Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

12/6/2013
07:00 AM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Linux Worm Targets Embedded Devices

Attacking a PHP vulnerability patched a year-and-a-half ago, the new outbreak shows the Internet of Things' seams

As security researchers look into a Linux worm that's gaining steam by targeting embedded devices, the lessons they learn could prove instructive for the industry as it seeks to protect the Internet of Things.

First brought to the forefront by researchers with Symantec just before Thanksgiving, and subsequently studied by others in labs at DeepEnd Research and Cisco, the Zollard worm has spiked the number of PHP exploit attempts for devices like routers, set-top boxes, security cameras, and more. The worm takes advantage of an old PHP vulnerability patched in May 2012 that, according to Cisco, is heavily exploited by a number of worms.

In the case of Zollard, in particular, the malware is tuned to go after a number of different architecture types beyond x86, including ARM, PPC, MIPS, and MIPSel. This activity of exploiting vulnerabilities in embedded devices could prove a more visceral portend for the potential dangers posed by the Internet of Things that many security pros have already been warning about for the past few years.

[Are you using your human sensors? See Using The Human Perimeter To Detect Outside Attacks.]

"The Internet of Things is a really terrible term to describe all of the terrible embedded devices that we have all around us that no one is going to ever fix and which will eventually be our downfall," says HD Moore, chief research officer at Rapid7. "I'm a little biased because I've spent so much time on it, but embedded devices are getting compromised left and right."

The big danger of these devices is the combination of forgetability and the hidden compute power they hold -- they're often single-purpose but still built on something like a Linux platform with online connectivity.

"They're small enough that a lot of administrators forget they're there and forget to patch them, change default passwords, and things like that," says Spencer McIntyre, security researcher for SecureState. "But they're running software that is well-known enough to contain vulnerabilities that can be leveraged by attackers."

And enterprises can't afford to sniff at the Internet of Things as a consumer trend only affecting newly connected house appliances; embedded devices are all over the enterprise, with plenty of items such as conference-room devices and printers at risk to malware like Zollard if they're not protected. In particular, routers and switches at large organizations could prove a juicy target for attackers, McIntyre says. "If someone is able to compromise a critical piece of infrastructure like that, then the floodgates are really open for what that attacker can do," McIntyre says, emphasizing the importance of organizations to re-evaluate their patch management and configuration management routines for these forgotten devices.

Unfortunately, embedded devices are often left to linger without appropriate firmware updates ever applied and with configuration frequently left at default states after a set-it-and-forget-it installation.

"This results in most embedded devices running fairly standard configurations," wrote Craig Williams, security researcher for Cisco. "If a vulnerability is found in default or common embedded configurations, attackers are much more likely to focus on it since the attack surface is going to be widespread."

Williams agreed that this stability could make attacks like Zollard more prevalent as these devices are "co-opted" by attackers for launching malware, reconnaissance, and other malicious activity. Moore, for example, predicts that we'll increasingly see botnets made up of infected embedded systems.

According to Williams, the answer is protection at the network level, pointing to current IDS signatures that block attacks against the PHP vulnerability that Zollard attacks.

"Though, as always, practicing defense in depth where possible is even better," he says.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 4/7/2020
The Coronavirus & Cybersecurity: 3 Areas of Exploitation
Robert R. Ackerman Jr., Founder & Managing Director, Allegis Capital,  4/7/2020
'Unkillable' Android Malware App Continues to Infect Devices Worldwide
Jai Vijayan, Contributing Writer,  4/8/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-1633
PUBLISHED: 2020-04-09
Due to a new NDP proxy feature for EVPN leaf nodes introduced in Junos OS 17.4, crafted NDPv6 packets could transit a Junos device configured as a Broadband Network Gateway (BNG) and reach the EVPN leaf node, causing a stale MAC address entry. This could cause legitimate traffic to be discarded, le...
CVE-2020-8834
PUBLISHED: 2020-04-09
KVM in the Linux kernel on Power8 processors has a conflicting use of HSTATE_HOST_R1 to store r1 state in kvmppc_hv_entry plus in kvmppc__tm, leading to a stack corruption. Because of this, an attacker with the ability run code in kernel space of a guest VM can cause the host kernel to...
CVE-2020-11668
PUBLISHED: 2020-04-09
In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit.c (aka the Xirlink camera USB driver) mishandles invalid descriptors, aka CID-a246b4d54770.
CVE-2020-8961
PUBLISHED: 2020-04-09
An issue was discovered in Avira Free-Antivirus before 15.0.2004.1825. The Self-Protection feature does not prohibit a write operation from an external process. Thus, code injection can be used to turn off this feature. After that, one can construct an event that will modify a file at a specific loc...
CVE-2020-7922
PUBLISHED: 2020-04-09
X.509 certificates generated by the MongoDB Enterprise Kubernetes Operator may allow an attacker with access to the Kubernetes cluster improper access to MongoDB instances. Customers who do not use X.509 authentication, and those who do not use the Operator to generate their X.509 certificates are u...