Odisha News, Odisha Latest news, Odisha Daily - OrissaPOST
  • Home
  • Trending
  • State
  • Metro
  • National
  • International
  • Business
  • Feature
  • Entertainment
  • Sports
  • More..
    • Odisha Special
    • Editorial
    • Opinion
    • Careers
    • Sci-Tech
    • Timeout
    • Horoscope
    • Today’s Pic
  • Video
  • Epaper
  • News in Odia
  • Home
  • Trending
  • State
  • Metro
  • National
  • International
  • Business
  • Feature
  • Entertainment
  • Sports
  • More..
    • Odisha Special
    • Editorial
    • Opinion
    • Careers
    • Sci-Tech
    • Timeout
    • Horoscope
    • Today’s Pic
  • Video
  • Epaper
  • News in Odia
No Result
View All Result
OrissaPOST - Odisha Latest news, English Daily -
No Result
View All Result

This is how your network can be hacked through smart lightbulb

IANS
Updated: February 6th, 2020, 07:40 IST
in Sci-Tech
0
Share on FacebookShare on TwitterShare on WhatsAppShare on Linkedin

New Delhi: Security researchers Wednesday warned that cybercriminals could exploit an Internet of Things (IoT) network – smart light bulbs and their control bridge — to launch attacks on conventional computer networks in homes, businesses or even smart cities.

The researchers from cybersecurity firm Check Point discovered vulnerabilities in the communication protocol used by Philips Hue smart lightbulbs — a marquee smart home device that relies on the Zigbee protocol.

Also Read

Shubhanshu Shukla

Axiom-4 astronaut ‘Shux’ details survival drills, photography lessons in mission training

10 hours ago
Pic- ISRO via PTI

ISRO completes first air-drop test for Gaganyaan parachute system

1 day ago

The research, which was done with the help of the Check Point Institute for Information Security (CPIIS) in Tel Aviv University, Israel was disclosed to Philips and Signify (owner of the Philips Hue brand) in November 2019.

Signify confirmed the existence of the vulnerability in their product, and issued a patched firmware version (Firmware 1935144040) which is now via an automatic update.

For the study, the researchers focused on the Philips Hue smart bulbs and bridge, and found vulnerabilities (CVE-2020-6007) that enabled them to infiltrate networks using a remote exploit in the ZigBee low-power wireless protocol that is used to control a wide range of IoT devices.

The researchers used the Hue lightbulb as a platform to take over the bulbs’ control bridge and ultimately, attacking the target’s computer network.

The more recent hardware generations of Hue lightbulbs do not have the exploited vulnerability, the study said.

“Many of us are aware that IoT devices can pose a security risk, but this research shows how even the most mundane, seemingly ‘dumb’ devices such as lightbulbs can be exploited by hackers and used to take over networks, or plant malware,” said Yaniv Balmas, Head of Cyber Research, Check Point Research.

“It’s critical that organisations and individuals protect themselves against these possible attacks by updating their devices with the latest patches and separating them from other machines on their networks, to limit the possible spread of malware. In today’s complex fifth-generation attack landscape, we cannot afford to overlook the security of anything that is connected to our networks,” Balmas said.

In an attack scenario that the researchers unravelled, the hacker controls the bulb’s colour or brightness to trick users into thinking the bulb has a glitch. The bulb appears as ‘unreachable’ in the user’s control app, so they will try to ‘reset’ it.

The only way to reset the bulb is to delete it from the app, and then instruct the control bridge to re-discover the bulb.

The bridge discovers the compromised bulb, and the user adds it back onto their network.

The hacker-controlled bulb with updated firmware then uses the ZigBee protocol vulnerabilities to trigger a heap-based buffer overflow on the control bridge, by sending a large amount of data to it.

This data also enables the hacker to install malware on the bridge – which is in turn connected to the target business or home network.

The malware connects back to the hacker and using a known exploit (such as EternalBlue), they can infiltrate the target IP network from the bridge to spread ransomware or spyware.

“We recommend users to make sure that their product received the automatic update of this firmware version,” Check Point said.

(IANS)

Tags: Check PointHackingInternet of Thingssmart lightbulb
ShareTweetSendShare
Suggest A Correction

Enter your email to get our daily news in your inbox.

 

OrissaPOST epaper Sunday POST OrissaPOST epaper

Click Here: Plastic Free Odisha

#MyPaperBagChallenge

Diptiranjan Biswal

December 12, 2019
#MyPaperBagChallenge

Rajashree Manasa Mohanty

December 12, 2019
#MyPaperBagChallenge

Pratik Kumar Ghibela

December 12, 2019
#MyPaperBagChallenge

Sisirkumar Maharana

December 12, 2019
#MyPaperBagChallenge

Archana Parida

December 12, 2019
#MyPaperBagChallenge

Manas Samanta

December 12, 2019
#MyPaperBagChallenge

Subhajyoti Mohanty

December 12, 2019
#MyPaperBagChallenge

Ankita Balabantray

December 12, 2019
#MyPaperBagChallenge

Parbati Mohanty

December 12, 2019
#MyPaperBagChallenge

Vandana Singh

December 12, 2019
#MyPaperBagChallenge

Tapaswini Mallick

December 12, 2019
#MyPaperBagChallenge

Mrutyunjaya Behera

December 12, 2019
#MyPaperBagChallenge

Sibarama Khotei

December 12, 2019
#MyPaperBagChallenge

Pitabas Tripathy

December 12, 2019
#MyPaperBagChallenge

Swarit Praharaj

December 12, 2019
#MyPaperBagChallenge

Akshaya Kumar Dash

December 12, 2019
#MyPaperBagChallenge

Anshuman Sahoo

December 12, 2019
#MyPaperBagChallenge

Jyotshna Mayee Pattnaik

December 12, 2019
#MyPaperBagChallenge

Bijswajit Pradhan

December 12, 2019
#MyPaperBagChallenge

Subhajyoti Mohanty

December 12, 2019
#MyPaperBagChallenge

Debasis Mohanty

December 12, 2019
#MyPaperBagChallenge

Priyasha Pradhan

December 12, 2019
#MyPaperBagChallenge

Saishree Satyarupa

December 12, 2019
#MyPaperBagChallenge

Adrita Bhattacharya

December 12, 2019
#MyPaperBagChallenge

Smitarani Sahoo

December 12, 2019
#MyPaperBagChallenge

Sitakanta Mohanty

December 12, 2019
#MyPaperBagChallenge

Anasuya Sahoo

December 12, 2019
#MyPaperBagChallenge

Pratik Kumar

December 12, 2019
#MyPaperBagChallenge

Mandakini Dakua

December 12, 2019
#MyPaperBagChallenge

Sarfraz Ahmad

December 12, 2019

Archives

Editorial

Laws For Vindictiveness

OPiate
August 25, 2025

Three new Bills were introduced in the Lok Sabha by Union Home Minister Amit Shah shortly before Parliament adjourned last...

Read moreDetails

India’s Pak Policy

AAKAR PATEL
August 24, 2025

Problems between two parties can be resolved in one of only three ways. The first is through negotiation between these...

Read moreDetails

CIC on Life Support

Silent Shift
August 23, 2025

As of September 14, the Central Information Commission (CIC) may be headless. Chief Information Commissioner Heeralal Samariya retires, and unless...

Read moreDetails

‘TACO’ Effect

August 20, 2025

It is interesting to note US President Donald Trump keeps changing his deadline for imposing new tariffs on goods from...

Read moreDetails
  • Home
  • State
  • Metro
  • National
  • International
  • Business
  • Editorial
  • Opinion
  • Sports
  • About Us
  • Advertise
  • Contact Us
  • Jobs
Developed By Ratna Technology

© 2024 All rights Reserved by OrissaPOST

  • News in Odia
  • Orissa POST Epaper
  • Video
  • Home
  • Trending
  • Metro
  • State
  • Odisha Special
  • National
  • International
  • Sports
  • Business
  • Editorial
  • Entertainment
  • Horoscope
  • Careers
  • Feature
  • Today’s Pic
  • Opinion
  • Sci-Tech
  • About Us
  • Contact Us
  • Jobs

© 2024 All rights Reserved by OrissaPOST

    • News in Odia
    • Orissa POST Epaper
    • Video
    • Home
    • Trending
    • Metro
    • State
    • Odisha Special
    • National
    • International
    • Sports
    • Business
    • Editorial
    • Entertainment
    • Horoscope
    • Careers
    • Feature
    • Today’s Pic
    • Opinion
    • Sci-Tech
    • About Us
    • Contact Us
    • Jobs

    © 2024 All rights Reserved by OrissaPOST