WOBURN, MA – February 7, 2018 — /BackupReview.info/ — Kaspersky Lab researchers have helped uncover a number of unknown vulnerabilities that have left gas stations around the world exposed to remote takeover, often for years. The vulnerabilities were found in an embedded gas station controller, of which there are currently over 1,000 installed and online. The manufacturer was notified when the threat was confirmed.

Ido Naor, senior security researcher at Kaspersky Lab, together with another researcher found the controller during unrelated research into devices with open connections to the internet. In many cases, the controller had been placed in the fuel station over a decade ago and had been connected to the internet ever since.

The controller, which runs a Linux machine, operates with high privileges and the researchers discovered a number of vulnerabilities that leave the device, as well as the systems it is connected to, open to cyberattacks. For example, the researchers were able to monitor and configure many of the gas station settings.

An intruder able to bypass the login screen and gain access to the main interfaces would be able to do any of the following:

  • Shut down all fueling systems
  • Change the fuel prices
  • Cause fuel leakages
  • Circumvent payment terminals to steal money (the controller connects directly to the payment terminal, so payment transactions could be hijacked)
  • Scrape vehicle license plates and driver identities
  • Execute code on the controller unit
  • Move freely within the gas station network

“When it comes to connected devices, it is easy to focus on the new and to forget about products installed many years ago that might be leaving the business wide open to attack,” said Ido Naor, senior security researcher, Kaspersky Lab. “The damage that could be done by sabotaging a gas station doesn’t bear thinking about. We have shared our findings with the manufacturer.”

The vulnerabilities have also been reported to MITRE and the research is ongoing.

Kaspersky Lab advises manufacturers of connected internet-of-thing devices to consider the security of their products from the very first moment of development and design, and to review legacy devices for possible security vulnerabilities. Users of connected devices are urged to regularly review the security of these devices and not to rely on factory settings.

More information on the research is available on Securelist.

About Kaspersky Lab
Kaspersky Lab is a global cybersecurity company that celebrated its 20 year anniversary in 2017. Kaspersky Lab’s deep threat intelligence and security expertise is constantly transforming into next generation security solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe. The company’s comprehensive security portfolio includes leading endpoint protection and a number of specialized security solutions and services to fight sophisticated and evolving digital threats. Over 400 million users are protected by Kaspersky Lab technologies and we help 270,000 corporate clients protect what matters most to them. Learn more at www.kaspersky.com

For the latest in-depth information on security threat issues and trends, please visit:

Securelist | Information about Viruses, Hackers and Spam
Follow @Securelist on Twitter

Threatpost | The First Stop for Security News
Follow @Threatpost on Twitter

Media Contact
Jessica Bettencourt

Source: Kaspersky Lab



General Tags: data security, compare online backups, online data backup, online backup services, top rated online backups, cloud computing, online backup providers directory, backing up online, CEO interviews, SaaS, online file backup, data storage, online backup news, software as a service, online backup companies, online backup reviews, online backup, online file storage

Like us on Facebook

Do you like this post? Subscribe to our RSS feed ===========================


Related posts:

  1. Hacking a Living Room: Kaspersky Lab Finds Multiple Vulnerabilities in Popular Connected Home Entertainment Devices
  2. Kaspersky Lab Discovers Vulnerabilities in Popular Pet Trackers
  3. Kaspersky Lab Sheds Light on “Darkhotel,” Where Business Executives Fall Prey to an Elite Spying Crew
  4. Digital Profiling: Kaspersky Lab Experts Uncover How Much Data Your Smartwatch Can Reveal
  5. Kaspersky Lab Discovers Critical Vulnerabilities in Popular Industrial Protocol
  6. Cohesity Expands Security Capabilities by Empowering Enterprises — For the First Time — to Uncover Vulnerabilities and Cyber Exposures Using Backup Data
  7. Kaspersky Lab DDoS Intelligence Report: Old Vulnerabilities Return, eSports and Cryptocurrencies as Leading Targets
  8. Software Vulnerabilities Create Internal Data Security Problems for 39 Percent of Companies
  9. Kaspersky Finds Ransomware Now Targeting Backup Data
  10. Kaspersky Lab and WISeKey Launch an Encrypted Vault for all that is Precious on your Mobile: The WISeID Kaspersky Lab Security App

Tags: ,