June 21, 2017 By Larry Loeb 2 min read

Security is a constant concern within the Internet of Things (IoT), especially with the emergence of IoT malware such as the Mirai bot.

Researchers from Pen Test Partners recently discovered more about Mirai, rendering it potentially even more dangerous than previous iterations. The firm investigated the hardware and software in connected devices to determine what is possible — other than a giant distributed denial-of-service (DDoS) botnet.

IoT Malware Continues to Develop

Pen Test Partners researcher Ken Munro said the firm looked at over 30 brands of DVR hardware. It found, among other things, that an exploitable buffer overflow is present over port 80, which could give rise to a new DVR botnet composed of 1 million or more devices.

The act of port exploitation is actually quite simple. A GET request in the device’s web server can be crafted to allow remote code execution. This web server is enabled by default to allow users to remotely manage their DVRs.

If at least 153 characters are appended during remote code execution, the main Sofia process will crash and reboot. Since all processes on the DVR run as root, any commands that are injected during the attack will do the same.

“The binary running the web service has not been compiled with any of the common mitigations (ASLR, SSP etc.), allowing this to be used for remote code execution,” Pen Test Partners reported. The firm also discovered that some of the DVRs use TCP port 12323, a Telnet port that is vulnerable to the same Mirai default credentials that were used in previous attacks.

Persistence Is Possible

Interestingly, Bleeping Computer explained that Pen Test Partners also found a way to remotely crush a standard Mirai botnet. However, the method could also be used to make Mirai persistent beyond a power-off reboot, which normally wipes the attack code.

In light of this, Pen Test Partners refrained from publishing any details about this new method. It feared that a weaponized version of Mirai might emerge, which is reasonable, given how the original Mirai code was swiftly modified and used in attacks.

IoT devices are sources of unregulated and widespread insecurity. While some manufacturers have taken limited steps to moderate the effects of the devices they make, they still have a long way to go to fully mitigate the risks.

More from

Remote access risks on the rise with CVE-2024-1708 and CVE-2024-1709

4 min read - On February 19, ConnectWise reported two vulnerabilities in its ScreenConnect product, CVE-2024-1708 and 1709. The first is an authentication bypass vulnerability, and the second is a path traversal vulnerability. Both made it possible for attackers to bypass authentication processes and execute remote code.While ConnectWise initially reported that the vulnerabilities had proof-of-concept but hadn’t been spotted in the wild, reports from customers quickly made it clear that hackers were actively exploring both flaws. As a result, the company created patches for…

Evolving red teaming for AI environments

2 min read - As AI becomes more ingrained in businesses and daily life, the importance of security grows more paramount. In fact, according to the IBM Institute for Business Value, 96% of executives say adopting generative AI (GenAI) makes a security breach likely in their organization in the next three years. Whether it’s a model performing unintended actions, generating misleading or harmful responses or revealing sensitive information, in the AI era security can no longer be an afterthought to innovation.AI red teaming is emerging…

What we can learn from the best collegiate cyber defenders

3 min read - This year marked the 19th season of the National Collegiate Cyber Defense Competition (NCCDC). For those unfamiliar, CCDC is a competition that puts student teams in charge of managing IT for a fictitious company as the network is undergoing a fundamental transformation. This year the challenge involved a common scenario: a merger. Ten finalist teams were tasked with managing IT infrastructure during this migrational period and, as an added bonus, the networks were simultaneously attacked by a group of red…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today