lundi 19 décembre 2016

Malware in ThyssenKrupp case was Winnti. Several companies affected https://t.co/LmIp8vgZIl


from Twitter https://twitter.com/RedaZitouni

Arconic - The Jetsons https://t.co/SJ2OQmaEDp


from Twitter https://twitter.com/RedaZitouni

IEEE puts out a first draft guide for how tech can achieve ethical AI design https://t.co/v9zp2TPYXA via @tech crunch #IoTNow


from Twitter https://twitter.com/RedaZitouni

Home routers under attack in ongoing malvertisement blitz | Ars Technica https://t.co/0xgz9pHRPo


from Twitter https://twitter.com/RedaZitouni

The Astonishing Big Data Generated In A Single Journey – Data Science Central https://t.co/46YcUn4b36


from Twitter https://twitter.com/RedaZitouni

samedi 17 décembre 2016

https://t.co/58fIH4IQOV


from Twitter https://twitter.com/RedaZitouni

10 major 2016 cyber attacks and what they mean for cyber security - Computer Business Review https://t.co/5xQrqGkkHQ


from Twitter https://twitter.com/RedaZitouni

Experts predict 2017's biggest cybersecurity threats https://t.co/nXjYs56jET via @techrepublic


from Twitter https://twitter.com/RedaZitouni

Insane: Obama Threatens Russia Over Election ‘Hacking’ Conspiracy https://t.co/lX1rGTFKUm via @realalexjones


from Twitter https://twitter.com/RedaZitouni

vendredi 9 décembre 2016

-Tech giants warn IoT vendors to get real about security • The Register https://t.co/j1yOBexnl5


from Twitter https://twitter.com/RedaZitouni

-How the 2017 IT Security Landscape Will Play Out - Tech Trends on CIO Today https://t.co/h5VNkkvRS0


from Twitter https://twitter.com/RedaZitouni

-IoT Is A Security Mess And Regulators Are Paying Attention | AdExchanger https://t.co/qpKSQOIrps


from Twitter https://twitter.com/RedaZitouni

dimanche 27 novembre 2016

New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article … https://t.co/Pe6nfhMJS2


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article … https://t.co/LNHf6UQYBa


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article … https://t.co/276NgOQJFi


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article … https://t.co/rPw2KAG38A


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article … https://t.co/GFgHA6ZC0I


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article … https://t.co/8VsOHX7wrz


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article … https://t.co/1bDaCYqCpg


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article … https://t.co/tI7L8EmLm5


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article … https://t.co/uXz6ZN57vx


from Twitter https://twitter.com/RedaZitouni

samedi 26 novembre 2016

New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article on Reda Zitouni blog: RT @Ronald_v… https://t.co/qT6KQH0lze


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article on Reda Zitouni blog: RT @Ronald_v… https://t.co/XkJxpD26bQ


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article on Reda Zitouni blog: RT @Ronald_v… https://t.co/tM8xRD0NeJ


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article on Reda Zitouni blog: RT @RedaZito… https://t.co/fgMKgSRPc1


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article on Reda Zitouni blog: RT @NetObjex… https://t.co/jKCUtHJqaH


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article on Reda Zitouni blog: RT @Ronald_v… https://t.co/a1dXgvlvEe


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article on Reda Zitouni blog: RT @RedaZito… https://t.co/Vqpdn3axZV


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article … https://t.co/dCLkpLb9BF


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article … https://t.co/bwcgNz8sy5


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: RT @Ronald_vanLoon: The Top IoT News of 2016 |… https://t.co/y2Qhi4M7At


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: RT @Ronald_vanLoon: The Top IoT News of 2016 |… https://t.co/DccR0MJerx


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: RT @Ronald_vanLoon: The Top IoT News of 2016 |… https://t.co/feW3DXKmLd


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: RT @RedaZitouni: #DDoS & #IoTSecurity: Archite… https://t.co/wfPfuChLP2


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: RT @NetObjex: The state of the Industrial Inte… https://t.co/kjQwsR71Iu


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: RT @Ronald_vanLoon: The Top IoT News of 2016 |… https://t.co/3kSggqRdtn


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: RT @RedaZitouni: #DDoS & #IoTSecurity: Archite… https://t.co/ywmCJ0VoHq


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article … https://t.co/YHVv7RIQfZ


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article … https://t.co/MwaEl75NGT


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: RT @Ronald_vanLoon: The Top IoT News of 2016 | #DataScience #IoT #RT … https://t.co/hq2OeHOGZl


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: RT @Ronald_vanLoon: The Top IoT News of 2016 | #DataScience #IoT #RT … https://t.co/K5X9EFawif


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: RT @Ronald_vanLoon: The Top IoT News of 2016 | #DataScience #IoT #RT … https://t.co/hq2OeHOGZl


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: RT @RedaZitouni: #DDoS & #IoTSecurity: Architecting #IoT for Emergencies and Dis… https://t.co/ophwF7Dyop


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: RT @NetObjex: The state of the Industrial Internet of Things market: 2021 outloo… https://t.co/lFQjd7BfC7


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: RT @Ronald_vanLoon: The Top IoT News of 2016 | #DataScience #IoT #RT … https://t.co/K5X9EFawif


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: RT @RedaZitouni: #DDoS & #IoTSecurity: Architecting #IoT for Emergencies and Dis… https://t.co/O6MFJuvUb7


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article on Reda Zitouni blog: I've just po… https://t.co/3AhCfKjylg


