Reply to post: Re: telnet??!!?

Forget Mirai – Brickerbot malware will kill your crap IoT devices

stephanh

Re: telnet??!!?

Perhaps connecting a telnet client to port 80 is a fun and educational exercise. However this device runs a telnet *server*. Telnet sends (typically) arbitrary shell commands over a plaintext connection, so anybody who can send packages to the telnet port can 0wn the device.

Unfortunately BusyBox contains a built-in telnet server and no ssh server, so any security-unaware IOT engineer (please excuse the tautology) will choose the path of least resistance and use telnetd instead of sshd.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon