on whether you intend to put your device at risk or just simply stop using it altogether.

Malware like Mirai are the reason that security experts all around the world fear the growing popularity of the Internet of Things.

Read More - https://www.incapsula.com/blog/mirai-scanner-unwitting-mirai-botnet-recruit.html

[Top Image - Shutterstock]

Cheap IoT Threatens The Global Internet

The world of Internet of Things (IoT) has opened us all to a world where we now have the power to automate, protect, and monitor our houses like never before. Not only this, one can now keep an eye on their children while out for work, integrate their home theater system, protect the house from theft, and even extend a helping hand in reducing capital spent on energy consumption. IoT has for sure made all this possible, but like every coin has two sides IoT too has a dark side.

While on one hand, IoT has made our life easier, on the other hand, cheap IoT has the potential of threatening the entire of the Internet and causing a major havoc.

Finished IoT products most often end up in the hands of technically unsophisticated consumers who often end up ignoring the updates or at times even forget their logins and passwords. In order to take care of these aforementioned situations, the module makers have designed a quick fix, a login/password combination that allows the tech support of that particular IoT device to remotely take control of the device and make the users happy again.

However, hackers end up taking an advantage of this arrangement. By putting standard Linux dissection tools to use, they start browsing the embedded software module and successfully find the backdoor password set up by the module makers…which they then use to unlock all of the IoT devices from the maker. Recently, we covered a story about how Mirai — a malware that had been responsible for causing one of the worst denial of service cyberattacks that the world had experienced in the last few years, had now spread and infected internet-connected devices in over 177 countries all around the world.

The pirates have quite literally taken over the ship. They end up uploading software to one's device and then turn it into a dangerous weapon that is an inclusive part of a DoS attack.

The brain behind the hacker isn't targeting an individual or an individual's phone, but the target is actually a political website that might have rubbed on negatively with the hacker, or, with increasing frequency, a site that the pirates aspires to hold for ransom.

What is even more terrifying is that these attacks have also managed to hit the Internet infrastructure services such as DNS (Domain Name System) servers.

The bottom line here is to understand the looming threat that cheap IoT devices represent. This can easily be considered as a crucial side effect of the smartphone revolution. Billions of smartphones have resulted in creation of an ecosystem of distributors, manufacturers, and components that are all engulfed in a competitive race to the bottom. This has further led to corners being cut, and an untold numbers of vulnerable devices are now lying in wait on the World Wide Web. A couple of years ago, no one could imagine that one day these very so-called “security” cameras would be hampering our security as they land in the dangerous hands of hackers.

[Top Image-v3.co.uk]

Market Reports

Market Report & Surveys
IndianWeb2.com © all rights reserved