Best Review

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Thursday, 4 July 2013

Emergency Alert System Vulnerable to Hackers, Report Finds

Posted on 17:48 by Unknown

Hackers could have a field day with the Emergency Alert System (EAS), thanks to vulnerabilities with equipment used to transmit the alerts, according to a new report.

According to Seattle-based IOActive, the systems that intercept emergency messages from federal officials and then interrupt regular broadcasts to transmit the message - known as DASDEC - are susceptible to cyber attacks.

"These DASDEC application servers are currently shipped with their root privileged SSH key as part of the firmware update package," Mike Davis, principal research scientist for IOActive, said in a statement. "This key allows an attacker to remotely log on in over the Internet and can manipulate any system function."

Hackers might disrupt a station's ability to transmit in order to broadcast their own, false message, according to Davis, who said "re-engineering needs to be done on the digital alerting system side and firmware updates to be pushed to all appliances."

The DASDEC systems are produced by New York-based Monroe Electronics. In April, Monroe released a software update for the DASDEC messaging system that it said resolved "potential security vulnerabilities and improve[d] several operational features" for the EAS.

That included the removal of default SSH keys, a simplified way for the user to load new SSH keys, and changes to password handling, among other things.

Monroe did not immediately respond to a request for comment, nor did the Federal Emergency Management Agency (FEMA), which handles oversight of the EAS.

But in a July 2 notice, the Homeland Security Department, which governs FEMA, addressed the IOActive report.

"IOActive reports that the administrative web server uses a predictable, monotonically increasing session ID," DHS said. "This finding is based on running the web server in a test environment. Testing on a variety of firmware versions on devices both at the factory and in the field, Monroe Electronics could not reproduce this finding."

Still, DHS did acknowledge vulnerabilities within the EAS. To fix the issue, the agency pushed for an update, which was rolled out April, but also encouraged users to: disable the compromised SSH key; manually inspect SSH keys; restrict access; and change default passwords.

According to IOActive, "each EAS participant needs to upgrade any Monroe hardware they're currently using. To the best of my knowledge there is still a significant number of vulnerable systems on the Internet that have not patched this issue. Additionally, many EAS systems run in a peer-to-peer network so even partial patching of the issue may still result in widespread fictitious EAS alerts."

IOActive's report comes several months after hackers breached a Montana TV station's emergency alert system, and sent out a bogus warning about zombie attacks. "Civil authorities in your area have reported that the bodies of the dead are rising from their graves and attacking the living," the message told viewers.

The zombie hackers reportedly struck in Michigan and New Mexico, too.

The EAS is used by broadcast, cable, satellite, and wireline providers and allows for quick alerts during an emergency. The first-ever nationwide EAS test was conducted in Nov. 2011 with a 30-second interruption of almost every radio and TV broadcast in the nation.


Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in News | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • RGT Force Feedback Pro Clutch Edition
    The RGT Force Feedback Pro Clutch Edition wheel and pedal set gives you the features and customization tools you want for a realistic racing...
  • France Drops Internet Disconnection From '3 Strikes' Piracy Law
    France has struck down the port...
  • Intel 335 Series 180GB SSD
    Intel has had a prominent role in the consumer solid-state drive (SSD) market since it launched its 80GB X25-M solid-state drive back i...
  • Microsoft Ending MSN TV Sept. 30
    Time to give the bad news to gr...
  • Accounting Software: Tips for First Time Users
    If you're like most business owners, you prefer to focus on the things that got you started satisfying clients, making a quality produc...
  • Tech Made in the U.S.A.
    Desktops ...
  • Brother MFC-9130CW
    Projectors PCMag.com provides up...
  • Epson Artisan 730
    Epson touts the Epson Artisan 730 ($199.99 direct) as an all-in-one for the photo hobbyista more accurate description than you might as...
  • The 5 Best Scanners for Macs
    OB Roundup As a Mac owner, ...
  • Review: Nikon Coolpix S6500
    Introduction Nikon's Coolpix S6500 combines Wi-Fi connectivity with a 12x optical zoom lens and a 16 million pixel sensor, all of which ...

