jeudi 13 décembre 2018

Vulnerabilities in connected electric car chargers could damage home networks

While modern electric vehicles are tested constantly for vulnerabilities, some of their essential accessories, such as the battery chargers, often remain neglected. Kaspersky Lab experts have discovered that electric vehicle (EV) chargers supplied by a major vendor carry vulnerabilities that can be exploited by cyberattackers, and that the consequences of a successful attack could include damage to the home electricity network.

Electric vehicles are a hot topic as their development makes a vital contribution to environmental sustainability. In some regions, public and private charging points are becoming commonplace. The growing popularity of electric vehicles led Kaspersky Lab experts to check widely available domestic chargers that include a remote access feature. The researchers found that, if compromised, the connected charger could cause a power overload that would take down the network it was connected to, causing both financial impact and, in the worst-case scenario, damaging other devices connected to the network.

The researchers found a way to initiate commands on the charger and to either stop the charging processor or set it to the maximum current possible. While the first option would only prevent a person from using the car, the second one could potentially cause the wires to overheat on a device that is not protected by a trip fuse.

All an attacker needs to do to change the amount of electricity being consumed is obtain Wi-Fi access to the network the charger is connected to. Since the devices are made for domestic use, security for the wireless network is likely to be limited. This means that attackers could gain access easily, for example by bruteforcing all possible password options, which is quite common: according to Kaspersky Lab statistics 94% of attacks on IoT in 2018 came from Telnet and SSH password bruteforcing. Once inside the wireless network, the intruders can easily find the charger’s IP-address. This, in turn, will allow them to exploit any vulnerabilities and disrupt operations.

All the vulnerabilities found were reported to the vendor and have now been patched.

“People often forget that in a targeted attack, cybercriminals always look for the least-obvious elements to compromise in order to remain unnoticed. This is why it is very important to look for vulnerabilities, not just in to unresearched technical innovations, but also in their accessories – they are usually a coveted prize for threat actors. As we have shown, vendors should be extra careful with connected vehicle devices, and initiate bug-bounties or ask cybersecurity experts to check their devices. In this case we were fortunate to have a positive response and a rapid patch of the devices, which helped to prevent potential attacks,” said Dmitry Sklyar, a security researcher at Kaspersky Lab.

Kaspersky Lab recommends taking following security measures:

• Regularly update all your smart devices to the latest software versions. Updates may contain patches for critical vulnerabilities, which, if left unpatched, may give cybercriminals access to your house and private life.
• Don’t use the default password for Wi-Fi routers and other devices, change it to strong ones and don’t use the same password for several devices.
• We recommend isolating the smart home network from the network used by your or your family’s personal devices for basic Internet searching. This is to ensure that if a device is compromised with generic malware through a phishing email, your smart home system won’t be affected.


MSR REVO Snowshoes & Tails

Purchased new in late 2017, red in color. Used recently once up Slide Mt. in the Catskills, for 3.0 miles. New tails included (never used). I personally prefer my EVO's over the REVO's. Asking $170 (shipping not included). Willing to meet locally near Middletown, N.Y., or in the Catskills at a trailhead or other location (cash only).


lundi 10 décembre 2018

Nye 12/09

Many adventures were had today.

I had selected Street & Nye for my next venture, as the distance/elevation seemed according to my abilities, given the winter conditions. I knew the trail had been broken in and at least one person had been there a week ago from a recording I saw on a popular app. For additional assurance, I presented myself on Sunday morning, assuming hikers would harden the trail on Saturday.

As I was prepping for my 7:45 start, another hiker passed by in the parking and he mentioned that he thought people had been up Street & Nye the day before. Indeed, when I got to the trail register, I saw 3 groups mentioning this as their destination (1 of which hadn’t signed out, I assume they forgot or came back another way). So, it was with renewed determination that I headed out on this beautiful and comparatively warm day.

Each season has its perks. Today, as I was walking West, the leafless trees allowed me to view both Street & Nye early on. The frozen Heart Lake with Algonquin backdrop was spectacular. And streams made a sort of gurgling chant – though perhaps this was a siren’s cursed call for me.
Things got complicated at the Indian Brook crossing. It was a river. With some sketchy-looking ice over 60% of it. I am borderline-OCD on trip selection/planning, so I’d read a ton of TR. The brook is often not passable in high water – I knew that.

