Jump to content

IoT_Reaper Botnet At 2+ Million Infected Devices

Lurick
1 minute ago, leadeater said:

Because you need to flush it when you're not at home lol.

Gotta bother the dogs while you're away, you know, to keep them awake. 

Cor Caeruleus Reborn v6

Spoiler

CPU: Intel - Core i7-8700K

CPU Cooler: be quiet! - PURE ROCK 
Thermal Compound: Arctic Silver - 5 High-Density Polysynthetic Silver 3.5g Thermal Paste 
Motherboard: ASRock Z370 Extreme4
Memory: G.Skill TridentZ RGB 2x8GB 3200/14
Storage: Samsung - 850 EVO-Series 500GB 2.5" Solid State Drive 
Storage: Samsung - 960 EVO 500GB M.2-2280 Solid State Drive
Storage: Western Digital - Blue 2TB 3.5" 5400RPM Internal Hard Drive
Storage: Western Digital - BLACK SERIES 3TB 3.5" 7200RPM Internal Hard Drive
Video Card: EVGA - 970 SSC ACX (1080 is in RMA)
Case: Fractal Design - Define R5 w/Window (Black) ATX Mid Tower Case
Power Supply: EVGA - SuperNOVA P2 750W with CableMod blue/black Pro Series
Optical Drive: LG - WH16NS40 Blu-Ray/DVD/CD Writer 
Operating System: Microsoft - Windows 10 Pro OEM 64-bit and Linux Mint Serena
Keyboard: Logitech - G910 Orion Spectrum RGB Wired Gaming Keyboard
Mouse: Logitech - G502 Wired Optical Mouse
Headphones: Logitech - G430 7.1 Channel  Headset
Speakers: Logitech - Z506 155W 5.1ch Speakers

 

Link to comment
Share on other sites

Link to post
Share on other sites

24 minutes ago, rockking1379 said:

The only IoT device I have is my ecobee thermostat

Just wait til it gets hacked and turns off the heat in the winter while you're away ?

https://linustechtips.com/main/topic/631048-psu-tier-list-updated/ Tier Breakdown (My understanding)--1 Godly, 2 Great, 3 Good, 4 Average, 5 Meh, 6 Bad, 7 Awful

 

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, AresKrieger said:

Just wait til it gets hacked and turns off the heat in the winter while you're away ?

My winters are now 100+ Fahrenheit... 

 

People are already wearing thin coats...

Cor Caeruleus Reborn v6

Spoiler

CPU: Intel - Core i7-8700K

CPU Cooler: be quiet! - PURE ROCK 
Thermal Compound: Arctic Silver - 5 High-Density Polysynthetic Silver 3.5g Thermal Paste 
Motherboard: ASRock Z370 Extreme4
Memory: G.Skill TridentZ RGB 2x8GB 3200/14
Storage: Samsung - 850 EVO-Series 500GB 2.5" Solid State Drive 
Storage: Samsung - 960 EVO 500GB M.2-2280 Solid State Drive
Storage: Western Digital - Blue 2TB 3.5" 5400RPM Internal Hard Drive
Storage: Western Digital - BLACK SERIES 3TB 3.5" 7200RPM Internal Hard Drive
Video Card: EVGA - 970 SSC ACX (1080 is in RMA)
Case: Fractal Design - Define R5 w/Window (Black) ATX Mid Tower Case
Power Supply: EVGA - SuperNOVA P2 750W with CableMod blue/black Pro Series
Optical Drive: LG - WH16NS40 Blu-Ray/DVD/CD Writer 
Operating System: Microsoft - Windows 10 Pro OEM 64-bit and Linux Mint Serena
Keyboard: Logitech - G910 Orion Spectrum RGB Wired Gaming Keyboard
Mouse: Logitech - G502 Wired Optical Mouse
Headphones: Logitech - G430 7.1 Channel  Headset
Speakers: Logitech - Z506 155W 5.1ch Speakers

 

Link to comment
Share on other sites

Link to post
Share on other sites

4 hours ago, LukaH said:

hide yo fridges, hide yo microwaves,.....

