Showing posts with label Shodan Search Engine. Show all posts
Showing posts with label Shodan Search Engine. Show all posts

Thursday, 11 February 2016

Russian Hospital Hacked Via Wifi And Old XP Flaw



A researcher has managed to hack a Russian hospital by a weak wifi password and a nearly 8-year-old vulnerability in Windows XP. The hack took place with the permission of the hospital in Moscow, let researcher Sergey Lozhkin know anti-virus company Kaspersky Lab.

He was using the Shodan search engine discovers a login portal of a CT scan machine hospital, which was only secured with a default password. Lozhkin had a friend who controlled the hospital and warned him. The hospital then agreed to an informal penetration test. The researcher decided to attack the hospital could do as a real attacker and began the Wi-Fi network of the hospital. He managed to retrieve the password through a brute force attack, let it faces Threat Post know.

After he had gained access to the wireless network he found a Windows XP machine that contained a vulnerability that Microsoft on October 23, 2008 had been patched. However, the update was not rolled out by the hospital. It was the vulnerability that also used the infamous Confickerworm to spread. Lozhkin then managed on the network to find the administrator panel of an MRI machine that was not password protected. Through the panel he had access to patient data and diagnoses were performed by the machine. According to the researcher shows his work that IT security too often forgotten by software developers, both in the medical industry and in other sectors.

Saturday, 18 April 2015

New Leak Can Crash 115,000 Minecraft Servers


A security researcher has published found vulnerability in Minecraft after nearly two years in 2013, allowing an attacker can certainly crash 115,000 Minecraft servers. Ammar Askar warned on July 28, 2013 Minecraft developer Mojang for a vulnerability in the popular game, more globally than 100 million registered players.

By sending to make a simple package, it was possible to let Minecraft-servers crash. As proof Askar also developed an exploit. Despite repeated attempts to contact an update remained, making the researcher, now almost two years later, has revealed the leak. The original vulnerability was discovered in version 1.6.2. Meanwhile 1.8.3 the latest version and this version is also vulnerable.
Servers

Research by the Shodan search engine that took place in late March this year, shows that worldwide certainly 115,000 Minecraft servers are online. Blog Posting of Askar in which he revealed the vulnerability also provided the necessary attention and brought him back into contact with developer Mojang. The company said work on an update. A previous solution would not have solved the problem, but Askar think Mojang had no solution developed, as he had sent an exploit to test his bug message.

Yet in retrospect, he suggests that he probably should have given the company a final warning before he revealed the vulnerability. "A combination of miscommunication and lack of testing led to this situation. Hopefully it's a good learning experience," says the researcher.

Friday, 27 February 2015

Shodan Search Engine Will Find Thousands Of Hacked Websites


Many websites hacked and leave a message of the attacker behind often with "Hacked by" begins. The developer of the search engine Shodan is using this term were found thousands of websites have been hacked recently and were provided with the text "Hacked by."

Shodan is known as search engine that sorts of devices connected to the Internet, such as printers , routers, cameras and even complete industrial SCADA systems can be found. However, the search engine indexes also websites. The research that developer John Matherly conducted revealed that many of the hacked websites were hosted by one provider. A quarter of the "Hacked by" sites was in fact housed in the E commerce Corporation.

Almost all servers of this hosting company running on Apache and PHP, although not all have the same versions. Continue turning the most hacked websites not entirely surprised on port 80 (HTTP). Matherly also wanted to know what attackers had most websites and so could create a Top 10, where "GHoST61" 57 defacement's ends on the first place. The investigation of the Shodan developer late unfortunately not see how the sites were compromised.

Saturday, 21 February 2015

250,000 routers discovered with same SSH key


A researcher who wrote a program to include the "fingerprints" of collecting SSH keys watched curiously when he found one fingerprint on over 250,000 devices. It turned out to routers of the Spanish telecommunications provider Telefonica de Espana.

Some network would default SSH feature, which the manufacturer decides to roll out the same operating system image on all devices. Researcher John Matherly , founder of the Shodan search engine, also found two keys that 200,000 and 150,000 times were used, respectively.

"By analyzing these cases it is easy to get a picture of the systemic problems both hardware manufacturers and ISPs pests," said Matherly. He has a list of unique fingerprints collected offers now via Github to. "It would not surprise me if you find interesting security problems by analyzing why these things are configured incorrectly," he notes.