• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

IoT weakness

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    IoT weakness

    Half Baked IoT Stove Could Be Used As A Remote Controlled Arson Device | Hackaday

    [Pen Test Partners] have found some really scary vulnerabilities in AGA range cookers. They are connected by SMS by which a mobile app sends an unauthenticated SMS to the AGA to give it commands for instance preheat the oven, You can also just tell your AGA to turn everything on at once.

    The problem is with the web interface; it allows an attacker to check if a user’s cell phone is already registered, allowing for a slow but effective enumeration attack. Once the attacker finds a registered device, all they need to do is send an SMS, as messages are not authenticated by the cooker, neither is the SIM card set up to send the messages validated when registered.
    You could burn half of Islington down!
    Always forgive your enemies; nothing annoys them so much.

    #2
    Office really hot today. It was reported last night - however night shift do not have internet access so could do nothing until day shift arrived.

    Someone was telling me MBNA Chester heating was controlled from the USA. Great fun with the time difference.

    Comment


      #3
      Wasn't there something recently about a similar vulnerability in washing machines?
      Originally posted by Stevie Wonder Boy
      I can't see any way to do it can you please advise?

      I want my account deleted and all of my information removed, I want to invoke my right to be forgotten.

      Comment


        #4
        Originally posted by SimonMac View Post
        Wasn't there something recently about a similar vulnerability in washing machines?
        yep kiddies with libraries they don't understand.
        Always forgive your enemies; nothing annoys them so much.

        Comment


          #5
          The old oil/wood ones don't have any electrics in them, never mind electronics. Great when there's a blackout.
          …Maybe we ain’t that young anymore

          Comment


            #6
            another reason why the IoT is just pretty dumb and pointless!

            Comment


              #7
              Originally posted by SimonMac View Post
              Wasn't there something recently about a similar vulnerability in washing machines?
              And a dildo.

              Comment


                #8
                Originally posted by original PM View Post
                another reason why the IoT is just pretty dumb and pointless!
                Another reason why original PM is just pretty dumb and pointless!

                Comment


                  #9
                  Yep IoT is a bloody nightmare and most organisations are not even remotely aware how ****ed they are.

                  Comment


                    #10
                    How about a Wifi toilet paper dispenser. Instructions on how to download the app behind the toilet door.
                    "A people that elect corrupt politicians, imposters, thieves and traitors are not victims, but accomplices," George Orwell

                    Comment

                    Working...
                    X