OP needs to select this as beat answer xD

 

@Lurick

Fanboys are the worst thing to happen to the tech community World. Chief among them are Apple fanboys. 

Link to comment
Share on other sites

Link to post
Share on other sites

17 minutes ago, Ginger137 said:

OP needs to select this as beat answer xD

 

@Lurick

This is Tech News so there is no best answer except "F#ck EA". 

Cor Caeruleus Reborn v6

Spoiler

CPU: Intel - Core i7-8700K

CPU Cooler: be quiet! - PURE ROCK 
Thermal Compound: Arctic Silver - 5 High-Density Polysynthetic Silver 3.5g Thermal Paste 
Motherboard: ASRock Z370 Extreme4
Memory: G.Skill TridentZ RGB 2x8GB 3200/14
Storage: Samsung - 850 EVO-Series 500GB 2.5" Solid State Drive 
Storage: Samsung - 960 EVO 500GB M.2-2280 Solid State Drive
Storage: Western Digital - Blue 2TB 3.5" 5400RPM Internal Hard Drive
Storage: Western Digital - BLACK SERIES 3TB 3.5" 7200RPM Internal Hard Drive
Video Card: EVGA - 970 SSC ACX (1080 is in RMA)
Case: Fractal Design - Define R5 w/Window (Black) ATX Mid Tower Case
Power Supply: EVGA - SuperNOVA P2 750W with CableMod blue/black Pro Series
Optical Drive: LG - WH16NS40 Blu-Ray/DVD/CD Writer 
Operating System: Microsoft - Windows 10 Pro OEM 64-bit and Linux Mint Serena
Keyboard: Logitech - G910 Orion Spectrum RGB Wired Gaming Keyboard
Mouse: Logitech - G502 Wired Optical Mouse
Headphones: Logitech - G430 7.1 Channel  Headset
Speakers: Logitech - Z506 155W 5.1ch Speakers

 

Link to comment
Share on other sites

Link to post
Share on other sites

I have the solution! /s

 

win311logo.gif

Main rig on profile

VAULT - File Server

Spoiler

Intel Core i5 11400 w/ Shadow Rock LP, 2x16GB SP GAMING 3200MHz CL16, ASUS PRIME Z590-A, 2x LSI 9211-8i, Fractal Define 7, 256GB Team MP33, 3x 6TB WD Red Pro (general storage), 3x 1TB Seagate Barracuda (dumping ground), 3x 8TB WD White-Label (Plex) (all 3 arrays in their respective Windows Parity storage spaces), Corsair RM750x, Windows 11 Education

Sleeper HP Pavilion A6137C

Spoiler

Intel Core i7 6700K @ 4.4GHz, 4x8GB G.SKILL Ares 1800MHz CL10, ASUS Z170M-E D3, 128GB Team MP33, 1TB Seagate Barracuda, 320GB Samsung Spinpoint (for video capture), MSI GTX 970 100ME, EVGA 650G1, Windows 10 Pro

Mac Mini (Late 2020)

Spoiler

Apple M1, 8GB RAM, 256GB, macOS Sonoma

Consoles: Softmodded 1.4 Xbox w/ 500GB HDD, Xbox 360 Elite 120GB Falcon, XB1X w/2TB MX500, Xbox Series X, PS1 1001, PS2 Slim 70000 w/ FreeMcBoot, PS4 Pro 7015B 1TB (retired), PS5 Digital, Nintendo Switch OLED, Nintendo Wii RVL-001 (black)

Link to comment
Share on other sites

Link to post
Share on other sites

16 hours ago, Lurick said:

So far various device types from routers, to NAS boxes, to linux machines and temperature sensors have been seen as being infected.

Um I think your lying to us. Only Windows is vulnerable. Linux is supposed to be superior like Mac.. /s

 

Seriously though, not sure why consumers but this garbage. No one really seems to care about security... It's always in the back burner.

