November 2, 2016
The DDoS attack on DNS provider Dyn Oct. 21 brought IoT security into the general public’s consciousness for the first time. Now, researchers from Invincea Labs have discovered two vulnerabilities in Belkin’s WeMo home automation devices, one of which demonstrated that a flaw in an IoT device could cause problems with an Android smartphone.
“In the past, people may not have been concerned if there were vulnerabilities with their Internet-connected lighting or crockpot, but now that we’ve discovered that bugs in IoT systems can impact their smartphones, people will pay a bit more attention,” says Scott Tenaglia, research director at Invincea Labs. “It’s the first case that we’ve found that an insecure IoT device could be used to run malicious code inside a phone.”
Tenaglia, along with Joseph Tanen, lead research engineer, conducted their tests over the summer. They found two vulnerabilities. The first is a SQL injection vulnerability that could be used to gain root access to a WeMo device. When the WeMo app on the smartphone would set a rule that, for example, would make all the lights in the home shut off at 10 p.m., the app would run a SQL query that was susceptible to SQL injection.
The fix, which Belkin confirmed was made available yesterday, was to release firmware that sanitizes the inputs used to build SQL queries. Belkin said it will push the fix out via the app, so users will see a new firmware notification when they open up the application.
Belkin issued a fix for this flaw with a software update included in version 1.15.2 back in August. The fix was to update the Apache Cordova framework that the application is based on. Once a user installs the patch, the malicious code does not launch.
Tenaglia and Tanen will present their research this Friday morning at Black Hat Europe 2016 in London at a session titled, Breaking BHAD: Abusing Belkin Home Automation Devices.
About the Author(s)
You May Also Like
Hacking Your Digital Identity: How Cybercriminals Can and Will Get Around Your Authentication MethodsOct 26, 2023
Modern Supply Chain Security: Integrated, Interconnected, and Context-DrivenNov 06, 2023
How to Combat the Latest Cloud Security ThreatsNov 06, 2023
Reducing Cyber Risk in Enterprise Email Systems: It's Not Just Spam and PhishingNov 01, 2023
SecOps & DevSecOps in the CloudNov 06, 2023
Passwords Are Passe: Next Gen Authentication Addresses Today's Threats
How to Deploy Zero Trust for Remote Workforce Security
What Ransomware Groups Look for in Enterprise Victims
Concerns Mount Over Ransomware, Zero-Day Bugs, and AI-Enabled Malware
Securing the Remote Worker: How to Mitigate Off-Site Cyberattacks