Categories

  • Best Review
  • Electronic Review
  • News
  • Review
  • Tutorial

Blog Archive

  • ▼  2013 (500)
    • ▼  July (353)
      • Haswell vs. Ivy Bridge: A Look at Old and New
      • Seagate Unleashes New Ultrathin Hard Disk Drive
      • Glidecam HD-2000
      • Ask Alex: When to Send a Thank-You Email
      • HBO GO, WatchESPN Added to Apple TV
      • Toshiba 39L2300U
      • Panasonic TC-P50ST50
      • New Rules on Kids' Online Privacy Require Adults t...
      • HP LaserJet Enterprise 700 Printer M712dn
      • Viber Updates Windows Phone 8, Desktop Apps
      • From GPS to Watches: Killed by the Cell Phone
      • Panasonic TC-P60ST50
      • Microsoft Tips Windows 8.1 Preview, Smaller Window...
      • Sharp Introduces First THX-Certified, 70-Inch 4K HDTV
      • HP LaserJet Enterprise 700 Printer M712dn
      • At Apple, Steve Jobs' Legacy Lives On
      • Aereo Expanding to Chicago in September
      • IBM Acquires Cloud-Computing Firm SoftLayer
      • Bitdefender's Wildly Different Antivirus Tools Bot...
      • New Dropbox Platform Syncs App Data
      • Digital Storm Virtue
      • Facebook App Beta Testing; Verizon LTE Almost Fini...
      • Why Instagram Videos Stink
      • Intel Lifts the Curtain on Thunderbolt 2
      • Tribeca Film Festival Breaks Out From the Screen
      • Canon Color imageClass MF8280Cw
      • Samsung's 55-Inch Curved OLED Now Selling for $13,000
      • France Drops Internet Disconnection From '3 Strike...
      • How to Turn on Two-Factor Authentication for Facebook
      • Panasonic TC-P65ST50
      • HP LaserJet Enterprise flow MFP M525c
      • Digital Storm Virtue
      • Apple's Cheap Shot Bodes Ill for Company
      • Global LCD TV Shipments Fall for First Time Ever
      • Sony Unveils $2,000 Digital Binoculars With Image,...
      • How to Turn on Two-Factor Authentication For Your ...
      • Seiki SE39UY04
      • Report: Google Developing Android-Powered Game Con...
      • Facebook's New Swedish Data Center Goes Live
      • Nokia Chat Beta for Lumia Phones Goes Global
      • Chromium-Based Opera 15 Arrives on Windows, Mac
      • Yelp Expands Into Food Delivery
      • Seagate Slim for Mac
      • Facebook App Beta Testing; Verizon LTE Almost Fini...
      • Memjet C6010 Powered by Memjet
      • Buying an HDTV: Frequently Asked Questions
      • Comcast Boosts Xfinity Parental Controls
      • Bringing the Checkout Counter to You
      • Advanced Persistent Threats Rare, But We're Still ...
      • GoPro Hero3 Black Edition
      • Mobile Threat Monday: Android Spamware, In-App Bil...
      • Dell B1165nfw Mono Laser Multifunction Printer
      • Amazon Launches Jet City Comics With George R.R. M...
      • Samsung PN60F8500
      • What Is a Resilient City?
      • Sony Action Cam
      • And Now: Frickin' Laser TVs
      • Infographic: The Future Is in the Cloud
      • $3,500 Asus 4K Monitor Now Up for Pre-Order
      • Ubisoft Database Hack; NYC Gets .nyc; Tesla Petiti...
      • Tech Made in the U.S.A.
      • Samsung CLP-680ND
      • Crowdfunding For Environmental Change
      • Drift Innovation HD Ghost
      • Report: Apple, TWC Nearing Deal for Apple TV Progr...
      • Microsoft Opens Build; Nvidia Shield Delayed; FTC ...
      • Your All-in-One Guide to Super Bowl XLVII
      • Researchers Demo 3D Printing of Liquid Metal
      • Infographic: Digital Attacks! Protect Yourself Aga...
      • Hisense 55K610GW
      • Brother MFC-9130CW
      • Samsung PN60F8500
      • Drift Innovation HD Ghost
      • Major Microsoft Shakeup Rumored for Thursday
      • It's Not the iWatch, Deneve May Have Other Designs...
      • Porn Spam on YouTube: The Struggle Against Interne...
      • Are Dual-Boot Android and Windows Laptops Viable?
      • Sony's Howard Stringer to Retire in June
      • Intel 335 Series 180GB SSD
      • Samsung Acquires Boxee for Reported $30M
      • MSN TV Shuttering; Samsung Shares Dip; Apple App S...
      • Apple TV or Bust
      • Samsung PN64F8500
      • GoPro Hero3 Black Edition
      • Are Dual-Boot Android and Windows Laptops Viable?
      • Brother MFC-9330CDW
      • ADV: The Antispyware Center from PCMag.com
      • Nokia Lumia 1020; Garmin HUD Displays Directions; ...
      • NASA to Search for Life on Mars in 2020
      • Report: SSD Prices On the Rise Due to Tight Supply
      • Samsung PN60F8500
      • Lenovo Desktops Scale Down for Small Biz
      • Android Master Key Bug Not a Risk if You Stick Wit...
      • Get Organized: 4 Tips for Organizing iPhone Apps
      • Hisense 50K610GW
      • Netflix, CBS Renew Streaming Deal, Add New Shows t...
      • Sony Action Cam
      • New Dropbox Platform Syncs App Data
      • Is This the New LG Optimus G2?
      • Brother MFC-9340CDW
    • ►  June (147)
Powered by Blogger.

About Me

Unknown
View my complete profile