Quantcast
Channel: StudioSysAdmins Message Board
Viewing all articles
Browse latest Browse all 3749

Web server directory traversal vuln on a dish washer

$
0
0
Web server directory traversal vuln on a dish washer
posted by Will Rosecrans on March 27, 2017, 2:10 p.m. (1 day ago)
Fun fact: the only time I ever burned down my dad's house while I was house sitting for him, it turned out that it was the dish washer. The heating element got stuck on and it never got cycled because nobody was doing dishes. After about two days, it burned through the insulation and took out the house.

So, if your iot dish washer has a security vulnerability that could let it lock on a heating element, this could be a privilege escalation exploit of the worst kind.


On Mar 27, 2017 7:27 PM, "Jean-Francois Panisset" <panisset@gmail.com> wrote:
Looks like we need to add the appliances in the office kitchen to the list of gear to "worry" about...

Made me think of that bit in Mr Robot where they took over all the IoT devices in the fancy house to drive out the owner.

JF


To unsubscribe from the list send a blank e-mail to mailto:studiosysadmins-discuss-request@studiosysadmins.com?subject=unsubscribe

Thread Tags:
  discuss-at-studiosysadmins 

0 Responses   0 Plus One's   0 Comments  
 
Fun fact: the only time I ever burned down my dad's house while I was house sitting for him, it turned out that it was the dish washer. The heating element got stuck on and it never got cycled because nobody was doing dishes. After about two days, it burned through the insulation and took out the house.

So, if your iot dish washer has a security vulnerability that could let it lock on a heating element, this could be a privilege escalation exploit of the worst kind.


On Mar 27, 2017 7:27 PM, "Jean-Francois Panisset" <panisset@gmail.com> wrote:
Looks like we need to add the appliances in the office kitchen to the list of gear to "worry" about...

Made me think of that bit in Mr Robot where they took over all the IoT devices in the fancy house to drive out the owner.

JF


To unsubscribe from the list send a blank e-mail to mailto:studiosysadmins-discuss-request@studiosysadmins.com?subject=unsubscribe


Viewing all articles
Browse latest Browse all 3749

Trending Articles