The Xiongmai Botnet 'Recall' Will Not Work

Author: John Honovich, Published on Oct 25, 2016

The Xiongmai 'recall' has been the topic of global news, following the unprecedented bot net attacks that use their equipment, among others.

However well intentioned this 'recall' may be, it is not going to work. Understanding how Xiongmai and their customer's business model works makes this clear.

Xiongmai No Branded Sales

Xiongmai does not sell under its own brand nor to end users. Because of this, they have no idea what end users actually have their products.

Hidden OEM / Supplier

Xiongmai, even within the video surveillance industry, has near zero brand recognition (until this disaster). Because of this, the companies that Xiongmai sell components / modules to almost never disclose that they use Xiongmai. Indeed, this is a key reason why despite the global coverage, few if any manufacturers have been identified as using Xiongmai.

OEMs / Relabelers No Interest In Disclosing Now

For the recall to work, the companies that buy and use Xiongmai components (OEMs / relabelers) will have to disclose to their customers that they are using Xiongmai. Even under normal circumstances, video surveillance OEMs have legal agreements that prohibit their suppliers, like Xiongmai, from confirming who their OEMs are. These companies/OEMs have zero incentive to do so now as acknowledging it risks massive brand damage and potential litigation. 

No Records of End Users Likely

Indeed, even if Xiongmai's customers were open to a publicly announced recall, most have no idea who are using these products. Registration of products is extremely uncommon within the video surveillance industry, where products are either sold through retail (which does not track end users) or through integrators (who typically do not want their manufacturer partners to know who 'their' customers are).

Realistic About Recall No Impact

Because of all this, we all need to be realistic that a recall is not going to work, even if Xiongmai really wants to try one. Sure, they can recall things in inventory from their partners if those products are vulnerable but there are millions of Xiongmai based devices already deployed (as Xiongmai is a major supplier) and the likelihood that they can recall / remove even a fraction of the infected botnet army is slim to none.

Net / net, to stop these infections, we need to look beyond the potential of a recall.

3 reports cite this report:

CES 2018 Show Final Report on Jan 12, 2018
This is IPVM's final edition of our 2018 CES show report. Below are already numerous images and commentary, with more coming tomorrow.   CES is...
Mirai-like Botnet Persirai Attacks IP Cameras - Impact Analyzed on Jun 14, 2017
Mirai made headlines in 2016, exploiting weaknesses in cameras, including those from Dahua and XiongMai to create a massive botnet that was used to...
Hackers Battle For 3 Million Strong Mirai Botnet on Nov 28, 2016
Mirai-infected devices have become so large and so prevalent that multiple hackers are now fighting each other to control these devices. This...

Comments (23)

Only IPVM PRO Members may comment. Login or Join.

Agreed. A recall won't work.

This may require a Stuxnet type response. Yes, a deliberate action to render these units useless.

If that seems drastic, I would like to hear what other ideas exist to address the threat of continued DDoS attacks on the internet.

This may require a Stuxnet type response. Yes, a deliberate action to render these units useless.

Its harder than you might think on these devices, since they have read-only filesystems with the passwords hardcoded.

So if you just break it, a default reset puts it back in the game.

That'a the reason that even XiongMai doesn't have a firmware fix for these devices.

The cost of using the "cheapest" product out there means that the entire "internet" economy suffers due to this.

How many more attacks before we wake up to, China doesn't care....

Their economy requires it has to be firing on all 8 cylinders in order to keep 1 Billion people "happy". If it means causing the rest of the world to suffer, they really don't care.

That said, when we "exported" capitalism to China, they put their economy on steroids and like locusts they will swallow anything in sight in order to control that space.

Shutting down the infrastructure without dropping 1 bomb is cheaper and inherently a less risky proposition.

A bigger concern is the integrators who don't care. They are effectively fuel for the fire. This is unlikely to remedy until it becomes too costly to sell these products due to litigation.

Net / net, to stop these infections, we need to look beyond the potential of a recall.

Should Hikvision Hack Its Own DVR's?

Should I Hack 10,000 Dahua Cameras?

Should Axis Hack Axis Public Cameras?

Prediction: XiongMai ends up using this global news coverage to their advantage. They will say repeatedly that

  1. Its not our fault
  2. Even if its our fault, others manufacturers are equally at fault
  3. Even if its our fault, improper installation is equally at fault
  4. Even if its our fault, we fixed it in all our latest products
  5. Its our fault, but we are the only manufacturer to do the right thing and recall our products

A smart reverse reputation play, even if 7 people take them up on the recall.

