Attacks/Breaches
2/15/2013
12:42 PM
50%
50%

Zombie Hackers Exploited Emergency Alert System Security Flaws

FCC has known about security gaps in networked alert systems equipment for more than 10 years. What if next hoax is serious?

"It's been known for a while that the Emergency Broadcasting System was set up without security," digital forensics consultant Jonathan Grier said via email. "The threat the U.S. had in mind was WWIII, not stateside hackers."

According to Venable's Barnett, the emergency alert devices "were developed over the last few decades, and while they're part of a network, it was before packet-switched and Internet concepts were even prevalent in our society, so some of the connections to other networks are now, you could say, bolted on."

Security researchers first discovered vulnerabilities in the EAS in 2002. In 2004, meanwhile, the FCC confirmed that "security and encryption were not the primary design criteria when EAS was developed and initially implemented," The Register reported.

"Now, however, emergency managers are becoming more aware of potential vulnerabilities within the system," said the FCC in 2004. "For example, the complete EAS protocol is a matter of public record and potentially subject to malicious activations or interference."

Given that 10 years have elapsed without a proper fix, arguably the FCC doesn't see EAS insecurities as representing a grave threat. "The response from the government was they didn't view this as a major concern: people instinctively cross-validate shocking news, so if one TV station reports, for example, a need for an emergency evacuation, it's unlikely to cause a panic -- people will cross-validate this before taking action," Grier said. "But it does make you think of Orson Welles."

Now, however, a stronger government response will be likely. "You can watch the Federal Communications Commission and FEMA to see what comes out," Barnett said. "I'm willing to bet that they'll have an investigation and report into this." He also recommended that the alerting industry rethink its approach to security. "They need to look at coming together and codifying some best practices to make sure that these types of things don't happen," he said.

Previous
2 of 2
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
MyW0r1d
50%
50%
MyW0r1d,
User Rank: Apprentice
2/19/2013 | 9:34:29 PM
re: Zombie Hackers Exploited Emergency Alert System Security Flaws
Thank goodness they were good hearted, albeit bored hooligans that meant no real harm. Imagine the panic if they had presented a more credible story to be transmitted? Or instead of the SuperBowl, the next power outage may be caused by a hack (or fully functioning "smart" control software) shutting down the circuit of the grid controlling Wall Street or the Chicago Merc ?
kjhiggins
50%
50%
kjhiggins,
User Rank: Strategist
2/15/2013 | 9:33:33 PM
re: Zombie Hackers Exploited Emergency Alert System Security Flaws
It sounds like the pranksters basically provided a handy proof-of-concept that could help pressure some security fixes for the technology. All I could think of when I first heard this story was Orson Welles and the confusion over his "War of the Worlds" reading on the radio.

Kelly Jackson Higgins, Senior Editor, Dark Reading
Register for Dark Reading Newsletters
White Papers
Cartoon
Latest Comment: nice post
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-1750
Published: 2015-07-01
Open redirect vulnerability in nokia-mapsplaces.php in the Nokia Maps & Places plugin 1.6.6 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the href parameter to page/place.html. NOTE: this was originally reported as cross-sit...

CVE-2014-1836
Published: 2015-07-01
Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to delete arbitrary files via a full pathname in the image_path parameter in a cancel action.

CVE-2015-0848
Published: 2015-07-01
Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image.

CVE-2015-1330
Published: 2015-07-01
unattended-upgrades before 0.86.1 does not properly authenticate packages when the (1) force-confold or (2) force-confnew dpkg options are enabled in the DPkg::Options::* apt configuration, which allows remote man-in-the-middle attackers to upload and execute arbitrary packages via unspecified vecto...

CVE-2015-1950
Published: 2015-07-01
IBM PowerVC Standard Edition 1.2.2.1 through 1.2.2.2 does not require authentication for access to the Python interpreter with nova credentials, which allows KVM guest OS users to discover certain PowerVC credentials and bypass intended access restrictions via unspecified Python code.

Dark Reading Radio
Archived Dark Reading Radio
Marc Spitler, co-author of the Verizon DBIR will share some of the lesser-known but most intriguing tidbits from the massive report