기본 콘텐츠로 건너뛰기

A dumb security flaw let a hacker download US drone secrets

Sensitive files about the MQ-9 Reaper drone and M1 Abrams tank could be accessed because of an unpatched router. It was totally avoidable


A hacker used a basic security vulnerability to access highly sensitive files relating to the US military's spy drones and tanks, new research claims. Security firm Recorded Future says it discovered a criminal attempting to sell the secret information for only a few hundred dollars on a dark web forum last month. 
The documents, which were advertised at between $150 and $200, included technical details of the MQ-9 Reaper drone. The drone has been used for unmanned surveillance missions for the military and other organisations including border control. Maintenance manuals and a list of airmen who were assigned to work on repairs were allegedly being sold among a cache of classified data.




The information was exposed after two members of the US military connected to the internet through Netgear routers that still used the default log-in settings for file sharing. The bypass for the routers was first discovered two years ago and devices still vulnerable haven't had their firmware updated. 
Andrei Barysevich, a dark web expert at Recorded Future, says some of the documents were taken from the computer of an Air Force captain working at a base in Nevada. "Another thing he [the hacker] was claiming to have access to was a broad range of live CCTV cameras, including those installed on surveillance planes and across the US-Mexico border and checkpoints, highways, and the drone that surveys the Gulf of Mexico," Barysevich says. 




One of the files exposed was a certificate saying the captain had successfully completed cybersecurity training. A second member of the military was also impacted, with maintenance documents for the M1 Abrams tank and details of how to defend against improvised explosive devices (IEDs) being put up for sale. 
The files were advertised for sale on a dark web forum, Recorded Future says, though the firm believes nobody purchased the documents. Recorded Future would not provide the username of the alleged hacker or the forum that the details were being advertised on. Barysevich says the firm is continuing to work with law enforcement.

WIRED contacted the US Department of Defense for comment on supposed documents and details but had not received a response at the time of publication. Barysevich says he is "pretty much 100 per cent certain" the documents being advertised for sale were genuine.
The security researcher says he began talking to the hacker on the dark web forum but moved to an encrypted messaging app to be provided with screenshots of sample documents. These included potential images from drones and technical documents for other military equipment.
"Pretty much immediately after we reached out to law enforcement and passed information to the airforce, he deleted the advertisement saying he lost access to the vulnerable system," Barysevich says. He doesn't know how much of the data was downloaded by the hacker as it was claimed the person had a poor internet connection and low bandwidth. As a result, they allegedly didn't download everything which was available until a buyer had been found.




The incident is the latest case of insecure routers leading to security vulnerabilities. Barysevich says the hacker scanned the Shodan search engine, which shows internet-connected devices, for Netgear routers that may not have had their default details updated. 
Once a device has been located it can be accessed remotely and the File Transfer Protocol system could be accessed using the username 'admin' and password 'password'. Recorded Future says its scan of Shodan revealed 4,000 devices that could be compromised using the method. This is down from 6,000 when the problem was first reported in 2016. Shodan searches only show devices that are currently active and connected to the internet.
In April this year, cybersecurity officials in the UK and US issued a joint warning to individuals and businesses highlighting their belief that routers – as well as other technical equipment – were being compromised by Russian hackers. Millions of devices had been targeted through man-in-the-middle attacks and intellectual property could have been stolen. The routers were being targeted to "potentially lay a foundation for future offensive operations".
Separately, malware that's been dubbed VPNFilter has been found in more than 500,000 routers. The malware, which was first discovered by Cisco’s Talos security team, has the potential to completely shutdown the router and kill its internet connection. "The behaviour of this malware on networking equipment is particularly concerning, as components of the VPNFilter malware allows for theft of website credentials," Cisco wrote as it published details of the malware in May this year. 
In the most destructive incident so far, routers and other Internet of Things devices were used as part of a mass botnet that temporarily took down the internet for millions of people in October 2016
The continuing vulnerabilities in routers show how fragile connected devices can be. "He was abusing this system and method on a daily basis," Barysevich says of the hacker who targeted the US military. "He told us he scans Shodan for new victims and then spends the entire day dong from system to system to see if anything of any value could be obtained." It is claimed documents from a cryptocurrency company, a medical practice, a supply chain provider to oil and gas provider were all exposed using the same method. "He didn't know the true value of this data," Barysevich says.

 Wednesday 11 July 2018

댓글

이 블로그의 인기 게시물

BLACK LABEL Secured Automobile Smart Key Solution

Developed by MERCEDES BENZ for the first time 20 years ago, the SmartKey has been very convenient for motorists. However, since this technology has been applied so far, the smart key security has not been upgraded so that even if a simple wireless hacking device is purchased on the market, the password which is exchanged between the car and the smart key is wirelessly captured, the car door is opened, Things are happening in a random way. The biggest problem in smart key security so far is that the identification code exchanged between the smart key and the key is a fixed value and the security is difficult to hack the fixed single code value. However, if a mutual verification system, which is a security solution of BLACK LABEL, is applied to a smart key and a vehicle, it is impossible to access the vehicle even if the identification code value is fixed in a single code, Can be made. This is because the code that has been changed once and then discarded is discarded. ...

Avoiding Cryptocurrency Scams

The Money Makers Club now has 6 of 15 available seats. Learn more here! Everyone is always focused on the potential upside of buying cryptocurrency, but they forget there are always going to be hidden downsides as well. The downside risk of investing in cryptocurrencies is huge. Not only do you need to worry about the high volatility of these assets, but you also need to bear in mind that theft is always a possibility, and the assets are poorly regulated.  Lack of Regulation Creates Opportunity for Thieves In the equity and debt markets, there are stringent controls on the way capital is invested and the rules that govern investors. The goal is to protect investors from any fraud or wrongdoing, and even though there are times where it takes regulators longer than normal to catch on (see: Bernie Madoff), the general effect is a safer investment marketplace.  Fraud can occur in a variety of ways. It can be the result of false claims by the company regarding the s...

BLACK LABEL IoT SECURITY SOLUTION, MUTUAL VERIFICATION SYSTEM

Black Label's security solution is a mutual verification system, which is a personal identification security solution through mutual verification between SIM and identity authentication server. Among existing wireless communication networks, a mobile communication network using a USIM, which is a personal identification device, is considered to be most secure against hacking. This is because the USIM card has a personal identification code, including the user's mobile communication number, so it sends and receives a telephone call or message after authentication. BLACK LABEL has developed a security solution called "Mutual Verification System" by utilizing the characteristics of SIM and enhancing the disadvantages of the personal identification process to enhance the personal identification security. The mutual verification system is a system that sends and receives personally identifiable information to the authentication server by infinitely changing the i...