Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

For The First Time, Hackers Have Used A Refrigerator To Attack Businesses
Business Insider ^ | January 17. 2014 | JULIE BORT

Posted on 01/17/2014 6:19:17 AM PST by MeshugeMikey

Security researchers at Proofpoint have uncovered the very first wide-scale hack that involved television sets and at least one refrigerator.

Yes, a fridge.

This is being hailed as the first home appliance "botnet" and the first cyberattack from the Internet of Things.

(Excerpt) Read more at businessinsider.com ...


TOPICS: Computers/Internet
KEYWORDS:
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-75 next last
To: MeshugeMikey
people regularly ask why I don't upgrade my phone…

And your answer is…?

41 posted on 01/17/2014 8:44:21 AM PST by doc11355
[ Post Reply | Private Reply | To 38 | View Replies]

To: MeshugeMikey

Guess I’ll continue to nurse my 25+ year old fridge. That reminds me, it needs the drip bucket at the bottom and on the inside dumped.


42 posted on 01/17/2014 9:00:50 AM PST by bgill
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger
Soon, your toaster will be spying on you!


43 posted on 01/17/2014 9:26:55 AM PST by Bloody Sam Roberts ("The further a society drifts from truth the more it will hate those who speak it." - George Orwell)
[ Post Reply | Private Reply | To 4 | View Replies]

To: fuzzylogic

The article doesn’t talk about a trojan horse with these devices it talks about spamm emails sent from the devices, ergo the premise WiFi was unsecured. If the WiFi was secured the hackers’ entry point from the internet would not have been able to get into the premise WiFi network to obtain and use the network ID of these devices to send their spamm emails out the premise WiFi/router’s internet connection. If some of those network IDs are ‘toaster[unique ID]@usersISP.com’ so what. It still gives the spammer an email address to use and that’s all they care about.

And even if the appliance had trojan hardware (like the irons in Russia) it still requires an unsecured, DHCP-enabled WiFi LAN to get out to the internet and contact the hacker to enable the exploitation of the LAN and its devices.

The attack goes something like this:
Get users’ IP address off message boards, ISPs, etc. Scan the subnets looking for an unsecured or default password premise modem/routers supplied by the ISP (which they know the default passwords for). Access the unsecured router to get a list of LAN IDs. Use those IDs to send traffic to the premise router to send out their spamm emails. That way the emails orginate from non-blocked domains and known spammers.

There is more to it but there are plenty of ways to avoid your appliances getting cease-and-dissist email from your ISP. Setting a password on the ISP router/modem, disabling ISP email and blocking the router’s port 25 are a few simple ways.

It’s just spammers looking to get around their notariety to ISPs and security programs. They need an innocent ISP account (and router) to send their spamm.


44 posted on 01/17/2014 9:40:22 AM PST by Justa
[ Post Reply | Private Reply | To 39 | View Replies]

To: fuzzylogic

WiFi-enabled devices and WiFi-enabled ISP routers typically are preset for DHCP. On an unsecured WiFi network the new WiFi appliances will auto-join the local network. No user action required. This is what the hackers are looking for. The fridge just provides an additional email account to send their spamm out the WiFi router.

And the “business hacking” is most likely a business complementary WiFi for their customers in the waiting room. Like Joe’s Auto Repair w/free WiFi. They don’t secure it because they’d then have to setup every user. Even though their WiFi network is only a network access point their WiFi-enabled appliance has a network ID to exploit for spamming. In this case the fix is to block everything on their premise router but what’s needed for their customers (port 80, 443, etc.) particularly the mail ports (24, 25, 57, 109, 110, etc.).


45 posted on 01/17/2014 10:03:35 AM PST by Justa
[ Post Reply | Private Reply | To 39 | View Replies]

Comment #46 Removed by Moderator

Comment #47 Removed by Moderator

To: MeshugeMikey
how to encrypt those frozen Chocolate Cream Pies?

"I'm sorry, Dave. I can't let you have that beer.
Would you like a carrot stick?"

