【】
It sounds like a sci-fi movie. Over 5,000 connected devices, including light bulbs and vending machines, were hacked to slow internet service at a university to a crawl.
Poorly secured internet of things (IoT) devices have become gold mines for hackers looking to launch DDoS attacks to take websites and services offline. But this latest case, detailed in Verizon's Data Breach Digest 2017, is the rare example of gadgets attacking their own network.
SEE ALSO:Your smart fridge is about to make our IoT security nightmare so much worseThe devices were making hundreds of Domain Name Service (DNS) lookups every 15 minutes, causing the university's network connectivity to become unbearably slow or even inaccessible.
Weirdly enough, the majority of the searches "showed an abnormal number of sub-domains related to seafood," the report said.
Here's an abstract from the Digest'ssneak peek:
The firewall analysis identified over 5,000 discrete systems making hundreds of DNS lookups every 15 minutes. Of these, nearly all systems were found to be living on the segment of the network dedicated to our IoT infrastructure.
With a massive campus to monitor and manage, everything from light bulbs to vending machines had been connected to the network for ease of management and improved efficiencies.
While these IoT systems were supposed to be isolated from the rest of the network, it was clear that they were all configured to use DNS servers in a different subnet.
Of Botnet and seafood
It's very unlikely, to use an understatement, that thousands of students at the university had a sudden and simultaneous urge to eat seafood.
Instead, what did happen was that cheeky hackers instructed the IoT devices to make DNS lookups related to seafood every 15 minutes.
Here's what Verizon's RISK (Research, Investigations, Solutions and Knowledge) team told the university after they were summoned to investigate the attack:
The RISK Team had provided me with a report detailing known indicators found in the firewall and DNS logs that I had sent over earlier. Of the thousands of domains requested, only 15 distinct IP addresses were returned. Four of these IP addresses and close to 100 of the domains appeared in recent indicator lists for an emergent IoT botnet.
So here's the case of vending machines and lamp posts compulsively searching for seafood and overwhelming the network with requests with the aim of taking it down.
If this isn't creepy/dystopian/fascinating, we don't know what is.
Stopping the wildfire from spreading
Luckily for the guys at the university, there was no need to replace "every soda machine and lamp post".
The Verizon's RISK team explained that the botnet "spread from device to device by brute forcing default and weak passwords".
To solve the massive hack, the university intercepted a clear-text malware password for a compromised IoT device and then used "that information to perform a password change before the next malware update".
Easy, right?
Overall, it doesn't look like this problem is going away anytime soon. There are more than 6 billion IoT devices currently running, according to Gartner Research. That number could reach more than 20 billion by 2020.
Featured Video For You
What Is the Internet of Things?
TopicsCybersecurity
相关文章

Dramatic photo captures nun texting friends after Italy earthquake
The image of an injured, bloodied nun, calmly texting friends and family in the wake of the deadly e2025-12-18
咳嗽是很常見的疾病,對於比較嚴重的咳嗽通常是需要通過及時的吃藥才可以治愈,輕微的咳嗽其實是可以通過食療的方法來治療的,比如可以喝梨水來治療咳嗽,不過梨子的種類是很多的 ,有些梨子是具有止咳的作用,有些梨2025-12-18
蝦仁和苦瓜在平時都是很常見的食材,不過二者的營養價值都是很高的,經常食用的話,對身體健康的好處是很多的 ,蝦仁大家都知道,蛋白質的含量是很高的 ,苦瓜雖然吃起來比較哭,但是營養物質是很豐富的 ,如果將蝦仁和2025-12-18
Beyoncé's 'Cowboy Carter': social media reactions
Since Beyoncé announced a new album during her Super Bowl commercial — in pink cat ear2025-12-18
Tributes flow after death of former Singapore president S.R. Nathan
The Singaporean government has announced that former president, 92-year-old Sellapan Ramanathan (wid2025-12-18
關節部位在被扭傷以後是必須要記住冷敷,這個時候如果是熱敷會出現適得其反的效果 ,還要注意在冷敷的時候不要讓冰塊直接接觸到自己的皮膚 ,這是會讓皮膚出現凍傷的反應 ,等到冰敷好以後就要讓自己受傷的患處得到充分2025-12-18

最新评论