[爆卦] 美網路安全暨基礎設施安全局證實UPS漏洞

作者: GETpoint (擲雷爆卦)   2022-04-02 11:43:08
美國網路安全暨基礎設施安全局(CISA)指出UPS成為駭客攻擊目標:
官網: https://tinyurl.com/bdzu74ak
CISA and the Department of Energy (DOE) are aware of threat actors gaining
access to a variety of internet-connected uninterruptable power supply (UPS)
devices, often through unchanged default usernames and passwords.
Organizations can mitigate attacks against their UPS devices, which provide
emergency power in a variety of applications when normal power sources are
lost, by removing management interfaces from the internet.
CISA發布的聲明中指出,攻擊者通常會透過未變更的預設使用者名稱及密碼,來獲得不同
連網 UPS 的存取權限。所以我們最好能先將預設密碼改成強固密碼或較複雜密碼,至少
可以獲得基本的安全保障。再者,我們可以透過將管理介面從網際網路上移除,便能有效
減緩連網 UPS 被攻擊的可能性。

Links booklink

Contact Us: admin [ a t ] ucptt.com