The Xiongmai Botnet 'Recall' Will Not Work

Author: John Honovich, Published on Oct 25, 2016

The Xiongmai 'recall' has been the topic of global news, following the unprecedented bot net attacks that use their equipment, among others.

However well intentioned this 'recall' may be, it is not going to work. Understanding how Xiongmai and their customer's business model works makes this clear.

Xiongmai No Branded Sales

Xiongmai does not sell under its own brand nor to end users. Because of this, they have no idea what end users actually have their products.

Hidden OEM / Supplier

Xiongmai, even within the video surveillance industry, has near zero brand recognition (until this disaster). Because of this, the companies that Xiongmai sell components / modules to almost never disclose that they use Xiongmai. Indeed, this is a key reason why despite the global coverage, few if any manufacturers have been identified as using Xiongmai.

OEMs / Relabelers No Interest In Disclosing Now

For the recall to work, the companies that buy and use Xiongmai components (OEMs / relabelers) will have to disclose to their customers that they are using Xiongmai. Even under normal circumstances, video surveillance OEMs have legal agreements that prohibit their suppliers, like Xiongmai, from confirming who their OEMs are. These companies/OEMs have zero incentive to do so now as acknowledging it risks massive brand damage and potential litigation. 

No Records of End Users Likely

Indeed, even if Xiongmai's customers were open to a publicly announced recall, most have no idea who are using these products. Registration of products is extremely uncommon within the video surveillance industry, where products are either sold through retail (which does not track end users) or through integrators (who typically do not want their manufacturer partners to know who 'their' customers are).

Realistic About Recall No Impact

Because of all this, we all need to be realistic that a recall is not going to work, even if Xiongmai really wants to try one. Sure, they can recall things in inventory from their partners if those products are vulnerable but there are millions of Xiongmai based devices already deployed (as Xiongmai is a major supplier) and the likelihood that they can recall / remove even a fraction of the infected botnet army is slim to none.

Net / net, to stop these infections, we need to look beyond the potential of a recall.

3 reports cite this report:

CES 2018 Show Final Report on Jan 12, 2018
This is IPVM's final edition of our 2018 CES show report. Below are already numerous images and commentary, with more coming tomorrow.   CES is...
Mirai-like Botnet Persirai Attacks IP Cameras - Impact Analyzed on Jun 14, 2017
Mirai made headlines in 2016, exploiting weaknesses in cameras, including those from Dahua and XiongMai to create a massive botnet that was used to...
Hackers Battle For 3 Million Strong Mirai Botnet on Nov 28, 2016
Mirai-infected devices have become so large and so prevalent that multiple hackers are now fighting each other to control these devices. This...

Comments (23)

Only IPVM PRO Members may comment. Login or Join.

Agreed. A recall won't work.

This may require a Stuxnet type response. Yes, a deliberate action to render these units useless.

If that seems drastic, I would like to hear what other ideas exist to address the threat of continued DDoS attacks on the internet.

This may require a Stuxnet type response. Yes, a deliberate action to render these units useless.

Its harder than you might think on these devices, since they have read-only filesystems with the passwords hardcoded.

So if you just break it, a default reset puts it back in the game.

That'a the reason that even XiongMai doesn't have a firmware fix for these devices.

The cost of using the "cheapest" product out there means that the entire "internet" economy suffers due to this.

How many more attacks before we wake up to, China doesn't care....

Their economy requires it has to be firing on all 8 cylinders in order to keep 1 Billion people "happy". If it means causing the rest of the world to suffer, they really don't care.

That said, when we "exported" capitalism to China, they put their economy on steroids and like locusts they will swallow anything in sight in order to control that space.

Shutting down the infrastructure without dropping 1 bomb is cheaper and inherently a less risky proposition.

A bigger concern is the integrators who don't care. They are effectively fuel for the fire. This is unlikely to remedy until it becomes too costly to sell these products due to litigation.

Net / net, to stop these infections, we need to look beyond the potential of a recall.

Should Hikvision Hack Its Own DVR's?

Should I Hack 10,000 Dahua Cameras?

Should Axis Hack Axis Public Cameras?

Prediction: XiongMai ends up using this global news coverage to their advantage. They will say repeatedly that

  1. Its not our fault
  2. Even if its our fault, others manufacturers are equally at fault
  3. Even if its our fault, improper installation is equally at fault
  4. Even if its our fault, we fixed it in all our latest products
  5. Its our fault, but we are the only manufacturer to do the right thing and recall our products

A smart reverse reputation play, even if 7 people take them up on the recall.

XiongMai who nobody knew yesterday, gets a instant brand, tarnished a bit for sure, but that fades if you deliver in the meantime.