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Ryujin2003 said:

Um I think your lying to us. Only Windows is vulnerable. Linus is supposed to be superior like Mac.. /s

 

Seriously though, not sure why consumers but this garbage. No one really seems to care about security... It's always in the back burner.

Some random class in some random grade...

Some teacher: "Alright students, remember sharing is caring. That's it for today."

Ten years later...

That teachers student: "Oh, I can use this smart device and control it from my phone, awesome!"

Some random LTT forum member: "Hey man, that thing has terrible security and hackers could easily get into it and infect the rest of your stuff."

That teachers student: "It just controls my house appliances, so what if someone else can see it, I have nothing to hide mister you know everything."

Some random LTT forum member: "*Sighs* Whatever, I tried."

Link to comment
Share on other sites

Link to post
Share on other sites

Here it is directly from the source https://research.checkpoint.com/new-iot-botnet-storm-coming/ There is also  a full listing of affected devices at that link. But it appears only devices running on the Lua programming language are targeted. So no Pc's, smartphones, etc. Lua code is run in a register-based VM like dalvic for Android. Lua is basically a very light programming language which makes it ideal for IoT devices. I'd suggest even if your device isn't listed, might still not be a bad idea to figure out what programming language is used on your gadgets.

Link to comment
Share on other sites

Link to post
Share on other sites

7 hours ago, Coaxialgamer said:

These IoT devices really should require first time password setup . Default settings on these devices is turning out to be way too much of an issue.

Even if the gadget forces the user to change the password in most cases the user will use the worst password possible (1234. abcd, etc). Not to mention that when the manufacturer makes the program for these security isnt their priority(probably its at the bottom of the list). Make it as cheap as possible, thats their motto...

Link to comment
Share on other sites

Link to post
Share on other sites

I like the idea of making devices that anybody can use, but this is getting ridiculous. They really should have a test administered by ISPs before letting people connect anything to the internet. Devices should require some form of username/password configuration out of the box before it can be used and UPnP should be disabled by default on all routers to prevent these devices from being publicly accessible.

-KuJoe

Link to comment
Share on other sites

Link to post
Share on other sites

10 hours ago, leadeater said:

Because you need to flush it when you're not at home lol.

Gotta spook anyone who might be rummaging through your bathrooms :D 

Current Network Layout:

Current Build Log/PC:

Prior Build Log/PC:

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, KuJoe said:

UPnP should be disabled by default on all routers to prevent these devices from being publicly accessible.

Maybe make it so UPnP only works with certified devices, a bit like signed drivers in modern Windows.

Link to comment
Share on other sites

Link to post
Share on other sites

5 minutes ago, leadeater said:

Maybe make it so UPnP only works with certified devices, a bit like signed drivers in modern Windows.

As somebody who likes to go the "build you own" route, I don't like this idea. :P

-KuJoe

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, KuJoe said:

As somebody who likes to go the "build you own" route, I don't like this idea. :P

Well you could also have the "I know what I'm doing option disable certified device enforcement" option.

 

Edit:

Not that I even use UPnP though so what do I care :P

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, leadeater said:

Well you could also have the "I know what I'm doing option disable certified device enforcement" option.

And the common potato would check that once they found out it would "Make their PC faster" or whatever garbage came up to trick people into disabling it :) 

 

People are stupid, we need to eliminate people, it's the only way!

Current Network Layout:

Current Build Log/PC:

Prior Build Log/PC:

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, leadeater said:

Well you could also have the "I know what I'm doing option disable certified device enforcement" option.

But only in the dev/debug menu so people couldn't just click a button to disable it. :)

-KuJoe

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, leadeater said:

Not that I even use UPnP though so what do I care :P

Have you ever used it? I enabled it one time for my NAS and after using it for 15 minutes I disabled it because it started opening ports I didn't need and weren't even in the documentation so I wasn't sure what they were used for.

 

My perspective is if you want to poke holes in your network's security, you should have to manually do it.

