It appears you have not yet registered with our community. To register please click here...

 
Go Back [M] > Madshrimps > WebNews
Severe security problem detected in all IoT devices Severe security problem detected in all IoT devices
FAQ Members List Calendar Search Today's Posts Mark Forums Read


Severe security problem detected in all IoT devices
Reply
 
Thread Tools
Old 10th June 2020, 07:14   #1
[M] Reviewer
 
Stefan Mileschin's Avatar
 
Join Date: May 2010
Location: Romania
Posts: 148,964
Stefan Mileschin Freshly Registered
Default Severe security problem detected in all IoT devices

CallStranger needs patching

A severe vulnerability in a core protocol found in almost all internet of things (IoT) devices allows and attackers to hijack smart devices for DDoS attacks and bypass security to reach and conduct scans on a victim's internal network .

Dubbed CallStranger, the bug impacts UPnP, which stands for Universal Plug and Play, a collection of protocols that ship on most smart devices.

UPnP feature allows devices to see each other on local networks, and then establish connections to easily exchange data, configurations, and even work in sync.

UPnP has been around since the early 2000s, but since 2016, its development has been managed by the Open Connectivity Foundation (OCF), which controls what makes it in the UPnP protocols, in an effort to standardise how these features work across devices.

Security engineer named Yunus Çadirci found a bug in this extremely widespread technology which means that an attacker can send TCP packets to a remote device that contains a malformed callback header value in UPnP's SUBSCRIBE function.

This malformed header can be abused to take advantage of any smart device that was left connected on the internet, and which supports the UPnP protocols -- such as security cameras, DVRs, printers, routers, and others.
https://fudzilla.com/news/iot/50966-...ll-iot-devices
Stefan Mileschin is offline   Reply With Quote
Reply


Similar Threads
Thread Thread Starter Forum Replies Last Post
Ring now requires two-factor sign-ins for its home security devices Stefan Mileschin WebNews 0 19th February 2020 07:34
The FIDO Alliance wants to bring password-less security to IoT devices Stefan Mileschin WebNews 0 28th June 2019 08:16
UK mulls security warnings for smart home devices Stefan Mileschin WebNews 0 3rd May 2019 05:03
Microsoft already has a fix for that severe WiFi security exploit Stefan Mileschin WebNews 0 17th October 2017 05:35
Security bugs put Apple devices running iOS and Mac OS X at risk Stefan Mileschin WebNews 0 25th July 2016 11:01
Google rolling out security update for Nexus devices Stefan Mileschin WebNews 0 10th September 2015 08:21
Google Commits To Monthly Security Updates For Nexus Devices Stefan Mileschin WebNews 0 6th August 2015 17:56
Google's Android security scans over 200 million devices a day Stefan Mileschin WebNews 0 3rd April 2015 16:45
Security Tips for iOS Devices @ ThinkComputers.org Stefan Mileschin WebNews 0 4th July 2013 06:45
Webcam turned security cam with motion detected email notifications jmke WebNews 0 18th April 2011 15:37

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 08:07.


Powered by vBulletin® - Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO