Kaspersky Lab: Several popular connected home entertainment devices can pose a real threat to digital security due to vulnerabilities in their software, as well as a lack of basic security measures, such as strong, default passwords for administrators and encryption of the Internet connection.
David Jacoby, a security analyst at Kaspersky Lab, conducted a research experiment in his living room to determine how digitally secure his home is. To do this, he examined various home entertainment devices (e.g. network-attached storage devices, Smart TV, router, Blu-ray player , etc.) that were found to be vulnerable to digital attacks.
For the experiment, two models of network-attached storage devices from different manufacturers, a Smart TV, a satellite receiver, and a networked printer were examined. During the investigation, David Jacoby was able to find 14 vulnerabilities in the storage devices, one vulnerability in the Smart TV, and several potentially hidden remote control functions in the router.
In accordance with Kaspersky Lab 's responsible disclosure policy , the company does not disclose the names of the manufacturers whose products were part of the research until the patch covering the vulnerabilities is released. It is noted that all companies have been informed of the existence of the vulnerabilities. Kaspersky Lab experts also work with product providers to eliminate the vulnerabilities they discover.
“Both individual users and businesses need to understand the security risks associated with connected devices. We also need to always keep in mind that our information is not safe just because we have entered a strong password, and that there are many things we cannot control. It took me less than 20 minutes to identify and confirm extremely serious vulnerabilities in a device that seems secure and whose name itself refers to the concept of security. How would a similar investigation end if it were conducted on a much larger scale than in my living room? This is just one of many questions that product manufacturers, the security industry, and device users need to answer in the near future. The other important issue is the lifespan of devices. Based on various discussions with manufacturers, it appears that some companies will not develop patches for a vulnerable device when its life cycle is at the end. Typically, this cycle covers one or two years, while the actual lifespan of devices – for example, attached storage devices – is much longer,” said David Jacoby.
Remote code execution and weak passwords: The most serious vulnerabilities were found in network-attached storage devices. Several of them would allow an attacker to remotely execute commands, even with the highest possible administrative privileges on a system. In addition, the default passwords for these devices were weak, many of the configuration files had authorization errors, and they contained the passwords in plain text. In particular, the default administrator password for one of the devices contained only one digit. Another device even shared its entire configuration file with encrypted passwords with all users on the network.
Using a separate vulnerability, the researcher was able to “upload” a file to an area of the storage memory that is inaccessible to the average user. If this file was malicious, the compromised storage device could become a source of “infection” for all devices connected to it (e.g. PCs), and even be used as a DDoS bot on a malicious network. Furthermore, since the vulnerability allowed the file to be “uploaded” to a special part of the device’s file system, the only way to delete it was to use the vulnerability itself. Obviously, this is not an easy task even for an expert, let alone for the average owner of home entertainment equipment.
Man-in-the-Middle attacks via Smart TV: Examining the security level of his own Smart TV, a Kaspersky Lab discovered that no encryption is used in the communication between the TV and the servers . This potentially opens the way for Man-in-the-Middle attacks, which could result in the user transferring money to fraudsters when trying to purchase content via the Smart TV. In fact, the researcher was able to replace an icon in the interface with another image. Normally, widgets and thumbnails are downloaded from the servers , but due to the lack of an encrypted connection, the information could be modified by a third party. The researcher also discovered that the “smart” TV can execute Java which – combined with the ability to intercept data exchange between the TV and the Internet – could lead to malicious attacks based on vulnerabilities.
Hidden spying features in routers : The DSL that provided wireless Internet access to all other household devices included several dangerous features that were hidden from its owner. According to the researcher, some of these hidden features could give the Internet Service Provider (ISP) remote access to every device on a private network. More importantly, however, the device owner cannot see or customize parts of the router ’s web interface called “ Web Cameras,” “Telephony Expert Configure,” “Access Control,” “WAN-Sensing,” and “Update,” the research showed. Access to these parts was only possible by exploiting a vulnerability that allowed browsing to various parts of the interface (in reality, these are web pages, each with an alphanumeric address).
Initially, these features were implemented to provide greater convenience to the device owner: the remote access feature allows the ISP to easily and quickly resolve potential technical issues with the device. However, this convenience can turn into a risk if control falls into the wrong hands.
How to stay safe in the world of connected devices
- Install the latest security and firmware updates on all your devices . This will minimize the risks of exploiting known vulnerabilities.
- Ensure that the default username and password have been changed, as these are the first details an attacker will look at when attempting to compromise a device.
- Most home routers and switches offer the option to configure your network for each device and at the same time restrict access to it. For example, if you have a TV, you might want to restrict access to it and only allow it to access a specific resource on your network. There is no particular reason to have your printer connected to your TV.
The full report on the research, titled “Internet of Things: How I Hacked My Home,” is available at Securelist.com.
