Live data from Hacker News

A Rogue Raspberry Pi Let Hackers Into JPL Network

extremetech.com

31–37 of 37 posts

Re: A Rogue Raspberry Pi Let Hackers Into JPL Network

#31
post #16

Earlier quoted context omitted.

Recommendations suck, they just write couple of times that administrators should update "Information Technology Security Database" and that they failed to do that. That should be automated. They have all those "CISO", "SAISO", "OCIO" and "CIO" but there is no one who knows how to setup automated nmap scan for a network range? Then trigger someone and add it to some inventory like "hey there is some new raspberry pi i…

It's not like you can easily detect a rogue RPi with just nmap. It's trivial not to respond to anything sent to you. You have to start looking at ARP, but that's not iron-clad either.

But that is not the point, point is they make admins do stuff manually. Getting kids to brush teeth every morning and evening is hard, getting bunch of IT admins to do something, what seems pointless, every day is close to impossible. Setting up something that scans network every day is trivial by comparison.

Re: A Rogue Raspberry Pi Let Hackers Into JPL Network

#33

>5,406 unresolved SPLs—about 86 percent of which were rated high or critical >JPL did not effectively address a known software vulnerability, first identified in 2017, with a critical score of 10. This software flaw can be used by cyberattackers to remotely execute malicious code >one of the projects has a waiver of JPL IT security requirements to change passwords every 90 days. Instead, the project relies on a desig…

If I was a betting man, I'd bet that there are some old dusty areas of NASA facilities where there are open NFS exports, NIS providing security, and Sun workstations doing work. I bet someone could fire up a SATAN scanning instance with a Mosaic browser and find some open stuff on some of those old and crusty computers. :)

Thanks for making me remember Saint and Satan times! Also Nessus was open source.

Re: A Rogue Raspberry Pi Let Hackers Into JPL Network

#34

>5,406 unresolved SPLs—about 86 percent of which were rated high or critical >JPL did not effectively address a known software vulnerability, first identified in 2017, with a critical score of 10. This software flaw can be used by cyberattackers to remotely execute malicious code >one of the projects has a waiver of JPL IT security requirements to change passwords every 90 days. Instead, the project relies on a desig…

If I was a betting man, I'd bet that there are some old dusty areas of NASA facilities where there are open NFS exports, NIS providing security, and Sun workstations doing work. I bet someone could fire up a SATAN scanning instance with a Mosaic browser and find some open stuff on some of those old and crusty computers. :)

Can we get more details about this Satan thing?

Re: A Rogue Raspberry Pi Let Hackers Into JPL Network

#35

Earlier quoted context omitted.

If I was a betting man, I'd bet that there are some old dusty areas of NASA facilities where there are open NFS exports, NIS providing security, and Sun workstations doing work. I bet someone could fire up a SATAN scanning instance with a Mosaic browser and find some open stuff on some of those old and crusty computers. :)

Can we get more details about this Satan thing?

Security Administrator Tool for Analyzing Networks

(Or, if you repent, SANTA.)

https://en.wikipedia.org/wiki/Security_Administrator_Tool_fo...

Re: A Rogue Raspberry Pi Let Hackers Into JPL Network

#37

Earlier quoted context omitted.

Can we get more details about this Satan thing?

Security Administrator Tool for Analyzing Networks (Or, if you repent, SANTA.) https://en.wikipedia.org/wiki/Security_Administrator_Tool_fo...

So an early version of metasploit?
Post reply on HN