| Thread Tools |
10th September 2019, 08:24 | #1 |
[M] Reviewer Join Date: May 2010 Location: Romania
Posts: 153,541
| Avast finds 600,000 GPS trackers with basic password 123456 Security researchers from Czech cyber-security outfit Avast have found more than 600,000 GPS trackers manufactured by a Chinese company using the same default password of 123456. Hackers can use the passworld to hijack users' accounts, from where they can spy on conversations near the GPS tracker, spoof the tracker's real location, or get the tracker's attached SIM card phone number for tracking via GSM channels. Avast researchers said they found these issues in T8 Mini, a GPS tracker manufactured by Shenzhen i365-Tech, a Chinese IoT device maker. Avast found that the issues impacted more than 30 other models of GPS trackers, all manufactured by the same vendor, and some even sold as white-label products, bearing the logos of other companies. All models shared the same backend infrastructure, which consisted of a cloud server to which GPS trackers reported, a web panel where customers logged in via their browsers to check the tracker's location, and a similar mobile app, which also connected to the same cloud server. The user IDs were based on the GPS tracker's IMEI (International Mobile Equipment Identity) code and was sequential, while the password was the same for all devices -- 123456. This means that a hacker can launch automated attacks against Shenzhen i365-Tech's cloud server by going through all user ID's one by one, and using the same 123456 password, and take over users' accounts. While users can change the default after they log into their account for the first time, Avast said that during a scan of over four million user IDs, it found that more than 600,000 accounts were still using the default password. https://fudzilla.com/news/49351-avas...basic-password |
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
The Best GPS Trackers for Cats and Dogs | Stefan Mileschin | WebNews | 0 | 4th March 2019 10:30 |
Avast pulls latest version of CCleaner | Stefan Mileschin | WebNews | 0 | 7th August 2018 13:49 |
Avast claims its secure browser is 30 percent faster than yours | Stefan Mileschin | WebNews | 0 | 7th April 2018 05:28 |
Avast buys AVG | Stefan Mileschin | WebNews | 0 | 10th July 2016 15:53 |
'Minecraft' fan finds a way to program BASIC code in-game | Stefan Mileschin | WebNews | 0 | 21st January 2016 08:03 |
Epson's first fitness trackers reach the US | Stefan Mileschin | WebNews | 0 | 8th January 2015 16:36 |
Avast Antivirus Was Spying On You with Adware (Until This Week) | Stefan Mileschin | WebNews | 0 | 23rd October 2014 11:59 |
Avast Support Forum Hacked, Information Stolen in Breach | Stefan Mileschin | WebNews | 0 | 2nd June 2014 09:48 |
Avast! Pro License Key Used Illegally 774651 Times | jmke | WebNews | 0 | 8th December 2010 15:53 |
Avast! Is the Hardware Industry marketing to Pirates now? | jmke | WebNews | 0 | 28th July 2006 13:31 |
Thread Tools | |
| |