Live data from Hacker News

Hacking Google's HVAC Systems

cylance.com

1–10 of 46 posts

Re: Hacking Google's HVAC Systems

#2
I'm surprised there aren't botnets running on these embedded devices... yet. Probably because most people don't leave it openly available on the internet.

There are millions of rarely updated devices... printers, security systems, fire alarms, cameras, etc... the list goes on and on.

Re: Hacking Google's HVAC Systems

#3
Interesting related story from July 2012: http://www.washingtonpost.com/investigations/tridiums-niagar...

“We’re not going to say Niagara is secure”

What I find most worrisome about this is that it can enable attackers to access internal video feeds. Seems like an excellent vector to grab someone's credentials.

Also, ironically, one of the people mentioned in the WaPo article who discovered these vulnerabilities used to work for Google.

edit: Aaron's reading comprehension is evidently VERY LOW today ;)

Re: Hacking Google's HVAC Systems

#6
post #2

I'm surprised there aren't botnets running on these embedded devices... yet. Probably because most people don't leave it openly available on the internet. There are millions of rarely updated devices... printers, security systems, fire alarms, cameras, etc... the list goes on and on.

>I'm surprised there aren't botnets running on these embedded devices

That's a pretty bold assumption :)

Re: Hacking Google's HVAC Systems

#8
post #6
post #2

I'm surprised there aren't botnets running on these embedded devices... yet. Probably because most people don't leave it openly available on the internet. There are millions of rarely updated devices... printers, security systems, fire alarms, cameras, etc... the list goes on and on.

>I'm surprised there aren't botnets running on these embedded devices That's a pretty bold assumption :)

I think this was posted on HN a few months ago:

http://internetcensus2012.bitbucket.org/paper.html

They ran their own botnet to map the internet, and then discovered other malware already running on insecure home routers.

Re: Hacking Google's HVAC Systems

#10
You don't need a "custom exploit" or a "custom developed tool" to access a public file called config.bog and base64 decode the user:pass. This Tridium exploit was well publicized in the past year but too many people (including this contractor who installed it) failed to upgrade the security or install the patches.
Post reply on HN