-KuJoe

Link to comment
Share on other sites

Link to post
Share on other sites

13 hours ago, ARikozuM said:

Am I the only one here who has placed all my smart locks and devices (TV's, fridge, etc.) onto a closed network with no internet access unless opened by me? Surely, I can't be. 

Same here. Have my NAS on a seperate wired router, which is not on the internet.

\\ QUIET AUDIO WORKSTATION //

5960X 3.7GHz @ 0.983V / ASUS X99-A USB3.1      

32 GB G.Skill Ripjaws 4 & 2667MHz @ 1.2V

AMD R9 Fury X

256GB SM961 + 1TB Samsung 850 Evo  

Cooler Master Silencio 652S (soon Calyos NSG S0 ^^)              

Noctua NH-D15 / 3x NF-S12A                 

Seasonic PRIME Titanium 750W        

Logitech G810 Orion Spectrum / Logitech G900

2x Samsung S24E650BW 16:10  / Adam A7X / Fractal Axe Fx 2 Mark I

Windows 7 Ultimate

 

4K GAMING/EMULATION RIG

Xeon X5670 4.2Ghz (200BCLK) @ ~1.38V / Asus P6X58D Premium

12GB Corsair Vengeance 1600Mhz

Gainward GTX 1080 Golden Sample

Intel 535 Series 240 GB + San Disk SSD Plus 512GB

Corsair Crystal 570X

Noctua NH-S12 

Be Quiet Dark Rock 11 650W

Logitech K830

Xbox One Wireless Controller

Logitech Z623 Speakers/Subwoofer

Windows 10 Pro

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, KuJoe said:

Have you ever used it? I enabled it one time for my NAS and after using it for 15 minutes I disabled it because it started opening ports I didn't need and weren't even in the documentation so I wasn't sure what they were used for.

 

My perspective is if you want to poke holes in your network's security, you should have to manually do it.

Well considering I haven't used an ISP modem since dialup no xD. I've always half bridged/bridged to a proper firewall since adsl onward because consumer routers/firewalls are just bleh feature wise.

 

I setup an ERLite-3 at a friends place where my offsite server is and that has UPnP support... but disabled.

Link to comment
Share on other sites

Link to post
Share on other sites

5 hours ago, leadeater said:

Need to be far more obscure.

 

hqdefault.jpg

ooohhhhh, good idea. ;)

Main rig on profile

VAULT - File Server

Spoiler

Intel Core i5 11400 w/ Shadow Rock LP, 2x16GB SP GAMING 3200MHz CL16, ASUS PRIME Z590-A, 2x LSI 9211-8i, Fractal Define 7, 256GB Team MP33, 3x 6TB WD Red Pro (general storage), 3x 1TB Seagate Barracuda (dumping ground), 3x 8TB WD White-Label (Plex) (all 3 arrays in their respective Windows Parity storage spaces), Corsair RM750x, Windows 11 Education

Sleeper HP Pavilion A6137C

Spoiler

Intel Core i7 6700K @ 4.4GHz, 4x8GB G.SKILL Ares 1800MHz CL10, ASUS Z170M-E D3, 128GB Team MP33, 1TB Seagate Barracuda, 320GB Samsung Spinpoint (for video capture), MSI GTX 970 100ME, EVGA 650G1, Windows 10 Pro

Mac Mini (Late 2020)

Spoiler

Apple M1, 8GB RAM, 256GB, macOS Sonoma

Consoles: Softmodded 1.4 Xbox w/ 500GB HDD, Xbox 360 Elite 120GB Falcon, XB1X w/2TB MX500, Xbox Series X, PS1 1001, PS2 Slim 70000 w/ FreeMcBoot, PS4 Pro 7015B 1TB (retired), PS5 Digital, Nintendo Switch OLED, Nintendo Wii RVL-001 (black)

Link to comment
Share on other sites

Link to post
Share on other sites

15 hours ago, AresKrieger said:

Just wait til it gets hacked and turns off the heat in the winter while you're away ?

You mean like this?

https://hothardware.com/news/nest-thermostats-knocked-offline-during-dead-of-winter-due-to-software-bug

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×