But I was operating on the premise that many people had been through recently. I studied the layout for a while and chose what looked like a reasonable rock-hop combination. Now, I am not entirely certain what happen, but I suspect one of those rocks might’ve been an iceberg, so in the stream I went. I was in at least 1’ of water. But I hadn’t lost my balance (using my poles) and was 80% across, so I trudged on. I tried stepping on the ice, but it just gave way with a sickening crack. This is picture of where I crossed – in retrospect, it looks crazy:


I was on the opposite bank in short order and, as I was retrieving my change of socks and plastic bags to put in my boots, I reflected on my situation. I was not injured, I was not feeling cold at all, my spirits were good, I had a thermos of warm tea and other changes of clothes. I saw no reason not continue, despite what I had told my spouse (“at worse, if I fall in the stream, I’ll just come back, it’s close to the trailhead”).

Now to get back on the trail. This is when I suddenly realized this was not going to be an easy one (although I should’ve realize this before, one could say). There were no recent prints on this side and 6’’+ of snow lay on the path. When I got to the 2nd crossing, I saw the log on which you are supposed to go but it had 2’ of hard snow on it. I could find no other way, so started to clear some snow off it and pulled myself piggyback-style across the log.

After that, the snow deepened, and the path became less defined. 15 minutes later, I veered off path, the first of many such occurrences. Each time, I fired up the GPS and tracked back, also trying to erase the wrong tracks for those crazy enough to head this way. At the 3-mile mark, the fresh snow was a foot deep and the HP would soon become just a hint. But you could often tell when going off-track because while there is a solid base on the HP there is, and I am not exaggerating, 4-5’ of soft snow all around it. In fact, my poles were pretty much useless, they just sank in.

It was rough going. My hands were cold from stopping to check my position all the time. I was wet from all the snow coming down each time I touched a tree. My knee was doing great though (long story short, I’ve been doing PT for a month).

There is a grove of taller trees maybe .2 mile before the Street/Nye intersection. There was less snow there, and all ways seemed as likely. Somewhere around there, the HP turned left, but I did not. By the time I once again took out my phone, I was wading in deep snow, sometimes just lying on my back and shifting my legs to gain a yard. I was wary of spruce traps and checking purchase with my poles. How much is too much snow? This.

I was more than an hour off my schedule. The wind was picking up and blowing snow at my face. I began to worry about extenuation and daylight. I still had to re-cross the damn brook. And so, I reached the decision to turn back. But I would at least reconnect with the trail - I did not want to leave a dead-end in case someone followed.

My phone told me I had to go due South and then died. I connected it to my charger, not knowing if it would revive in the cold. I eventually got back to a place where I could be confident I was on the HP. Lo and behold, I was next to Nye’s summit. So, I went up the remaining distance, which allowed for this picture of the glorious Macintyre range:


Going down, there was not even a thought about Street – I didn’t even notice the intersection. If you are planning to do Street soon, know that the HP is currently buried. As I went, I did my best to correct my earlier errors on the path (I apologize for any remaining).

Not having to use my phone anymore, my hands started warming up again which was good because I was in my 3rd and last pair of mitts/gloves. The high-altitude winds were gone. The sun was out in full and there was an orange tinge to the landscape - idyllic.



Nonetheless, I started feeling uneasy as I got closer to Indian Brook. But I entertained the thought that perhaps my earlier Nordic spa adventure was due to poor selection of crossing point. When I reached the edge the stream, there was however no doubt that this would be difficult. I entered problem-solving mode. I took my time and ventured considerably upstream to find a better entry point. The best I found was a place where I could get halfway across on boulders – the rest was a vast iced-over area. In preparation, I removed my snowshoes, put everything in zip bags or inside my pack liner, and then put large bags over my legs. At worst, I would walk through, as this area did not seem deep. When I got to the edge of the ice, I tested it with my poles. The ice closer to my island gave way, but only for 6’’. Further along, it had a different, uniform, color and looked sturdier. I put a foot, then the other and nothing happened. Only at the utter edge of the opposite bank did the ice make a sound. I expected as much and heaved myself on a close by boulder for the win.

The rest was a walk in the park. I was privileged to see the setting sun on Heart Lake. I put in a warning about the hazardous crossing in the trail register. I had been on the trail for 8 hours.


dimanche 9 décembre 2018

Game camera recommendations

I purchased a Wildgame Innovations game camera from Dicks and it lasted about a year before it stopped working. Is this normal? I would think the thing should last more than one year. Any recommendations on a good unit with long life expectancy? Thanks,


samedi 8 décembre 2018

Hennessy Hammock

I have for sale a Hennessy sleep system. It is used but in good condition. Includes Hammock, Hugger Straps, Original Rain Fly (too small IMO), Under Cover and Under Pad. It is the Expedition Classic (bottom entry) with Insulation System (#1 Classic). Description and Specifications in the links below. $50.00 will get you off the hard wet ground, swinging sweetly anywhere you find two trees. Can ship U.S. for additional $20.

https://hennessyhammock.com/products...n-asym-classic

https://hennessyhammock.com/products...stem-1-classic

If the birth canal entry is not your thing, side zipper modifications obtained here
https://www.2qzqhammockhanger.com/fullwidth/


RSS Feeds

Site Admin,

Do you guys have rss site feeds on this forum?

I'm looking specifically for the feed from "Northville Placid Trail" sub-forum.

Not sure if 3.8 has rss feeds or not, or if they just aren't enabled.


jeudi 6 décembre 2018

2018’s malicious crypto-mining fever powered by pirated software and content

The global outbreak in malicious cryptocurrency mining that unfolded in 2018 saw the number of attacks increase by more than 83%, with over five million users attacked online in the first three quarters of the year, compared to 2.7 million over the same period in 2017. The major driver behind the crypto gold rush was the installation and use of unlicensed software and content, according to Kaspersky Lab.

In 2018, malicious cryptocurrency mining prevailed over the main threat of the last few years: ransomware. The number of internet users attacked by malicious cryptocurrency mining software increased steadily during the first half of the year, peaking in March, with around 1.2 million users a month coming under attack.

Kaspersky Lab experts have investigated the economic background of the sudden onset of crypto-mining fever to discover what drove the global distribution of this threat. They analyzed the regulatory landscape, electricity prices in the top 10 countries targeted by crypto miners and main infection vectors for the popular malware families.

The analysis shows that neither cryptocurrency legislation nor the cost of power has a significant impact on the spread of malicious mining malware. However, the investigation of malware families reveals that they mainly infected devices by duping users into installing pirated software and unlicensed content.

“Our analysis of the economic background of malicious crypto mining and the reasons for its widespread presence in certain regions revealed a clear correlation: the easier it is to distribute unlicensed software, the more incidents of malicious crypto miner activity were detected. In short, an activity not generally perceived as dangerous: the downloading and installation of dubious software, underpins what is arguably the biggest cyberthreat story of the year – malicious crypto mining,” notes Evgeny Lopatin, security expert at Kaspersky Lab.

Other key findings from the report include:
• The total number of users who encountered miners rose by more than 83% from 2,726,491 in 2017 to 5,001,414 in 2018;
• The share of miners detected, from the overall number of threats detected also grew, from 5% in 2017 to 8% in 2018;
• The share of miners detected, from the overall risk tool detections is also on the rise – from 9% in 2017 to 17% in 2018;
• The total number of users who encountered mobile miners also grew, increasing by over five times from 1,986 in 2017 to 10,242 in 2018.

To reduce the risk of infection with miners, consumers and businesses are advised to:

1. Always keep software updated on all the devices you use. To prevent miners from exploiting vulnerabilities, use tools that can automatically detect vulnerabilities and download and install patches.
2. For personal devices, use a reliable consumer security solution and remember to keep key features – such as System Watcher – switched on.
3. Don’t overlook less obvious targets, such as queue management systems, POS terminals, and even vending machines. As the miner that relied on the EternalBlue exploit shows, such equipment can also be hijacked to mine cryptocurrency.
4. Use application control to track malicious activity in legitimate applications. Specialized devices should be in Default Deny mode. Use dedicated security solution, such as Kaspersky Endpoint Security for Business that includes these functions.
5. To protect the corporate environment, educate your employees and IT teams, keep sensitive data separate, and restrict access.

The full text of the Story of the Year 2018: Cryptocurrency miners is available here.