Breaking News

New Vero L6 generation of the PSUs The Lockerstor Gen2 Series Brings 10-Gigabit Performance for 5-Gigabit Prices ASUS Republic of Gamers Launches ROG Matrix GeForce RTX 5090 Razer Unveils Raiju V3 Pro Elite Esports Controller For PS 5 Crucial UK Black Friday SSD Deals Are Live

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Researchers Show How Networks Can Be Hacked from a Lightbulb

Researchers Show How Networks Can Be Hacked from a Lightbulb

Enterprise & IT Feb 5,2020 0

Security researchers showed how a threat actor could exploit an IoT network (smart lightbulbs and their control bridge) to launch attacks on conventional computer networks in homes, businesses or even smart cities.

Check Point’s researchers focused on the market-leading Philips Hue smart bulbs and bridge, and found vulnerabilities (CVE-2020-6007) that enabled them to infiltrate networks using a remote exploit in the ZigBee low-power wireless protocol that is used to control a wide range of IoT devices.

With the help of the Check Point Institute for Information Security (CPIIS) in Tel Aviv University, the researchers were able to take control of a Hue lightbulb on a target network and install malicious firmware on it. From that point, they used the lightbulb as a platform to take over the bulbs’ control bridge, and attacked the target network as follows:

  • The hacker controls the bulb’s color or brightness to trick users into thinking the bulb has a glitch. The bulb appears as ‘Unreachable’ in the user’s control app, so they will try to ‘reset’ it.
  • The only way to reset the bulb is to delete it from the app, and then instruct the control bridge to re-discover the bulb.
  • The bridge discovers the compromised bulb, and the user adds it back onto their network.
  • The hacker-controlled bulb with updated firmware then uses the ZigBee protocol vulnerabilities to trigger a heap-based buffer overflow on the control bridge, by sending a large amount of data to it. This data also enables the hacker to install malware on the bridge – which is in turn connected to the target business or home network.
  • The malware connects back to the hacker and using a known exploit (such as EternalBlue), they can infiltrate the target IP network from the bridge to spread ransomware or spyware.

The research was disclosed to Philips and Signify (owner of the Philips Hue brand) in November 2019. Signify confirmed the existence of the vulnerability in their product, and issued a patched firmware version (Firmware 1935144040) which is now available on their site.

In a joint decision with Signify, Check Point decided to postpone the release of the full technical details of the research in order to allow Philips Hue clients to have enough time to safely update their products to the latest version.

Tags: HackingSmart HomeCybersecurity
Previous Post
Spotify Reports Rise in Premium Subscribers
Next Post
Seagate Set to Launch 18TB HDDs in The First Half of the Calendar Year 2020

Related Posts

  • MSI has been hacked, be warned about where you download files

  • Hackers gain access to PS5 Debug Menu and show decrypted PS5 firmware files

  • HP Threat Research Shows Attackers Exploiting Zero‐Day Vulnerability Before Enterprises Can Patch

  • EA Gets hacked - 780GB of data and sourcecode stolen

  • European Supercomputers Researching Covid-19 Report Hacking Attacks

  • Intel Confirms "Thunderspy" Risk in Thuerbolt Devices

  • Microsoft Offers You $100,000 If You Can Hack the Linux-based Azure Sphere

  • Zoom Users' Data have Been on Sale on Dark Web: report

Latest News

New Vero L6 generation of the PSUs
PC components

New Vero L6 generation of the PSUs

The Lockerstor Gen2 Series Brings 10-Gigabit Performance for 5-Gigabit Prices
Enterprise & IT

The Lockerstor Gen2 Series Brings 10-Gigabit Performance for 5-Gigabit Prices

ASUS Republic of Gamers Launches ROG Matrix GeForce RTX 5090
GPUs

ASUS Republic of Gamers Launches ROG Matrix GeForce RTX 5090

Razer Unveils Raiju V3 Pro Elite Esports Controller For PS 5
Gaming

Razer Unveils Raiju V3 Pro Elite Esports Controller For PS 5

Crucial UK Black Friday SSD Deals Are Live
Consumer Electronics

Crucial UK Black Friday SSD Deals Are Live

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Soundpeats Pop Clip

Soundpeats Pop Clip

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed