HomeSecurityThousands of IoT medical devices found vulnerable to online attacks

Thousands of IoT medical devices found vulnerable to online attacks

Medical equipment can be easily hacked and taken over online, two security researchers discovered at DerbyCon.
Connecting medical equipment to the Internet seemed like a pretty smart idea a few years ago. You'll change your mind after watching Scott Erven and Mark Collao's presentation at the recent security conference, DerbyCon 2015.

Thousands of IoT medical devices found vulnerable to online attacks online online online
According to the two security researchers, over 68,000 medical systems are exposed online, with over 12,000 of them belonging to a single healthcare organization.
What’s even more worrying is that most of these devices are connected to the Internet via computers running very old versions of Windows XP, which are known to have many exploitable vulnerabilities.
All of these devices are easily discoverable via Shodan, a search engine that can find Internet-connected devices online, and are also easy to hack through brute-force attacks, using hard-coded connections.
During their research, the two INFOSEC experts found anesthesia equipment, cardiology devices, nuclear medicine systems, infusion systems, pacemakers, MRI scanners, and image archiving and communication equipment, all with simple Shodan queries.
Acting on their initial findings, the two experts created honeypots, special servers that looked like medical devices to outsiders, filled with vulnerabilities and fake medical data, but which also contained a powerful connection-related component.
Digging through the logs collected online from these honeypots, the researchers found that the attackers were able to authenticate via SSH to the fake medical devices over 55,000 times and leave behind 299 malware payloads.
There were also 24 cases where the attackers successfully exploited the MS08-067 XP vulnerability, the same one used in Conficker worm infections.
The researchers say that most of the time the attackers didn't realize what they had just hacked and were content to leave an infected machine behind as part of their botnets.
If hackers realized the access they could gain through these devices, they could easily steal patient health information, and even use these devices to spread more dangerous malware within the hospital IT infrastructure, which would help them carry out more devastating attacks.
You can watch Scott Erven and Mark Collao’s full presentation below:

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS