Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


jarledb

Webhead
3319 posts

Uber Geek
+1 received by user: 1983

Moderator
ID Verified
Trusted
Lifetime subscriber

#210450 28-Mar-2017 00:16
Send private message

So Miele made an internet connected dishwasher. And predictably failed to secure it properly, and completely ignore the calls to patch the security hole - leaving the unit open to abuse for anyone that can get access to its ip-address.

 

Dishwasher has directory traversal bug





Jarle Dahl Bergersen | Referral Links: Want $50 off when you join Octopus Energy? Use this referral code
Are you happy with what you get from Geekzone? Please consider supporting us by making a donation or subscribing.


Create new topic
frankv
5705 posts

Uber Geek
+1 received by user: 3666

Lifetime subscriber

  #1749140 28-Mar-2017 06:51
Send private message

 I can't imagine what a web server on a dishwasher would do for me, the customer.

 

 




darylblake
1172 posts

Uber Geek
+1 received by user: 410

Trusted

  #1749148 28-Mar-2017 07:34
Send private message

Yeh thats pretty poor. 

I mean, my regular dishwasher washes dishes. So I don't really see the benefit of buying a IoT dishwasher.

 

My wife wanted me to buy this samsung fridge for $8.5K which had all this un-necessary stuff in it too, like a web browser, cameras in the fridge a sound bar and pandora.


wellygary
8810 posts

Uber Geek
+1 received by user: 5287


  #1749149 28-Mar-2017 07:35
Send private message

Technically its not a clasic dishwasher, its a

 

"Laboratory Glassware Washer PG 8527 / PG 8528"

 

It has the abilty to scan bar codes on wash batches and presumable pass that along..

 

http://www.miele-pro.com/us/prof/products/14071_16161.htm

 

 http://www.miele-pro.com/media/sap/PSHOT/30/ZBP/DMS_PCD1__55DA24D8A4D3C1E0E10080000AB5C9E5.jpg

 

 




tardtasticx
3084 posts

Uber Geek
+1 received by user: 483


  #1749150 28-Mar-2017 07:40
Send private message

As above, it's for use in laboratories so isn't something people will have sitting at home behind an ISP supplied modem/router combo. 
While still silly to not bake any security into the device, one would hope that a an institution needing this would have a competent IT team who would prevent this accessing the internet. 


sbiddle
30853 posts

Uber Geek
+1 received by user: 9996

Retired Mod
Trusted
Biddle Corp
Lifetime subscriber

  #1749153 28-Mar-2017 07:56
Send private message

With so many security exploits in so called IoT devices (and exploits in more common things such as CCTV / VoIP) I really think port forward functionality should be removed from routers!

 

 


MadEngineer
4591 posts

Uber Geek
+1 received by user: 2570

Trusted

  #1749169 28-Mar-2017 08:50
Send private message

Port forwarding will become a thing of the past - just wait till all those insecure IoT devices get a public IPv6 address!




You're not on Atlantis anymore, Duncan Idaho.

Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.