Stories
Slash Boxes
Comments

SoylentNews is people

posted by cmn32480 on Monday October 24 2016, @10:52AM   Printer-friendly
from the all-your-PC-are-belong-to-us dept.

With all the noise about default passwords on Internet-connected devices, it is maybe time to revisit a 2012 paper on the Carna botnet. There were probably other even quieter ones before that and certainly default passwords have been long exploited. The Carna botnet operator went to the trouble of publishing a paper four years ago. He or she was playing around with the Nmap Scripting Engine (NSE) and discovered an amazing number of open embedded devices on the Internet. Many allowed login with empty or default credentials and were thus used to build a distributed port scanner to scan all IPv4 addresses to form a kind of census of the IPv4 Internet. The scanned data is in the public domain and available for download and analysis over Bittorrent.

IPv6 is another can of worms and the IPv4 data is thus of historical interest.


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 1) by fraxinus-tree on Monday October 24 2016, @11:32AM

    by fraxinus-tree (5590) on Monday October 24 2016, @11:32AM (#418103)

    I wonder what kind of trouble the author went in? Anyway, a good read and a good pile of data to analyze that I didn't noticed.

  • (Score: 2) by JoeMerchant on Monday October 24 2016, @12:41PM

    by JoeMerchant (3937) on Monday October 24 2016, @12:41PM (#418122)

    The Snowden kind of trouble, but enforced by corporations instead of governments. This is info that needs to be out there; without awareness business as usual will continue.

    --
    🌻🌻 [google.com]