There is evidence now that today's massive attack on DNS system at DYN involved the same Botnet as the attacks of past weeks. Please, if you are using any of these "internet of things" devices, like cameras, baby monitors, etc. which are connectable by Web interfaces, you are likely as not part of this botnet.(Unless you are very technically savvy, and are sure your device is secured, most cannot be). Those of you who are tech types, and do informal or formal "tech support" for family, friends, etc. could really help by tweeting/FBing those in your circle as to the dangers involved in the use of these devices. At the very least, turn off UPnP on your router, and close up open Port Forwarding. And as always, SECURE PASSWORDS,not the damn defaults! Distributed attacks are almost entirely preventable, if everyone takes security somewhat seriously on their own system, and if they can resist cheapass China junk which never receives firmware updates. Almost all of the Web devices, unless they use a service you signed up for on a server somewhere, are vulnerable to attack via the ports they open on your network, and use simple passwords for telnet and SSH which are hard coded and you cannot change them. Leaving UPnP active on your router/gateway allows these devices to punch holes in the firewall you paid for! Thanks, trying to get the message out, but I do not participate in social networking, so your help is needed to spread the news.
This contribution deserves to be widely forwarded !
--------------------- W dwóch słowach, warto dodać, że na co dzień żyję w Warszawie, intryguje mnie podróżowanie, uwielbiam aktywny tryb życia, oraz jak każdy człowiek szykowne auta;)
Unfortunately there is gathering evidence that a large portion of today's attack exploited cheap cameras that have firmware-coded passwords for telnet/ssh access, with the GUI only offering the ability to change the password for web login: Agonizingly stupid, of course. (Or, if your a conspiracy-minded person, awfully convenient. :-) )
And speaking of criminalizing negligent security: any time a site with more than 1000 users is caught hashing passwords with unsalted md5 they should pay a heavy fine, per user. Any time a site is caught with reversibly-encrypted or unencrypted passwords someone should go to jail for a while. :-)
why the fuck do you need your camera to connect to the internet. You can tell where the pic was taken by LOOKING AT IT. and nearly all photos are selfies anyway lol
Hi,fellow reaperites. I hesitated to post this here as it isn't reaper related, but I wanted to get the message out any way I can. Security cameras are the latest of the botnet stories, as the botnet software was just released into the public,and is specific to these cameras, but this type of attack can be used for lots of hardware. Scariest to me was the outbreak a while back of compromised home routers. Since you cannot easily monitor traffic on the WAN side of the device, you could be part of a large botnet, and never know it, unless your ISP shut you down or notified you. I am taking steps to put a sniffer on the WAN side of my network, at least occasionally, to see what is going outbound.It will also be fun to see the spy traffic from the new Windows updates to Win 7 and 8.1...