网站地图 - XML地图 - 设为首页 - 加入收藏
您的当前位置:主页 > 国内 > 正文

大众点评

Researcher: National Emergency Alert System is Easy To Exploit_我的网站

生死狙击

一 |     The Department of Homeland Security is telling state and local governments to update software and beef up security around devices connected to the nationwide Emergency Alert System (EAS). The recommendation comes days after security researcher Ken Pyle revealed vulnerabilities in devices used by officials to encode EAS alerts.,Pyle told KerbsOnSecurity that he first discovered the vulnerabilities in 2019 after buying old EAS equipment on eBay. He quickly found the vulnerabilities and alerted the FBI, DHS, and the manufacturer of the devices. Pyle decided to give the manufacturer and government time to address the issue before going public.,DHS Inspector General Overseeing Jan.6 Secret Service Probe Previously Misled Investigators: Report4 August, 12:27 GMT,He started to worry after the Jan 6, 2021 riot at the US Capitol, fearing that the vulnerabilities could be used “to start a civil war.”,That is because despite a patch being issued in 2019, many of the devices have not been updated either because they are too old for the new firmware or because of simple neglect by the operators. Pyle also says that many operators do not perform basic security measures recommended by the manufacturer, like changing the default password and putting the devices behind a firewall.,This is a problem because of the way EAS messages are distributed. There is no central authority and the process is automated in most cases. This means that someone could issue an alert locally and as long as it is accepted as a real EAS alert, it could spread nationwide.,“These devices are designed such that someone locally can issue an alert, but there’s no central control over whether I am the one person who can send or whatever,” Pyle told KerbsOnSecurity. “If you are a local operator, you can send out nationwide alerts. That’s how easy it is to do this.”,One device obtained by Pyle was a non-functional EAS device, purchased from an electronics recycling company. While the device no longer operated, the person who discarded it and the recycling company neglected to wipe the hard drive, giving Pyle access to cryptographic keys allowing him to broadcast messages on Comcast’s network, the third largest cable company in the US.,Comcast told KerbsOnSecurity in a statement that the EAS was lost by a third-party shipper and that the keys and credentials found on the device will no longer work on their system. They also thanked Pyle for his research and for informing them about the issue.,EAS vulnerabilities have been exploited in the past. In 2013, someone hacked the EAS networks in Great Falls, Montana, and Marquette, Michigan, using their access to issue an alert saying that zombies are rising from their graves. That same prank was repeated in Indiana in 2017. There have been other incidents, though they did not include zombies.。    

又一位俄罗斯国防部高官被逮捕,这是一个月内的第二起。一场俄罗斯特色的军队反腐大戏,正在拉开帷幕。刚刚卸任国防部长的绍伊古,可能是如坐针毡。
这一次被抓的,是俄罗斯国防部干部总局局长库兹涅佐夫,他在2021年至2023年就职于俄罗斯总参谋部第八局局长,自2023年起任国防部干部总局局长。

二 |

俄调查委员会通报称,库兹涅佐夫在收受了商业机构代表的贿赂。

三 | 调查人员发现了超过1亿卢布的现金、外币、金币、手表和奢侈品等。

很明显,库兹涅佐夫是一个军队大老虎。在他之前,还有一个更大的老虎被抓。
4月23日,俄国防部副部长伊万诺夫因涉嫌收受贿赂被拘捕。

四 | 据伊万诺夫的律师透露,其涉案金额达10亿卢布。外界普遍猜测,伊万诺夫的落马,会不会导致绍伊古的倒台。毕竟,伊万诺夫是绍伊古一手提拔起来的,在绍伊古身边工作了10多年,也是绍伊古最为亲密的助手之一。

如今,国防部干部总局局长又落马了,是不是意味着对国防部贪腐案调查已经全面开启了呢?
俄罗斯国防系统的贪污腐败,早就不是什么新闻了。去年普里戈任发动兵变前后,就屡次公开谴责国防部腐败,称俄军高官克扣军需品,导致前线作战艰难。2019年,普京曾经一口气解除了11名将军级高官,主要原因就是那些人都涉及到贪腐和寻租。现在来看,一批人下去了,另一批人上来了接着腐败。
普京就任新一届总统之后,决定让前第一副总理别洛乌索夫取代绍伊古当任国防部长,有俄罗斯分析人士指出,别洛乌索夫上任后的第一件事可能就是“反腐”。
毕竟,俄罗斯军队内部的腐败是全球都出了名的。如果前方将士在战场上流血送命,但后方的高官却贪污军费、腐败盛行,那么这支军队怎么可能有战斗力。
所有这些新闻,对于干了十多年国防部长的绍伊古来说,都不是好消息。普京并非不知道国防部内部存在贪腐现象,不过此前出于大局的考虑暂不追究。

五 | 如今,随着战场形势逐步稳定下来,普京开始腾出手来,逐步收拾军队内部的蛀虫。

在这一轮反腐大戏中,绍伊古究竟能不能平稳落地,还待进一步观察。

Current article:http://wbh.guizhuanguchuanluanzhoudi.shop/list_xvwh97/tezl.html

Published on:21:05:24


注:凡本网注明来源非本站的作品,均转载自其它媒体,并不代表本网赞同其观点和对其真实性负责。
本站致力于帮助文章传播,希望能够建立合作关系。
若有任何不适的联系以下方式我们将会在24小时内删除。联系方式:
Copyright © 2018 我的网站 版权所有