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: New article on Reda Zitouni blog: I've just po… https://t.co/hBec4bbJIX


from Twitter https://twitter.com/RedaZitouni

RT @Ronald_vanLoon: The Top IoT News of 2016 | #DataScience #IoT #RT https://t.co/2Rr4ykdMmx https://t.co/MHDV0tLGlT


from Twitter https://twitter.com/RedaZitouni

RT @RedaZitouni: #DDoS & #IoTSecurity: Architecting #IoT for Emergencies and Disasters - https://t.co/EEOlHUbY0o


from Twitter https://twitter.com/RedaZitouni

RT @NetObjex: The state of the Industrial Internet of Things market: 2021 outlook with tips https://t.co/P5OA6wM0fM @iscoopbiz… https://t.co/wKcQ6Xmzhr


from Twitter https://twitter.com/RedaZitouni

RT @Ronald_vanLoon: The Top IoT News of 2016 | #DataScience #IoT #RT https://t.co/2Rr4ykdMmx https://t.co/MHDV0tLGlT


from Twitter https://twitter.com/RedaZitouni

RT @RedaZitouni: #DDoS & #IoTSecurity: Architecting #IoT for Emergencies and Disasters - https://t.co/EEOlHUbY0o


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: I've just posted a new blog: IoT security came… https://t.co/F4bNmXmo7D


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: New article on Reda Zitouni blog: I've just posted a new blog: IoT security came… https://t.co/sLTZVkOaD9


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: I've just posted a new blog: IoT security camera infected within 98 seconds of p… https://t.co/uqXnLF9hdg


from Twitter https://twitter.com/RedaZitouni

New article on Reda Zitouni blog: I've just posted a new blog: IoT security camera infected within 98 seconds of p… https://t.co/zHbF5OboLb


from Twitter https://twitter.com/RedaZitouni

I've just posted a new blog: IoT security camera infected within 98 seconds of plugging it in https://t.co/kkSmJ58KHe


from Twitter https://twitter.com/RedaZitouni

I've just posted a new blog: IoT security camera infected within 98 seconds of plugging it in https://t.co/kkSmJ58KHe


from Twitter https://twitter.com/RedaZitouni

IoT security camera infected within 98 seconds of plugging it in

It took a mere minute and a half for an internet-connected security camera to be infected with malware



One and a half minutes is all it took after plugging in an internet-connected security camera for the camera be infected with malware.
Unlike the average Jane or Joe Doe who would not want their security camera to be immediately infected with malware, Rob Graham, CEO of Errata Security, called it “fun” to watch the infection happen. He tweet-documented his experience.
Graham purchased an inexpensive device—this $55 IoT security camera made by JideTech.

JideTech

It supports Universal Plug and Play (UPnP), not a secure feature but easy for non-techies to setup because basically a person plugs a UPnP device in and it works. The average user would not likely do this, but Graham said he isolated the camera from his home network by setting it up behind a Raspberry Pi router.




And just 98 seconds later, Graham’s camera was infected with malware.

Rob Graham

His security camera ended up with multiple malware infections. Mirai malware was not the first infection; he said it was “something else similar to it.”

iot security camera infection by mirai like malware
Rob Graham

It wasn’t long before the security camera had two active infections, one of those being Mirai. Then he got a good look at how Mirai works. He explained that after the first stage of Mirai got a toehold on the device, it downloaded the full Mirai malware.

Mirai malware hunting for new victimsRob Graham

Mirai, he said, “infects things via Telnet, not the web.” The malware sends out “a burst of 150 Telnet packets looking for new victims.” It waits a second for any responses before continuing to hunt for new victims.


Graham noted, “On my Mirai-infected camera, Telnet has a hardcoded password so you can reset your changeable web interface password.” At one point, he said, “One of the infections killed the Telnet daemon and kicked” him off.
The next day he added a command that can be run so you don’t get locked out of your Mirai-infected device.

command so you are not locked out of mirai infected device
Rob Graham

If you plan on buying someone an IoT security camera, or you receive one as a gift for the upcoming holidays, please do try to set it up correctly, since an infection can occur crazy-fast—within 98 seconds! No one, except maybe some security researchers, would want their IoT device to become part of a DDoS botnet.
Although changing the default password before connecting an IoT device to the internet is frequently advised, Graham said that would not help in the case of his Mirai-infected camera.
The correct mitigation, Graham said, is to “put these devices behind your firewall” because “many of the Mirai passwords can’t be changed.”

Z-Wave certified devices to be ‘hacker-proof’

While it certainly won’t resolve all IoT security issues, the Z-Wave Alliance did announce mandating “hacker-proof security on their smart devices.” That’s a bold claim made in an email about the announcement. However, it’s a step in the right direction to reduce security and privacy risks. All smart devices with Z-Wave that are certified after April 2, 2017, will be required to meet specific security requirements.
Certified Z-Wave devices will have to include a new security framework, dubbed S2. The Z-Wave Alliance said:
[S2] completely removes the risk of devices being hacked while they are included in the network. By using a QR or pin-code on the device itself, the devices are uniquely authenticated to the network as well. Common hacks such as man in the middle and brute force are virtually powerless against the S2 framework through the implementation of the industry-wide accepted secure key exchange using Elliptic Curve Diffie-Hellman (ECDH). Finally, Z-Wave also strengthened its cloud communication, enabling the tunneling of all Z-Wave over IP (Z/IP) traffic through a secure TLS 1.1 tunnel, removing vulnerability.
Reda Zitouni