48 posted on 01/17/2014 11:05:59 AM PST by Flick Lives (Got a problem with the government? Have a complaint. Get a free IRS audit!)
[ Post Reply | Private Reply | To 7 | View Replies]

To: PapaBear3625

I know someone with an expensive bed that shows up as a wi-fi network... very strange


49 posted on 01/17/2014 11:09:56 AM PST by GeronL (Extra Large Cheesy Over-Stuffed Hobbit)
[ Post Reply | Private Reply | To 3 | View Replies]

To: null and void

You beat me to the Toaster jokes.


50 posted on 01/17/2014 11:12:48 AM PST by Cyber Liberty (H.L. Mencken: "The urge to save humanity is almost always a false front for the urge to rule.")
[ Post Reply | Private Reply | To 13 | View Replies]

To: Flick Lives

Hal? HAL?


51 posted on 01/17/2014 11:21:59 AM PST by MeshugeMikey (This Message NOT Approved By The N.S.A.)
[ Post Reply | Private Reply | To 48 | View Replies]

To: Lazamataz
Not a joke. In the UK they have floated the idea of handing out "calorie cards" to ration your food. See my tagline, watch the propaganda videos.

Without a doubt, they will do this if they are allowed to continue unobstructed.

52 posted on 01/17/2014 12:16:44 PM PST by riri (Plannedopolis-look it up. It's how the elites plan for US to live.)
[ Post Reply | Private Reply | To 17 | View Replies]

To: riri
Not a joke. In the UK they have floated the idea of handing out "calorie cards" to ration your food. See my tagline, watch the propaganda videos.

England does not want me.

I'd kick up quite a fuss.


53 posted on 01/17/2014 12:22:54 PM PST by Lazamataz (Early 2009 to 7/21/2013 - RIP my little girl Cathy. You were the best cat ever. You will be missed.)
[ Post Reply | Private Reply | To 52 | View Replies]

To: null and void

Hmmm is this where The Brave Little Toaster ended up?


54 posted on 01/17/2014 12:25:43 PM PST by Nifster
[ Post Reply | Private Reply | To 13 | View Replies]

To: MeshugeMikey

They have to. Multiple devices cannot have the same IP at the same time, anyway.


55 posted on 01/17/2014 12:26:03 PM PST by ro_dreaming (Chesterton, 'Christianity has not been tried and found wanting. ItÂ’s been found hard and not tried')
[ Post Reply | Private Reply | To 6 | View Replies]

To: Lazamataz

Already patented. Prolly being built or offered for sale somewhere right now.


56 posted on 01/17/2014 12:32:03 PM PST by SgtHooper (If at first you don't succeed, skydiving is not for you.)
[ Post Reply | Private Reply | To 17 | View Replies]

To: MeshugeMikey

I have to laugh every time I see the pinheads on the taxpayer-funded PBS series “This Old House” brag about the home automation system they installed:

“We can control the lights, heat, locks, etc. from a smartphone or tablet! Ain’t that cool?”

Sure. What could _possibly_ go wrong?

*snort*

:wq


57 posted on 01/17/2014 1:33:46 PM PST by Peet (Oderint dum metuant)
[ Post Reply | Private Reply | To 1 | View Replies]

To: MeshugeMikey

Didn’t Google just pay 3.5bil for the outfit that makes wifi connected thermostats?


58 posted on 01/17/2014 1:37:51 PM PST by nascarnation (I'm hiring Jack Palladino to investigate Baraq's golf scores.)
[ Post Reply | Private Reply | To 21 | View Replies]

To: Darksheare

It’s ok, Darks. We love you anyway.


59 posted on 01/17/2014 2:09:33 PM PST by sweetliberty (If Obama is the answer, it must have been a really stupid question!)
[ Post Reply | Private Reply | To 19 | View Replies]

To: nascarnation

Yes I believe that they did!


60 posted on 01/17/2014 2:19:54 PM PST by MeshugeMikey (This Message NOT Approved By The N.S.A.)
[ Post Reply | Private Reply | To 58 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-75 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson