IoT Devices Enslaved Via 12-Year-Old OpenSSH Flaw
Attackers are enslaving Internet of Things (IoT) devices to remotely mount DDoS campaigns, by using a 12-year old vulnerability in OpenSSH.
Akamai Technology researchers Ory Segal and Ezra Caltum have dubbed the issue the SSHowDowN Proxy.
It’s not a new type of vulnerability or attack technique, but rather a continued weakness in many default configurations of internet-connected devices. But a broad range of devices are being exploited in mass-scale attack campaigns, including CCTV devices for video surveillance, DVRs, satellite antenna equipment, routers, Wi-Fi access points, cable and ADSL modems, internet-connected Network Attached Storage (NAS) devices and more.
This malicious network is mounting attacks against a multitude of internet targets and internet-facing services, such as HTTP, SMTP and network scanning, and against internal networks that host the connected devices. Once malicious users access the web administration console, they have been able to compromise the device’s data and, in some cases, fully take over the machine.
“We’re entering a very interesting time when it comes to DDoS and other web attacks; ‘The Internet of Unpatchable Things’ so to speak,” explained Segal. “New devices are being shipped from the factory not only with this vulnerability exposed, but also without any effective way to fix it. We’ve been hearing for years that it was theoretically possible for IoT devices to attack. That, unfortunately, has now become the reality.”
本文系统（linux）相关术语:linux系统 鸟哥的linux私房菜 linux命令大全 linux操作系统
本文标题：IoT Devices Enslaved Via 12-Year-Old OpenSSH Flaw