Friday, June 20, 2025
MediaNews4U
  • Exclusive
  • Advertising
  • Media
    • Radio
    • Cable & DTH
    • Print
    • Digital Frontier
    • Gaming Nexus
  • Television
  • OTT
  • Ad-Tech
  • Marketing
  • Campaigns
  • Analysis
  • Opinion
    • Opinion
    • Think Through
    • Prescience 2023
    • Prescience 2024
  • People
  • Events
    • Leader Speak
    • STRAIGHT TALK
    • Gamechangers
    • Print & TV Summit
MediaNews4U
  • Exclusive
  • Advertising
  • Media
    • Radio
    • Cable & DTH
    • Print
    • Digital Frontier
    • Gaming Nexus
  • Television
  • OTT
  • Ad-Tech
  • Marketing
  • Campaigns
  • Analysis
  • Opinion
    • Opinion
    • Think Through
    • Prescience 2023
    • Prescience 2024
  • People
  • Events
    • Leader Speak
    • STRAIGHT TALK
    • Gamechangers
    • Print & TV Summit
MediaNews4U.com
Home Featured

Avast research finds at least 32,000 smart homes and businesses at risk of leaking data

by MN4U Bureau
August 17, 2018
in Featured, Mobile/Digital
Reading Time: 3 mins read
A A
Avast research finds at least 32,000 smart homes and businesses at risk of leaking data

Share Share ShareShare

New Delhi: New research from Avast (LSE: AVST), the global leader in cybersecurity products, found more than 49,000 Message Queuing Telemetry Transport (MQTT) servers publicly visible on the internet due to a misconfigured MQTT protocol. This includes more than 32,000 (595 from India) servers with no password protection, putting them at risk of leaking data. The MQTT protocol is used to interconnect and control smart home devices, via smart home hubs. When implementing the MQTT protocol, users set up a server. In the case of consumers, the server usually lives on a PC or some mini-computer such as Raspberry Pi, to which devices can connect to and communicate with.

While the MQTT protocol itself is secure, severe security issues can arise if MQTT is incorrectly implemented and configured. Cybercriminals could gain complete access to a home to learn when their owners are home, manipulate entertainment systems, voice assistants and household devices, and see if smart doors and windows are opened or closed. Under certain conditions cybercriminals can even track a user’s whereabouts which can be a serious privacy and security threat.

Martin Hron
Martin Hron

“It is frighteningly easy to gain access and control of a person’s smart home, because there are still many poorly secured protocols dating back to bygone technology eras when security was not a top concern,” said Martin Hron, security researcher at Avast. “Consumers need to be aware of the security concerns of connecting devices that control intimate parts of their home to services they don’t fully understand and the importance of properly configuring their devices.”

Martin Hron describes five ways in which poorly configured MQTT servers can be abused by hackers:

  1. Open and unprotected MQTT servers can be found using the Shodan IoT search engine, and once connected, hackers can read messages transmitted using the MQTT protocol. Avast research shows that hackers can read the status of smart window and door sensors, for example, and see when lights are switched on and off. In this particular case, Avast also found that outsiders could control connected devices or at least poison data using the MQTT protocol on behalf of devices. This way, for example, an attacker could send messages to the hub to open the garage door.
  2. Even if an MQTT server is protected, Avast found that a smart home can be hacked as in some cases, the dashboard used to control a smart home’s control panel runs on the same IP address as the MQTT server. Many users use default configurations that come with their smart home hub software, and these are often not password protected, meaning a hacker can gain complete access to a smart home’s dashboard, allowing the hacker to control any device connected via the dashboard.
  3. Even if both the MQTT server and dashboard are protected, Avast found that in the case of smart hub software, Home Assistant software, open and unsecure SMB shares are public and therefore accessible to hackers. SMB is a protocol used for sharing files on internal networks, mainly on the Windows platform. Avast found publicly shared directories with all the Home Assistant files including configuration files. In the exposed files, Avast found a file storing passwords and keys stored in plain text. The passwords stored in the configuration file can allow a hacker to gain complete control of a person’s home.
  4. Smart homeowners can use tools and apps to create a dashboard for an MQTT-based smart home, to control their connected devices. A particular application, MQTT Dash, allows users to create their own dashboard and control panel to control smart devices using MQTT. Users have the option to publish the settings they set up using the dashboard to the MQTT server, so they can easily replicate the settings on as many devices as they would like. If the MQTT server used is unsecure, a hacker can easily access the user’s dashboard, which allows them to easily hack the smart home.
  5. Avast found that MQTT can, in certain instances, allow hackers to track users’ location, as MQTT servers typically concentrate on real time data. Many MQTT servers are connected to a mobile application called OwnTracks. OwnTracks gives users the possibility to share their location with others, but can also be used by smart home owners to let the smart home devices know when the user is approaching the home, to activate smart devices, like smart light lamps. In order to configure the tracking feature, users have to configure the application by connecting to an MQTT server and expose the MQTT server to the internet. During this process, users are not required to setup login credentials, meaning anyone can connect to the MQTT server. Hackers can read messages that include a device’s battery level, location using latitude, longitude, and altitude points, and the timestamp for the position.
Tags: Avast researchMartin HronMQTTPCsmart homes

RECENT POSTS

ACT Fibernet introduces ACT SmartWi-Fi powered by AI
Mobile/Digital

ACT Fibernet introduces ACT SmartWi-Fi powered by AI

January 22, 2025
0

MUMBAI: ACT Fibernet (Atria Convergence Technologies Ltd), an internet service provider, in partnership with Aprecomm.ai has upgraded its router OS...

Read more
WhatsApp’s channel categories allows people to browse and find channels they’re interested in
Mobile/Digital

WhatsApp’s channel categories allows people to browse and find channels they’re interested in

September 20, 2024
0

MUMBAI: Meta's mobile call and messaging service WhatsApp has announced Channel Categories, a new way for people to browse and...

Read more
Snap introduces fifth generation of its see-through, standalone AR glasses Spectacles at its Partner Summit
Mobile/Digital

Snap introduces fifth generation of its see-through, standalone AR glasses Spectacles at its Partner Summit

September 18, 2024
0

MUMBAI: Snap held its sixth annual Snap Partner Summit. On stage, leaders from across the business shared relevant news for...

Read more
Exploring the various types of water heaters
Featured

Exploring the various types of water heaters

August 29, 2024
0

A water heater or geyser is one of the many electronic appliances individuals use at home daily. Different water heaters...

Read more
Featured

Explore Bangalorе as a Tech Hub with a Grееn Hеart

August 21, 2024
0

Bangalorе is an India's Silicon Vallеy and it is a city whеrе modеrnity sеamlеssly blеnds with naturе. It's a place...

Read more
Grievance Appellate Committees resolve 937 of 1,065 Cases since March 2023 inception
Digital Frontier

Grievance Appellate Committees resolve 937 of 1,065 Cases since March 2023 inception

August 3, 2024
0

New Delhi: The Government of India, after extensive public consultations with relevant stakeholders, notified the Information Technology (Intermediary Guidelines and...

Read more

LATEST NEWS

Born to Be Wild: A Thrilling Wildlife Adventure Series across the Amazonian, African and Australian Wildernesses, Premieres on History TV18

Born to Be Wild: A Thrilling Wildlife Adventure Series across the Amazonian, African and Australian Wildernesses, Premieres on History TV18

January 31, 2025
Mindshare and Modi Illva launch The Rockford Circle Season 2, highlighting India’s rising entrepreneurs

Mindshare and Modi Illva launch The Rockford Circle Season 2, highlighting India’s rising entrepreneurs

January 31, 2025

ANALYSIS

MRSI Golden Key Awards 2024 to recognize Industry Icons Ashok Das, C. K. Sharma, and Dr. Lalit S. Kanodia
Analysis

MRSI Golden Key Awards 2024 to recognize Industry Icons Ashok Das, C. K. Sharma, and Dr. Lalit S. Kanodia

January 31, 2025
0

Mumbai: The Market Research Society of India’s (MRSI) Golden Key Awards has rapidly become the foremost platform acknowledging and celebrating...

