June 21, 2017 By Larry Loeb 2 min read

Security is a constant concern within the Internet of Things (IoT), especially with the emergence of IoT malware such as the Mirai bot.

Researchers from Pen Test Partners recently discovered more about Mirai, rendering it potentially even more dangerous than previous iterations. The firm investigated the hardware and software in connected devices to determine what is possible — other than a giant distributed denial-of-service (DDoS) botnet.

IoT Malware Continues to Develop

Pen Test Partners researcher Ken Munro said the firm looked at over 30 brands of DVR hardware. It found, among other things, that an exploitable buffer overflow is present over port 80, which could give rise to a new DVR botnet composed of 1 million or more devices.

The act of port exploitation is actually quite simple. A GET request in the device’s web server can be crafted to allow remote code execution. This web server is enabled by default to allow users to remotely manage their DVRs.

If at least 153 characters are appended during remote code execution, the main Sofia process will crash and reboot. Since all processes on the DVR run as root, any commands that are injected during the attack will do the same.

“The binary running the web service has not been compiled with any of the common mitigations (ASLR, SSP etc.), allowing this to be used for remote code execution,” Pen Test Partners reported. The firm also discovered that some of the DVRs use TCP port 12323, a Telnet port that is vulnerable to the same Mirai default credentials that were used in previous attacks.

Persistence Is Possible

Interestingly, Bleeping Computer explained that Pen Test Partners also found a way to remotely crush a standard Mirai botnet. However, the method could also be used to make Mirai persistent beyond a power-off reboot, which normally wipes the attack code.

In light of this, Pen Test Partners refrained from publishing any details about this new method. It feared that a weaponized version of Mirai might emerge, which is reasonable, given how the original Mirai code was swiftly modified and used in attacks.

IoT devices are sources of unregulated and widespread insecurity. While some manufacturers have taken limited steps to moderate the effects of the devices they make, they still have a long way to go to fully mitigate the risks.

More from

Cybersecurity dominates concerns among the C-suite, small businesses and the nation

4 min read - Once relegated to the fringes of business operations, cybersecurity has evolved into a front-and-center concern for organizations worldwide. What was once considered a technical issue managed by IT departments has become a boardroom topic of utmost importance. With the rise of sophisticated cyberattacks, the growing use of generative AI by threat actors and massive data breach costs, it is no longer a question of whether cybersecurity matters but how deeply it affects every facet of modern operations.The 2024 Allianz Risk…

Autonomous security for cloud in AWS: Harnessing the power of AI for a secure future

3 min read - As the digital world evolves, businesses increasingly rely on cloud solutions to store data, run operations and manage applications. However, with this growth comes the challenge of ensuring that cloud environments remain secure and compliant with ever-changing regulations. This is where the idea of autonomous security for cloud (ASC) comes into play.Security and compliance aren't just technical buzzwords; they are crucial for businesses of all sizes. With data breaches and cyber threats on the rise, having systems that ensure your…

Adversarial advantage: Using nation-state threat analysis to strengthen U.S. cybersecurity

4 min read - Nation-state adversaries are changing their approach, pivoting from data destruction to prioritizing stealth and espionage. According to the Microsoft 2023 Digital Defense Report, "nation-state attackers are increasing their investments and launching more sophisticated cyberattacks to evade detection and achieve strategic priorities."These actors pose a critical threat to United States infrastructure and protected data, and compromising either resource could put citizens at risk.Thankfully, there's an upside to these malicious efforts: information. By analyzing nation-state tactics, government agencies and private enterprises are…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today