Vulnerabilities / Threats

6/29/2016
09:05 AM
50%
50%

Over 25,000 IoT CCTV Cameras Used In DDoS Attack

Probe uncovers attacks generated from 105 global locations and delivering 50,000 HTTP requests per second.

More than 25,000 IoT CCTV devices located worldwide have been hacked and are being used for a denial-of-service botnet attack, reports Network World quoting security research firm Sucuri. The botnet, discovered during a jewelry store DDoS attack probe, was found to deliver 50,000 HTTP requests per second.

“It is not new that attackers have been using IoT devices to start their DDoS campaigns,” says Sucuri. “However, we have not analyzed one that leveraged only CCTV devices and was still able to generate this quantity of requests for so long.”

According to Sucuri, the attacks, “a variation of the HTTP flood and cache bypass attack,” were initiated from 25,513 unique IP addresses in 105 countries with 5% of the IPs being IPv6. The most compromised CCTV devices were located in Taiwan, USA, Indonesia, Mexico, Malaysia and Israel, Italy, Vietnam, France and Spain, says Sucuri adding that around 46% of the cameras had default H.264 DVR logos.

Sucuri believes the CCTV devices may have been hacked via the remote code execution (RCE) flaw recently found to affect CCTV-DVR devices sold by some vendors.

Read full story at Network World.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
uRock
50%
50%
uRock,
User Rank: Apprentice
7/1/2016 | 11:31:31 AM
Where can we find which vendors?
I have a Swann system and would like to know if it is vulnerable. 

I am sure mine isn't being used as it is not connected to any router with internet access. It would still be nice to know if I should worry about this if I were to put it on my regular LAN.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
6/29/2016 | 1:04:52 PM
Re: CCTV
I would think some level of functionality would need to be maintained otherwise the owner of the CCTV would be alerted pretty quickly.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/29/2016 | 11:18:48 AM
Compromised CCTV
" The most compromised CCTV devices were located in Taiwan, USA, Indonesia, Mexico, Malaysia and Israel, Italy, Vietnam, France and Spain, says Sucuri "

Another question; are these the countries using CCTV devices most?
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/29/2016 | 11:16:08 AM
Re: RCE
Or follow up question, do they know that their devises are vulnerable? :--))
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/29/2016 | 11:14:40 AM
CCTV
A question came to my mind: What happens when CCTV is attacked, it does not record? That is a good way of disabling cameras in secure areas.

 
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
6/29/2016 | 9:50:27 AM
RCE
Has there been a patched released by the vendors to mitigate this RCE flaw?
Russia Hacked Clinton's Computers Five Hours After Trump's Call
Robert Lemos, Technology Journalist/Data Researcher,  4/19/2019
Tips for the Aftermath of a Cyberattack
Kelly Sheridan, Staff Editor, Dark Reading,  4/17/2019
Why We Need a 'Cleaner Internet'
Darren Anstee, Chief Technology Officer at Arbor Networks,  4/19/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-11498
PUBLISHED: 2019-04-24
WavpackSetConfiguration64 in pack_utils.c in libwavpack.a in WavPack through 5.1.0 has a "Conditional jump or move depends on uninitialised value" condition, which might allow attackers to cause a denial of service (application crash) via a DFF file that lacks valid sample-rate data.
CVE-2019-11490
PUBLISHED: 2019-04-24
An issue was discovered in Npcap 0.992. Sending a malformed .pcap file with the loopback adapter using either pcap_sendqueue_queue() or pcap_sendqueue_transmit() results in kernel pool corruption. This could lead to arbitrary code executing inside the Windows kernel and allow escalation of privilege...
CVE-2019-11486
PUBLISHED: 2019-04-23
The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the Linux kernel before 5.0.8 has multiple race conditions.
CVE-2019-11487
PUBLISHED: 2019-04-23
The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-after-free issues, if about 140 GiB of RAM exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h, include/linux/pipe_fs_i.h, kernel/trace/trace.c, mm/gup.c, and mm/hu...
CVE-2018-7576
PUBLISHED: 2019-04-23
Google TensorFlow 1.6.x and earlier is affected by: Null Pointer Dereference. The type of exploitation is: context-dependent.