PEOPLE

Noel Tata
People

Tata Group Leader Noel Tata awarded Honorary Doctorate by the University of Sussex

January 31, 2025
0

New Delhi: The University of Sussex has conferred an honorary doctorate upon Noel Tata, a distinguished business leader within the...

MARKETING

Etihad Airways takes center stage as Chennai Super Kings' Front-of-Jersey sponsor
Marketing

Etihad Airways takes center stage as Chennai Super Kings’ Front-of-Jersey sponsor

January 31, 2025
0

Mumbai: Etihad Airways, the national airline of the UAE, has elevated its partnership with Chennai Super Kings (CSK) by securing...

Subscribe to Newsletters

ADVERTISING

Hansa Research earns ISO Certifications, strengthening quality and security standards
Advertising

Hansa Research earns ISO Certifications, strengthening quality and security standards

January 31, 2025
0

MUMBAI: Hansa Research Group, a wholly-owned subsidiary of R K SWAMY Ltd., has received ISO 9001:2015 certification for quality management,...

PRINT

Omnicom Media Group dominates Global Media Growth in 2024: COMvergence
Advertising

Omnicom Media Group dominates Global Media Growth in 2024: COMvergence

December 19, 2024
0

Mumbai: Omnicom Media Group (OMG), the media services arm of Omnicom and parent to global media agency networks OMD, PHD,...

AUTHOR'S CORNER

The Power of Purpose: Why Students Choose Brands with Social Impact
Authors Corner

The Power of Purpose: Why Students Choose Brands with Social Impact

January 31, 2025
0

Students are reshaping brand interactions through strategic social awareness. Their purchasing decisions transcend traditional consumption, becoming powerful tools for systemic...

UPLIFT MEDIANEWS4U DIGITAL PVT LTD
No. 194B , Aram Nagar 2, JP Road,
Versova, Andheri West
Mumbai - 400061

For editorial queries:
[email protected]
[email protected]

For business queries:
Smitha Sapaliga - +91-98337-15455
[email protected]

Recent News

MRSI Golden Key Awards 2024 to recognize Industry Icons Ashok Das, C. K. Sharma, and Dr. Lalit S. Kanodia

MRSI Golden Key Awards 2024 to recognize Industry Icons Ashok Das, C. K. Sharma, and Dr. Lalit S. Kanodia

January 31, 2025
Born to Be Wild: A Thrilling Wildlife Adventure Series across the Amazonian, African and Australian Wildernesses, Premieres on History TV18

Born to Be Wild: A Thrilling Wildlife Adventure Series across the Amazonian, African and Australian Wildernesses, Premieres on History TV18

January 31, 2025
Mindshare and Modi Illva launch The Rockford Circle Season 2, highlighting India’s rising entrepreneurs

Mindshare and Modi Illva launch The Rockford Circle Season 2, highlighting India’s rising entrepreneurs

January 31, 2025

Newsletter

Subscribe to Newsletters

Medianews4u.com © 2019 - 2024 All rights reserved.

  • The South Side Story 2023 Download Report
  • Goafest 2023: Day 3
  • Goafest 2023: Day 2
  • Goafest 2023: Day 1
  • Straight Talk Gallery 2022
  • The South Side Story 2022 Download Report
  • Focus 2022
  • Futurescope Conclave Gallery 2022
  • The South Side Story 2021 Download Report
  • FOCUS 2021
  • Exclusive
  • Exclusive
  • Advertising
  • Media
    • Radio
    • Cable & DTH
    • Print
    • Digital Frontier
    • Gaming Nexus
  • Television
  • OTT
  • Ad-Tech
  • Marketing
  • Campaigns
  • Analysis
  • Opinion
    • Opinion
    • Think Through
    • Prescience 2023
    • Prescience 2024
  • People
  • Events
    • Leader Speak
    • STRAIGHT TALK
    • Gamechangers
    • Print & TV Summit

Medianews4u.com © 2019 - 2024 All rights reserved.