Hackers sell multiple international airports access for only $10
The airport should be a public place with a very high-security level in the eyes of ordinary people, but it is not known that you can black into the airport system for only $10.
The well-known security company McAfee found in the daily inspections that hackers sold server remote desktop connection credentials at multiple international airports in the dark market.
Anyone who spends tens of dollars can easily purchase these server passwords and then log in to the corresponding server with any hacking technology.
The Remote Desktop Protocol is mainly used by Microsoft to facilitate the operation and maintenance personnel to connect to the server. You can log in to the server remotely as long as you have the address and password.
After tracking, McAfee found that many sellers are selling such certificates in the dark market black market. For example, a dark market in Russia sells 40,000 server certificates.
For example, the researcher purchased several server credentials for an international airport for testing. After verification, the researchers confirmed that the data was all valid.
The airport’s security and building automation systems, monitoring and video analysis systems, and automated transportation system accounts outside the airport are all sold on the dark.
Besides, the researchers found that server credentials from multiple hospitals, nursing, and medical device manufacturers were leaked, which could pose a significant safety hazard.
Under normal circumstances, hackers who want to obtain remote desktop credentials mainly rely on zero-day exploits, malware phishing or social engineering attacks.
But being able to get so many remote desktop credentials is not possible with cumbersome social engineering attacks, so it’s likely to be through vulnerabilities and phishing attacks.
It is worth noting that most of these hacked servers are Windows Server 2008 and 2012. It is possible that these servers are not updated.
The most significant hazard in this security incident is the clear division of hackers. For example, the sellers of the dark network only sell data, but they do not attack themselves.
For other hackers, it only takes ten dollars to purchase account credentials and does not require extremely tedious work through zero-day vulnerabilities and social engineering.
Therefore, even a script kid with no hacking skills can purchase credentials to destroy, but the damages found at present are mainly mine mining.
Therefore, please use the high-strength password after the remote desktop protocol is enabled on the server and replace it regularly to avoid the broiler in the black market after the leak.
Source, Image: mcafee