Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Recursion

(56,582 posts)
Thu Apr 7, 2016, 10:49 PM Apr 2016

'Devastating' bug pops secure doors at airports, hospitals

http://www.theregister.co.uk/2016/04/04/devastating_bug_pops_secure_doors_at_airports_hospitals/

Criminals could waltz into secure zones in airports and government facilities by hacking and jamming open doors from remote computers over the Internet, DVLabs researcher Ricky Lawshae says.

The since-patched vulnerabilities affect HID's flagship VertX and Edge controllers which are distributed in scores of busy locations and large global enterprises.

...

All it takes Lawshae says is "a few simple UDP packets" for the "potentially devastating bug" to be exploited. Authentication is not required.

Lawshae says the attacks, which can open every door in a building, are possible because of a command injection vulnerability in a LED blinking lights service.


The Internet of Things: millions of unpatched embedded systems, generally running as root...
8 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
'Devastating' bug pops secure doors at airports, hospitals (Original Post) Recursion Apr 2016 OP
We have had a massive invasion of Lady Bugs WhiteTara Apr 2016 #1
You would be surprised the damage a ladybeetle can do Lordquinton Apr 2016 #6
Google infusion pump root telnet no password. Paulie Apr 2016 #2
OMG Recursion Apr 2016 #3
They said none of this mattered since you couldn't change the dosing Paulie Apr 2016 #5
Kick and recommend for a serious matter. oasis Apr 2016 #4
I think I understood 1/32 of what has been said here. vanlassie Apr 2016 #7
"a few simple UDP packets" bemildred Apr 2016 #8

WhiteTara

(29,721 posts)
1. We have had a massive invasion of Lady Bugs
Thu Apr 7, 2016, 10:57 PM
Apr 2016

and when I read the title of your article I envisioned millions of the little creatures worming their way through the doors!

Sorry, I realize this is a serious matter!

Paulie

(8,462 posts)
5. They said none of this mattered since you couldn't change the dosing
Thu Apr 7, 2016, 11:48 PM
Apr 2016

Then someone showed how to change the dosing. It's quite shocking.

A lot of the old automation gear is in old rough shape and lots plugged directly into the raw Internet. We used to talk about SCADA a few years ago, now, crickets.

Latest Discussions»General Discussion»'Devastating' bug pops se...