XiongMai who nobody knew yesterday, gets a instant brand, tarnished a bit for sure

'tarnished a bit' is an understatement. Their brand is destroyed, given the severity of the attacks. I don't think most tech and business people following this will ever trust them. And XiongMai is not some sophisticated marketing machine that can somehow find a way to turn this to their benefit. They are better off just purging the XiongMai brand and going with something else.

In 1982, seven Chicago-area residents died from cyanide-laced Extra-Strength Tylenol. Marketers predicted that the Tylenol brand would never recover from the sabotage.

The following year, Tylenol’s share of the analgesic market climbed 23 percent, and The New York Times wrote, “ It is almost as if nothing ever happened.”

Yes, you're right, Johnson and Johnson doesn't make DVR cards, and had an established brand already and HQ in the U.S. among their other vast differences.

But the point is that memories are short. Maybe another low-cost alternative to the Peoples Republic of Hikvision or the dysfunctional Dahuan Dynasty.

You can certainly argue persuasively that they're done, thats easily done considering the events. But I only made the prediction because of its apparent impossibility.

Firewalls are only way to stop this.

Especially edge firewall at customer premises.

Drop all DNS queries from camera subnet or ip range.

That will break ntp, so ntp server might have to be set by ip address, or set to an internal ntp service.

If you want to connect low cost devices to the internet, they have to be behind a properly configured firewall, otherwise it becomes tragedy of the commons - everyone dumps their junk in the common space.

Hear, hear David.

As long as the devices are not configured properly nor firewalled you will have networks (nutworks) that scream "here, here".

From Shenzhen Daily

A CHINESE electronics maker that has recalled products sold in the United States said Tuesday it did all it could to prevent a massive cyberattack that briefly blocked access to websites including Twitter and Netflix.

Hangzhou Xiongmai Technology has said some of its Web-connected cameras and digital recorders became compromised because customers failed to change their default passwords.

Liu Yuexin, Xiongmai’s marketing director, said that Xiongmai and other companies across the home surveillance equipment industry were made aware of the vulnerability in April 2015. Liu said Xiongmai moved quickly to plug the gaps and should not be singled out for criticism.

“We don’t know why there is a spear squarely pointed at our chest,” Liu said.

The hack has heightened long-standing fears among security experts that the rising number of interconnected home gadgets, appliances and even automobiles represent a cybersecurity nightmare. The convenience of being able to control home electronics via the Web also leaves them more vulnerable to malicious intruders, experts say.

Unidentified hackers seized control of gadgets including Xiongmai’s Friday and directed them to launch an attack that temporarily disrupted access to a host of sites, ranging from Twitter and Netflix to Amazon and Spotify, according to U.S. Web security researchers.

The “distributed denial-of-service” attack targeted servers run by Dyn Inc., an Internet company located in Manchester, New Hampshire. These types of attacks work by overwhelming targeted computers with junk data so that legitimate traffic can’t get through. (SD-Agencies)

The hack has heightened long-standing fears among security experts that the rising number of interconnected home gadgets, appliances and even automobiles represent a cybersecurity nightmare. The convenience of being able to control home electronics via the Web also leaves them more vulnerable to malicious intruders, experts say.

Having worked at a National Laboratory (an environment very concerned with security), I have never understood why one would want to hook something up to the Internet and then be vulnerable to the world's malicious elements.

We don't even do wireless in my house.

Craig

We don't even do wireless in my house.

Not even cell phones?

Now, now, no need for sarcasm... or obvious sanctimonious misinterpretation.

Not sarcastic at all.

I think its a fair question, since smartphones are roving wireless linux computers, no? And they have been known to be hacked every now and again.

OK... sorry. I misinterpreted.

I believe has was referring to wifi.

Maybe he can clarify.

Yes, I agree he most likely was. Still if the phone connects to the internet wirelessly, then it can be snooped on and MITM just the same,no?

No WIFI here. No smart phones, either (who wants to walk around with a computer that has more capability than some supercomputers had not that long ago).

...who wants to walk around with a computer that has more capability than some supercomputers had not that long ago...

Anyone looking for Pokemon. Its the minimum requirement :)

I mean this seriously, without any snark, but the answer to that question seems to literally be a majority of people.

Hmm.. Long thought. 1st- That would depend on where "the middle" is. Wireless, network? Who originated and who is "looking". Cellular is pretty darn good. Wifi is as good as it's implementer.

The original subject was the take over of cameras. If you look at the attack it was based on all the general default passwords of semi capable cute little devices. The point was if you leave a semi controllable (Linux) device on the open net without all the other proper cautions then... we have a DoS device.

Having made many "devices", I don't think we should blame the device, or the devices manufacturer. Rather, the implementers.

Newly added XM branded product in Amazon:

May be the cheapest 1080p ptz(d) out there.

Related Reports

Hikvision FIPS 140-2 Cybersecurity Certification Examined on Aug 27, 2018
A week after the US government passed a law banning Hikvision, Hikvision announced it had obtained a FIPS 140-2 certification from the US...
France Political Scandal Reveals Video Surveillance Problems on Aug 22, 2018
In what French media describes as "the most damaging crisis yet for" French President Marcon, a political scandal has revealed major gaps in the...
Sony Gen 5 IP Cameras Critical Vulnerabilities on Jul 26, 2018
Cybersecurity vulnerabilities remain prevalent in video surveillance devices. Now Talos researchers have discovered multiple vulnerabilities in...
July 2018 IP Networking Course on Jul 12, 2018
Registration is closed. This is the only networking course designed specifically for video surveillance professionals.  Lots of network training...
GDPR For Access Control Guide on Jul 03, 2018
Electronic access control is common in businesses plus organizations are increasingly considering biometrics for access control. With GDPR coming...
Replacing / Switching Access Control Systems Guide on Jun 28, 2018
Ripping out and replacing access control systems is hard for important reasons. Because users typically hold on to access control systems for as...
Hikvision Corrects False Cybersecurity Announcement on Jun 18, 2018
Hikvision has corrected a false cybersecurity announcement that claimed a British government-sponsored program endorsed the cybersecurity of...
The Dumb Ones: PSA's Bozeman On Cybersecurity on Jun 15, 2018
The smart ones are the hundred people who flew to Denver and spent $500+ on a 1.5-day conference featuring (now US government banned) Dahua as a...
Debating Relevance of China Hacking US Navy Plans on Jun 11, 2018
"Chinese government hackers have compromised the computers of a Navy contractor, stealing massive amounts of highly sensitive data related to...
Remove Dahua and Hikvision Gov Installs Required By US House Bill Ban on Jun 06, 2018
The final released US House Bill HR 5515 verifies that it not only prohibits the purchasing of Dahua and Hikvision products, it requires removing...

Most Recent Industry Reports

Alexa Guard Expands Amazon's Security Offerings, Boosts ADT's Stock on Sep 21, 2018
Amazon is expanding their security offerings yet again, this time with Alexa Guard that delivers security audio analytics and a virtual "Fake...
UTC, Owner of Lenel, Acquires S2 on Sep 20, 2018
UTC now owns two of the biggest access control providers, one of integrator's most hated access control platforms, Lenel, and one of their...
BluePoint Aims To Bring Life-Safety Mind-Set To Police Pull Stations on Sep 20, 2018
Fire alarm pull stations are commonplace but police ones are not. A self-funded startup, BluePoint Alert Solutions is aiming to make police pull...
SIA Plays Dumb On OEMs And Hikua Ban on Sep 20, 2018
OEMs widely pretend to be 'manufacturers', deceiving their customers and putting them at risk for cybersecurity attacks and, soon, violation of US...
Axis Vs. Hikvision IR PTZ Shootout on Sep 20, 2018
Hikvision has their high-end dual-sensor DarkfighterX. Axis has their high-end concealed IR Q6125-LE. Which is better? We bought both and tested...
Avigilon Announces AI-Powered H5 Camera Development on Sep 19, 2018
Avigilon will be showcasing "next-generation AI" at next week's ASIS GSX. In an atypical move, the company is not actually releasing these...
Favorite Request-to-Exit (RTE) Manufacturers 2018 on Sep 19, 2018
Request To Exit devices like motion sensors and lock releasing push-buttons are a part of almost every access install, but who makes the equipment...
25% China Tariffs Finalized For 2019, 10% Start Now, Includes Select Video Surveillance on Sep 18, 2018
A surprise move: In July, when the most recent tariff round was first announced, the tariffs were only scheduled for 10%. However, now, the US...
Central Stations Face Off Against NFPA On Fire Monitoring on Sep 18, 2018
Central stations are facing off against the NFPA over what they call anti-competitive language in NFPA 72, the standard that covers fire alarms....
Hikvision USA Starts Layoffs on Sep 18, 2018
Hikvision USA has started layoffs, just weeks after the US government ban was passed into law. Inside this note, we examine: The important...

The world's leading video surveillance information source, IPVM provides the best reporting, testing and training for 10,000+ members globally. Dedicated to independent and objective information, we uniquely refuse any and all advertisements, sponsorship and consulting from manufacturers.

About | FAQ | Contact