Live data from Hacker News

A Rogue Raspberry Pi Let Hackers Into JPL Network

extremetech.com

1–10 of 37 posts

Re: A Rogue Raspberry Pi Let Hackers Into JPL Network

#4
The actual OIG report: https://oig.nasa.gov/docs/IG-19-022.pdf I only did the briefest of scans, but the recommendations seem pretty basic best practices stuff.

In my experience, research labs tend to be creative spaces with a focus on collaboration and information security is not foremost on peoples mind. I guess that will have to change.

Re: A Rogue Raspberry Pi Let Hackers Into JPL Network

#5

It would be nice to know what this specific "Raspberry Pi" vulnerability is, considering the software stack is almost entirely Debian.

Not impossible to imagine the credentials were the unchanged default pi/raspberry... (I imagine quite a few people who haven't done much w/ a Pi don't even run raspi-config) I assume you can scan for similar exposed RPis with Shodan etc.

Re: A Rogue Raspberry Pi Let Hackers Into JPL Network

#6

It would be nice to know what this specific "Raspberry Pi" vulnerability is, considering the software stack is almost entirely Debian.

> The comprehensive federal review of JPL’s systems stemmed from an April 2018 incident when someone at JPL attached the Raspberry Pi to the network there for an unknown purpose

Basically, someone plugged in a computer to the corporate network that happened to be a Raspberry Pi. Might as well have been a Beaglebone, a Banana Pi or an Intel NUC for that matter.

Re: A Rogue Raspberry Pi Let Hackers Into JPL Network

#7
post #3

> If, however, they represented an adversarial nation, the data could be extremely valuable. Yes, heaven knows that data on manned spaceflight shouldn't be shared with all of mankind, only america and it's allies.

Or you know, lobbing ballistic warheads at some other country you've been at war with for literally centuries.

Re: A Rogue Raspberry Pi Let Hackers Into JPL Network

#8

It would be nice to know what this specific "Raspberry Pi" vulnerability is, considering the software stack is almost entirely Debian.

There is no RPi vulnerability(in this article). The RPi was just used as a bastion into the internal network. It could have been any SBC. Once your already inside the internal network things get stupid lax.

EG. I can't see your Windows shared folders from the internet, but the PC in the next room can. Someone sneaked an RPi into JPL to be that PC in the next room.

See Also; Season 1 Mr Robot had this exact scenario as a plot point.

Re: A Rogue Raspberry Pi Let Hackers Into JPL Network

#9

It would be nice to know what this specific "Raspberry Pi" vulnerability is, considering the software stack is almost entirely Debian.

Probably just ssh enabled with the default credentials. IIRC, raspberry pis have their own MAC address prefix, so it's pretty obvious when you find one.
Post reply on HN