PDA

View Full Version : HUAT AH! now ISIS can hack and control Airports' Doors!


Sammyboy RSS Feed
05-04-2016, 04:10 AM
An honorable member of the Coffee Shop Has Just Posted the Following:

http://www.scmagazineuk.com/root-vul...rticle/487255/ (http://www.scmagazineuk.com/root-vulnerability-gives-hackers-remote-control-of-doors/article/487255/)



Danielle Correa, Production Editor
April 04, 2016
Root vulnerability gives hackers remote control of doors
Share this article:
facebook
twitter
linkedin
google
0
Email
Print
A new root vulnerability, allows hackers to easily open networked door controllers in airports, university campus, hospitals, government facilities and other organisations.

According to Rickey Lawshae, researcher with Trend Micro's DVLabs division, HID Global's VertX and Edge controllers can be remotely managed by attackers over the network and a service called discoveryd that listens to UDP probe packets on port 4070.

The door controller responds with its physical MAC address, device type, firmware version and other revealing information when the packet is received. Apparently, discoveryd also responds to a command called command_blink_on that can be used to change the blinking pattern of the controller's status LED.

The discoveryd service runs as root, so whatever command sent will give complete control over the device, including alarm and locking functions. “This means that with a few simple UDP packets and no authentication whatsoever, you can permanently unlock any door connected to the controller. And you can do this in a way that makes it impossible for a remote management system to relock it,” Lawshae said in his blog post.

A patch has been made available through HID's partner portal.*


Click here to view the whole thread at www.sammyboy.com (http://www.singsupplies.com/showthread.php?227690-HUAT-AH!-now-ISIS-can-hack-and-control-Airports-Doors!&goto=newpost).