XiongMai who nobody knew yesterday, gets a instant brand, tarnished a bit for sure, but that fades if you deliver in the meantime.

XiongMai who nobody knew yesterday, gets a instant brand, tarnished a bit for sure

'tarnished a bit' is an understatement. Their brand is destroyed, given the severity of the attacks. I don't think most tech and business people following this will ever trust them. And XiongMai is not some sophisticated marketing machine that can somehow find a way to turn this to their benefit. They are better off just purging the XiongMai brand and going with something else.

In 1982, seven Chicago-area residents died from cyanide-laced Extra-Strength Tylenol. Marketers predicted that the Tylenol brand would never recover from the sabotage.

The following year, Tylenol’s share of the analgesic market climbed 23 percent, and The New York Times wrote, “ It is almost as if nothing ever happened.”

Yes, you're right, Johnson and Johnson doesn't make DVR cards, and had an established brand already and HQ in the U.S. among their other vast differences.

But the point is that memories are short. Maybe another low-cost alternative to the Peoples Republic of Hikvision or the dysfunctional Dahuan Dynasty.

You can certainly argue persuasively that they're done, thats easily done considering the events. But I only made the prediction because of its apparent impossibility.

Firewalls are only way to stop this.

Especially edge firewall at customer premises.

Drop all DNS queries from camera subnet or ip range.

That will break ntp, so ntp server might have to be set by ip address, or set to an internal ntp service.

If you want to connect low cost devices to the internet, they have to be behind a properly configured firewall, otherwise it becomes tragedy of the commons - everyone dumps their junk in the common space.

Hear, hear David.

As long as the devices are not configured properly nor firewalled you will have networks (nutworks) that scream "here, here".

From Shenzhen Daily

A CHINESE electronics maker that has recalled products sold in the United States said Tuesday it did all it could to prevent a massive cyberattack that briefly blocked access to websites including Twitter and Netflix.

Hangzhou Xiongmai Technology has said some of its Web-connected cameras and digital recorders became compromised because customers failed to change their default passwords.

Liu Yuexin, Xiongmai’s marketing director, said that Xiongmai and other companies across the home surveillance equipment industry were made aware of the vulnerability in April 2015. Liu said Xiongmai moved quickly to plug the gaps and should not be singled out for criticism.

“We don’t know why there is a spear squarely pointed at our chest,” Liu said.

The hack has heightened long-standing fears among security experts that the rising number of interconnected home gadgets, appliances and even automobiles represent a cybersecurity nightmare. The convenience of being able to control home electronics via the Web also leaves them more vulnerable to malicious intruders, experts say.

Unidentified hackers seized control of gadgets including Xiongmai’s Friday and directed them to launch an attack that temporarily disrupted access to a host of sites, ranging from Twitter and Netflix to Amazon and Spotify, according to U.S. Web security researchers.

The “distributed denial-of-service” attack targeted servers run by Dyn Inc., an Internet company located in Manchester, New Hampshire. These types of attacks work by overwhelming targeted computers with junk data so that legitimate traffic can’t get through. (SD-Agencies)

The hack has heightened long-standing fears among security experts that the rising number of interconnected home gadgets, appliances and even automobiles represent a cybersecurity nightmare. The convenience of being able to control home electronics via the Web also leaves them more vulnerable to malicious intruders, experts say.

Having worked at a National Laboratory (an environment very concerned with security), I have never understood why one would want to hook something up to the Internet and then be vulnerable to the world's malicious elements.

We don't even do wireless in my house.

Craig

We don't even do wireless in my house.

Not even cell phones?

Now, now, no need for sarcasm... or obvious sanctimonious misinterpretation.

Not sarcastic at all.

I think its a fair question, since smartphones are roving wireless linux computers, no? And they have been known to be hacked every now and again.

OK... sorry. I misinterpreted.

I believe has was referring to wifi.

Maybe he can clarify.

Yes, I agree he most likely was. Still if the phone connects to the internet wirelessly, then it can be snooped on and MITM just the same,no?

No WIFI here. No smart phones, either (who wants to walk around with a computer that has more capability than some supercomputers had not that long ago).

...who wants to walk around with a computer that has more capability than some supercomputers had not that long ago...

Anyone looking for Pokemon. Its the minimum requirement :)

I mean this seriously, without any snark, but the answer to that question seems to literally be a majority of people.

Hmm.. Long thought. 1st- That would depend on where "the middle" is. Wireless, network? Who originated and who is "looking". Cellular is pretty darn good. Wifi is as good as it's implementer.

The original subject was the take over of cameras. If you look at the attack it was based on all the general default passwords of semi capable cute little devices. The point was if you leave a semi controllable (Linux) device on the open net without all the other proper cautions then... we have a DoS device.

Having made many "devices", I don't think we should blame the device, or the devices manufacturer. Rather, the implementers.

Newly added XM branded product in Amazon:

May be the cheapest 1080p ptz(d) out there.

Related Reports

If You Have 4 Cameras, You Can Throw Them Away, If You Have 400, They Throw You Away on Jan 19, 2018
Do users care about anything but price? Do user care about cybersecurity? Do users care about trusting their supplier? These have become...
Chinese Government Hikvision Surveillance System On US Government Network on Jan 18, 2018
Hikvision, the Chinese government-owned manufacturer, has publicly claimed that their products are running on a US government network. Moreover,...
Hikvision Removed From US Army Base, Congressional Hearing Called on Jan 12, 2018
Hikvision has been removed from a US Army Base and a US congressional committee is planning a hearing on cybersecurity risks and specifically,...
Hikvision Declares 'Never Click On Links In Emails' on Jan 09, 2018
Hikvision is stepping up its cybersecurity efforts with a clear recommendation - to never click on links in emails: It is a surprising change...
Hacked Hikvision IP Camera Map on Dec 18, 2017
The interactive map below shows a sample of hacked and vulnerable Hikvision IP cameras across the USA. Hover over a marker to see an image from...
Broken Hikvision App Exposes Hypocrisy on Dec 06, 2017
While Hikvision talks about a commitment to cybersecurity, their broken app and their insecure 'solution' exposes not only their engineering...
Hikvision UPnP Hacking Risk on Dec 04, 2017
Hikvision IP cameras are being hacked even for end users who had not set up port forwarding and believed their cameras were 'safe' behind...
Dahua Forbes 'Next Web Crisis' Vulnerability Dispute on Nov 16, 2017
The buffer overflow vulnerability in Dahua products is not in dispute, in fact we covered it when it was first published. What is in dispute is...
Vivotek Remote Stack Overflow Vulnerability on Nov 14, 2017
A stack overflow vulnerability in Vivotek cameras has been discovered by bashis, the security researcher who has also found vulnerabilities in...
WSJ Investigates Hikvision on Nov 13, 2017
The Wall Street Journal (WSJ) has released a detailed investigation into Hikvision's government ownership and cybersecurity problems, hitting the...

Most Recent Industry Reports

PoE Powered Access Control Tutorial on Jan 19, 2018
Powering access control with Power over Ethernet is becoming increasingly common.  However, access requires more power than cameras, and the...
If You Have 4 Cameras, You Can Throw Them Away, If You Have 400, They Throw You Away on Jan 19, 2018
Do users care about anything but price? Do user care about cybersecurity? Do users care about trusting their supplier? These have become...
Chinese Government Hikvision Surveillance System On US Government Network on Jan 18, 2018
Hikvision, the Chinese government-owned manufacturer, has publicly claimed that their products are running on a US government network. Moreover,...
Winter 2018 Camera Course on Jan 18, 2018
Learn video surveillance and get certified. Register now. Save $50 on the course, ending this Thursday the 18th, plus get access to 2 class times...
VSaaS Usage Statistics 2018 on Jan 18, 2018
VSaaS has been a 'next big thing' for more than a decade. The prospect of managing, storing and streaming video from the cloud rather than...
Vivint Streety Video Strengthens Door Knocking on Jan 17, 2018
Vivint is famous (or infamous depending on your perspective) for mastering large scale door to door selling. The company has skyrocketed from a...
Axis: "It’s A Question Of Trust And Who You Want To Be Associated With" on Jan 17, 2018
Who do you trust? Who do you want to be associated with? Axis is raising hard questions to start 2018. In this note, we examine these questions,...
Software House Vulnerability Allows Inside Attacker To Open Doors on Jan 17, 2018
A vulnerability in Software House IP-ACM modules allows an attacker to potentially unlock doors, or perform other actions, on affected systems....
'Defiant' Hikvision 'Strikes Back' At WSJ And US on Jan 16, 2018
The fight is on. Hikvision and their owner, the Chinese government, 'strikes back' against the Wall Street Journal and US politicians raising...
The 2018 Surveillance Industry Guide on Jan 16, 2018
The 300 page, 2018 Video Surveillance Industry Guide, covering the key events and the future of the video surveillance market, is now available,...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact