Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - Takin' names and kickin' ASCII.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews



IObit Black Friday Sale

spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. MusicBee
5. Sergei Strelec's WinPE
6. Microsoft Visual C++ 2015-2022 Redistributable Package
7. Visual C++ Redistributable Runtimes AIO Repack
8. McAfee Removal Tool (MCPR)
9. K-Lite Mega Codec Pack
10. Tweaking.com - Windows Repair
More >>

top reads

Star All the New Features Landing in Windows 11 This December

Star Lossless vs Lossy: When FLAC, APE, and ALAC Beat MP3 and When They Don't

Star Google Search Tricks You'll Actually Use in 2025 and Beyond

Star Fresh PC Checklist: First 12 Things to Do On a New Windows 11 Machine

Star Running AI Models Locally: What They Are, Where to Find Them, and How to Get Started

Star Deciding Between Idle State, Sleep Mode, and Shutdown: What's Best for Your PC?

Star How to Fix VMware Workstation "The Update Server Could Not Be Resolved" Error Installing VMware Tools

Star How to Remove Google Gemini from Your Phone (and Your Life)

Star Windows Bloat Removal Guide: Debloat Safely and Keep What You Need

Star Windows 11 Repair Playbook: SFC, DISM, CHKDSK Without Breaking Stuff


MajorGeeks.Com » News » April 2013 » Security hole can damage heating systems

Security hole can damage heating systems


Contributed by: Email on 04/15/2013 03:21 PM [ comments Comments ]


It has been discovered that heating systems from German company Vaillant contain a serious security hole. The ecoPower 1.0 models of central heating and power systems include a vulnerability that allows attackers to turn the system off and potentially even damage the system in the process. In a message sent to its customers, the manufacturer recommends physically disconnecting the affected products from the network until a service technician can fix them on site.

The ecoPower 1.0 is a small-scale combined heat and power unit that uses natural gas to provide heating and power for one or two family homes. The system is connected to the internet and provides a web interface that allows home owners to remotely control the heating in their house. However, a security hole in this web interface makes it easy to access plain text passwords for the systems.

Aside from the customer administration passwords, attackers can then gain access to the functions usually reserved for service technicians working for Vaillant. With these remote administration credentials, attackers can shut down the system completely, which in winter months could damage the heating system were it to freeze up. In summer months, increasing the temperature above safe margins can overheat certain heating elements if they are not attached to independent limiters. The situation is exacerbated because of the way the heating systems in question are connected to the internet: because the systems are hooked up to Vaillant's own dynamic DNS service, it is relatively easy to find all of the ecoPower systems that are online by simple trial and error.

The hole was discovered by a reader of the German trade journal BHKW-Infothek. The industry journal collaborated with The H's associates at heise Security and CERT Bun at the German Federal Office for Information Security (BSI) to reproduce the problem and develop a fix. This fix is now being rolled out by Vaillant to affected customers. Vaillant is also working on offering customers a VPN box that encrypts the heating system's connection to the manufacturer. This VPN box will be provided free of charge to customers with a service contract. Other customers will have the option to buy the add-on for a currently undisclosed price.






« Google detects more malware than Bing · Security hole can damage heating systems · Google Fixes Three High-Risk Flaws in Chrome OS »




Comments
comments powered by Disqus

MajorGeeks.Com » News » April 2013 » Security hole can damage heating systems

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition