Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - I know you are, but what am I?.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews




spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. Visual C++ Redistributable Runtimes AIO Repack
5. Visual C++ Runtime Installer (All-In-One)
6. McAfee Removal Tool (MCPR)
7. MusicBee
8. Rufus
9. K-Lite Mega Codec Pack
10. Sergei Strelec's WinPE
More >>

top reads

Star How to Disable 1-Click Ordering on Amazon (and Avoid Surprise Charges)

Star How to Fix Shallow Paint Layer Depth in Bambu Studio

Star Aviator Betting Game Secrets: Unlock 97% RTP & Triple Your Wins

Star Windows Recall: What It Is, Why Hackers Will Love It, and How to Stay Safe

Star Star Trek Fleet Command Promo Codes: Redeem Codes for Free Shards, Blueprints And Resources

Star How To Use VLC Media Player to Trim Video Clips

Star What Is the $WinREAgent Folder and Can I Delete It?

Star Swear Your Way to Better Search Results

Star How to Get a Dark Start Menu and Taskbar in Windows 10 & 11

Star Enable, Disable, Manage, Delete or Create a System Restore Point


MajorGeeks.Com » News » April 2013 » Security hole can damage heating systems

Security hole can damage heating systems


Contributed by: Email on 04/15/2013 03:21 PM [ comments Comments ]


It has been discovered that heating systems from German company Vaillant contain a serious security hole. The ecoPower 1.0 models of central heating and power systems include a vulnerability that allows attackers to turn the system off and potentially even damage the system in the process. In a message sent to its customers, the manufacturer recommends physically disconnecting the affected products from the network until a service technician can fix them on site.

The ecoPower 1.0 is a small-scale combined heat and power unit that uses natural gas to provide heating and power for one or two family homes. The system is connected to the internet and provides a web interface that allows home owners to remotely control the heating in their house. However, a security hole in this web interface makes it easy to access plain text passwords for the systems.

Aside from the customer administration passwords, attackers can then gain access to the functions usually reserved for service technicians working for Vaillant. With these remote administration credentials, attackers can shut down the system completely, which in winter months could damage the heating system were it to freeze up. In summer months, increasing the temperature above safe margins can overheat certain heating elements if they are not attached to independent limiters. The situation is exacerbated because of the way the heating systems in question are connected to the internet: because the systems are hooked up to Vaillant's own dynamic DNS service, it is relatively easy to find all of the ecoPower systems that are online by simple trial and error.

The hole was discovered by a reader of the German trade journal BHKW-Infothek. The industry journal collaborated with The H's associates at heise Security and CERT Bun at the German Federal Office for Information Security (BSI) to reproduce the problem and develop a fix. This fix is now being rolled out by Vaillant to affected customers. Vaillant is also working on offering customers a VPN box that encrypts the heating system's connection to the manufacturer. This VPN box will be provided free of charge to customers with a service contract. Other customers will have the option to buy the add-on for a currently undisclosed price.






« Google detects more malware than Bing · Security hole can damage heating systems · Google Fixes Three High-Risk Flaws in Chrome OS »




Comments
comments powered by Disqus

MajorGeeks.Com » News » April 2013 » Security hole can damage heating systems

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition