Wednesday, 14 August 2013

Blackout warning: Philips “Smart lightbulbs” can be switched off by malware – and won’t come back on

Philips Hue lighting system is vulnerable to attacks which can cause a “perpetual blackout” in the homes of users, according to a security researcher.
The Hue wireless system – on sale in Apple store – controls wireless LED light bulbs in the home via a wireless bridge, and can be controlled by iOS and Android apps. But researcher Nitesh Dhanjani says that the system it uses to authenticate devices means that it’s all too easy to turn lights on and off in other people’s homes. .
Attackers could “black out” all the Hue lights from nearby (any nearby location within reach of the same Wi-Fi network) by using malware to capture one of the list of “whitelisted tokens” – and then “issue ‘all lights off’ instructions.” Dhanjani says that it’s also difficult for users to regain control of their system.
“The script infinitely issues a blackout command. If the victim manually switches the bulbs off and on, the lights will flicker on for less than half a second and then go off again until the victimrecognized and terminates the script. Alternatively, the victim can disconnect the bridge – however, the blackout will reoccur when the victim reconnects the bridge.”
Dhanjani explains that the system’s method of “recognizing” devices leaves it open to attack. “The hue bridge uses a whitelist of associated tokens toauthenticate requests. Any user on the same network segment as the bridge can issue HTTP commands toit to change the state of the lightbulb. In order to succeed, the user must also know one of the whitelisted tokens.It was found that in case of controlling the bulbs via the hue website and the iOS app, the secret whitelist token was not random but the MD5 hash of the MAC address of the desktop or laptop or the iPhone or iPad. This leaves open a vulnerability whereby malware on the internal network can capture the MAC address active on the wire (using the ARP
cache of the infected machine.”
At the recent Black Hat security conference in Las Vegas, researchers showed off hacks that could affect “connected” devices such as televisions, door alarms and toilets.
“By 2022, the average household with two teenage children will own roughly 50 such Internet connected devices, according to estimates by the Organization for Economic Co-Operation and Development,” Dhanjani says. “Our society is starting to increasingly depend upon Internet of Things devices to promote automation and increase our well being. As such, it is important that we begin a dialogue on how we can securely enable the upcoming technology.”
Hacks against the Hue website could also allow access, Dhanjani warns.
“The Internet app will accept a six-character password, and as we all know, users have a distressing habit of re-using passwords for lots of different sites – meaning that if a password leaks, an attacker can remotely control the system,” Richard Chirgwin writes in a report on The Register.
“Lighting is critical to physical security. Smart lightbulb systems are likely to be deployed in current and new residential and corporate constructions. An abuse case such as the ability of an intruder to remotely shut off lighting in locations such as hospitals and other public venues can result in serious consequences,” Dhanjani writes. “It is important that Philips and other consumer IoT organizations take issues like these seriously. In the age of malware and powerful botnets, it is vital that people’s homes be secure from vulnerabilities like these that can cause physical consequences.”
ESET Security Evangelist Stephen Cobb offers a basic guide to securing a household full of digital devices in a blog post here.“On a typical evening or weekend at home, how many computing devices is your household using?” Cobb asks. “In my house the answer is 10, and that’s just my wife and I. Before you decide we’re an extreme example, make sure your household computer count includes all of the laptops, tablets, iPods, smartphones and the like. Then think about the TV and DVD player, one or both of which may be connected to the home network. The fact is, many homes today are multi-device households, with numerous PCs, Macs, tablets and smartphones.”

YouTube download plug-ins hijack browsers to deliver malware-laced adverts

Two video plug-ins for YouTube hijack users visits to the site and insert extra adverts – some of which are being hijacked by “malvertisers”, sending users to fake adverts which attempt to infect their PCs.
Spider.io, a London analytics company which works in advertising fraud, say that two plug-ins, Easy YouTube Video Downloader and Best Video Downloader, supplied as part of a bundle of browser tools, deliver unwanted adverts whenever users visits the YouTube homepage.
“When a user who has installed these plugins visits youtube.com multiple display ad slots are injected across the YouTube homepage, channel pages, video pages and search results pages,” Spider.io writes. Some of these advert slots are being bought by major advertisers including “Domino’s, Ford, Kellogg’s, Norton, Toyota, Sprint, Walgreens and Western Union.”
Others are being bought by less reputable companies, and deliver “malware-laden” advertisements to users, Spider.io warns.
“The display ad slots injected by Sambreel are also being bought today by malvertisers—advertisers who provide malicious or malware-laden advertisements with a view to spreading malware to new users,” the company writes. “The first screenshot shows a fake alert, which suggests to the user that a Java update is required. If the user clicks the OK button, then the user is taken to the disreputable site shown in the second screenshot.”
A Google spokesperson, speaking to London’s Financial Times, said that the plug-ins violated YouTube’s Terms of Service, ““Applications that change users’ experiences in unexpected ways and provide no value to publishers are bad for users and bad for the web. We’re continuing to look into these types of bad actors and have banned them from using Google’s monetisation and marketing tools.”
Spider.io and the FT point out that Sambreel, the company behind the plug-ins, has already been blocked by Facebook for injecting adverts via adware browser plug-ins. The new tools were marketed by two companies, Yontoo and Alactro, which Spider.io says are subsidiaries of Sambreel.
Yontoo’s web page now says, “This product has been discontinued.”
An earlier blog post by ESET Security Evangelist Stephen Cobb described the impact of Yontoo on Mac OS X machines, “If you fall for it, a wealth of unwanted ads and redirections will likely follow, injected into pages on otherwise innocent sites. There are also reports of infection via phoney media players. The point is, criminals are using this plug-in to cheat online advertisers out of money by redirecting victims to sites that pay for traffic or clicks.”
“On December 9, 2011, the Wall Street Journal called Sambreel out for illegitimately injecting ads into Facebook and Google webpages via adware browser plugins like PageRage and BuzzDock,” Spider.io writes. “Facebook subsequently blocked its users from using Sambreel’s adware browser plugins whilst accessing Facebook webpages. With Sambreel’s adware publicly exposed, major sell-side platforms and ad exchanges like PubMatic, Rubicon Project, and OpenX dropped Sambreel as a supplier of display ad inventory in 2012.”