DerbyCon 2015: Connecting medical equipment to the internet may have seemed like a very smart idea a few years ago.
But you'll change your mind when you watch Scott Erven and Mark Collao's presentation from the recent DerbyCon 2015 security conference.
According to the two security researchers, over 68,000 medical systems are online, with at least 12,000 of them belonging to a single healthcare organization.
What is even more worrying is that most of these devices connect to the Internet through computers running very old versions of Windows, such as XP and 98, since they are known not to be upgraded and thus have many vulnerabilities.
All of these devices are easily detectable via Shodan, a search engine that can locate connected devices online on the internet, and are also easy to hack through brute-force attacks and using hard-coded logins.
During their research, the two experts came across anesthesia equipment, cardiology devices, nuclear medicine systems, infusion systems, pacemakers, MRI scanners, as well as image archiving and communications tools, all with simple queries on Shodan.
Building on their initial findings, the two security experts created honeypots (deceptions for hackers) on special servers that looked like medical devices to outsiders, with vulnerabilities and fake medical data, but also with strong login credentials.
Sifting through the logs collected from these honeypots, the researchers found that the attackers managed to bypass SSH authentication over 55,000 times, and that they left behind 299 malware.
There were also 24 cases where attackers successfully exploited the MS08-067 XP vulnerability, the same one used in Conficker worm infections.
Researchers say that most of the time the attackers didn't realize exactly what they were hacking and were content to simply leave behind an infected machine, just like a piece of their botnet.
If the hacker realized what he was up against, he could easily obtain patient health information from these devices, and even use the devices to spread more dangerous malware within the hospital's IT infrastructure, which would help them carry out even more devastating attacks.
Watch Scott Erven and Mark Collao's presentation at DerbyCon 2015, below:

