Skip to main content

Posts

Showing posts from September, 2018

Hacking your health (week 5)

In early August, researchers demonstrated at the Black Hat USA convention that pacemakers are still very vulnerable. The researchers asked people with medical implants to leave the are for safety reasons and then began their demonstration. Billy Rios and Jonathan Butts showed how malware can be installed remotely on implants such as pacemakers and insulin pumps. They blamed the lack of encryption and the software delivery methods as the main breaches in security. They also demonstrated that they could breach CareLink 2090 programmer, a program used by doctors to control implanted pacemakers. They showed 2 hacks, one that delivered a large shock and another that stopped the pacemaker from shocking, both could be used for deadly reasons. These attacks are due to firmware not being digitally signed and updates that are sent out are not encrypted in any way. When they asked Medtronic, the creator of the devices and program, about the lack of security they stated that the threat is 'low...

Stuxnet (week 4)

In 2010, the Natanz uranium  enrichment plant in Iran was experiencing rapid failure of centrifuges used to enrich uranium gas. Five months after replacing and repairing the centrifuges, they noticed that computers were crashing and rebooting multiple times. After calling in a third party to investigate, they found many malicious files, which is now classified as the world's first digital weapon. The bug, known as Stuxnet, was the cause of the failures and crashes. Development of Stuxnet was started in 2005 by several coders in the US and Israel. The bug works similarly to program used in the Russian Pipeline Explosion incident. It was designed to cause physical failures with equipment, however, unlike the pipeline incident, Stuxnet stopped alarms from triggering while continuing to overload equipment and it was able to spread itself to other computers. While Stuxnet was discovered in 2010, it was released in 2009 and a 'test run' was launched in 2008. In 2009, Stuxnet ...

The Russian Pipeline Explosion (week 3)

In 1981, it was discovered by the CIA that Russian KGB agents were stealing technology and software from US factories and researchers, some of which was to assist with the construction of a major natural gas pipeline through Siberia. When the US learned about this, Ronald Reagan and the CIA Director, William Casey, devised a plan. A program called Farewell was installed into several computers that they knew would be stolen. The Farewell  program was designed to run push valves, turbines, and other equipment to their breaking point and then reset them so no alarms would be triggered. Eventually, in the summer of 1982, the equipment failed and caused a massive explosion in Siberia. The explosion was so large that it could be seen from space and was the largest non-nuclear blast ever recorded. The explosion was called an equipment failure until 2004, when the CIA made the incident public. The exact origin and design of the Farewell  program has not been released, though versi...

Agent.BTZ (aka Autorun) - week 2

Agent.BTZ is possibly one of the most famous cyber attacks in American history. In 2008, a flash drive with the bug was inserted into a computer at a military base in the Middle East. Once in, it spread to other systems. To combat the bug, the military created a task force called ‘Yankey Buckshot’. This task force was tasked with containing the bug, which took nearly 14 months to do. This bug spreads by generating a AUTORUN.INF file in each drive it can reach. It then scans the system for useful data, opens a backdoor, and sends the information through. The main issue with Agent.BTZ is that it replicates itself and changes constantly. As of 2014, there was still traces of the bug in some systems, that’s why their efforts were to contain it instead of destroy it. The origin of the bug is still unknown, though it is theorized that it may have originated from Russia or China. This bug was written in Assembler (x86-32 bit) and is now thought to be created by a single person. In 2...