Home Upload Photo Upload Videos Write a Blog Analytics Messaging Streaming Create Adverts Creators Program
Bebuzee Afghanistan Bebuzee Albania Bebuzee Algeria Bebuzee Andorra Bebuzee Angola Bebuzee Antigua and Barbuda Bebuzee Argentina Bebuzee Armenia Bebuzee Australia Bebuzee Austria Bebuzee Azerbaijan Bebuzee Bahamas Bebuzee Bahrain Bebuzee Bangladesh Bebuzee Barbados Bebuzee Belarus Bebuzee Belgium Bebuzee Belize Bebuzee Benin Bebuzee Bhutan Bebuzee Bolivia Bebuzee Bosnia and Herzegovina Bebuzee Botswana Bebuzee Brazil Bebuzee Brunei Bebuzee Bulgaria Bebuzee Burkina Faso Bebuzee Burundi Bebuzee Cabo Verde Bebuzee Cambodia Bebuzee Cameroon Bebuzee Canada Bebuzee Central African Republic Bebuzee Chad Bebuzee Chile Bebuzee China Bebuzee Colombia Bebuzee Comoros Bebuzee Costa Rica Bebuzee Côte d'Ivoire Bebuzee Croatia Bebuzee Cuba Bebuzee Cyprus Bebuzee Czech Republic Bebuzee Democratic Republic of the Congo Bebuzee Denmark Bebuzee Djibouti Bebuzee Dominica Bebuzee Dominican Republic Bebuzee Ecuador Bebuzee Egypt Bebuzee El Salvador Bebuzee Equatorial Guinea Bebuzee Eritrea Bebuzee Estonia Bebuzee Eswatini Bebuzee Ethiopia Bebuzee Fiji Bebuzee Finland Bebuzee France Bebuzee Gabon Bebuzee Gambia Bebuzee Georgia Bebuzee Germany Bebuzee Ghana Bebuzee Greece Bebuzee Grenada Bebuzee Guatemala Bebuzee Guinea Bebuzee Guinea-Bissau Bebuzee Guyana Bebuzee Haiti Bebuzee Honduras Bebuzee Hong Kong Bebuzee Hungary Bebuzee Iceland Bebuzee India Bebuzee Indonesia Bebuzee Iran Bebuzee Iraq Bebuzee Ireland Bebuzee Israel Bebuzee Italy Bebuzee Jamaica Bebuzee Japan Bebuzee Jordan Bebuzee Kazakhstan Bebuzee Kenya Bebuzee Kiribati Bebuzee Kuwait Bebuzee Kyrgyzstan Bebuzee Laos Bebuzee Latvia Bebuzee Lebanon Bebuzee Lesotho Bebuzee Liberia Bebuzee Libya Bebuzee Liechtenstein Bebuzee Lithuania Bebuzee Luxembourg Bebuzee Madagascar Bebuzee Malawi Bebuzee Malaysia Bebuzee Maldives Bebuzee Mali Bebuzee Malta Bebuzee Marshall Islands Bebuzee Mauritania Bebuzee Mauritius Bebuzee Mexico Bebuzee Micronesia Bebuzee Moldova Bebuzee Monaco Bebuzee Mongolia Bebuzee Montenegro Bebuzee Morocco Bebuzee Mozambique Bebuzee Myanmar Bebuzee Namibia Bebuzee Nauru Bebuzee Nepal Bebuzee Netherlands Bebuzee New Zealand Bebuzee Nicaragua Bebuzee Niger Bebuzee Nigeria Bebuzee North Korea Bebuzee North Macedonia Bebuzee Norway Bebuzee Oman Bebuzee Pakistan Bebuzee Palau Bebuzee Panama Bebuzee Papua New Guinea Bebuzee Paraguay Bebuzee Peru Bebuzee Philippines Bebuzee Poland Bebuzee Portugal Bebuzee Qatar Bebuzee Republic of the Congo Bebuzee Romania Bebuzee Russia Bebuzee Rwanda Bebuzee Saint Kitts and Nevis Bebuzee Saint Lucia Bebuzee Saint Vincent and the Grenadines Bebuzee Samoa Bebuzee San Marino Bebuzee São Tomé and Príncipe Bebuzee Saudi Arabia Bebuzee Senegal Bebuzee Serbia Bebuzee Seychelles Bebuzee Sierra Leone Bebuzee Singapore Bebuzee Slovakia Bebuzee Slovenia Bebuzee Solomon Islands Bebuzee Somalia Bebuzee South Africa Bebuzee South Korea Bebuzee South Sudan Bebuzee Spain Bebuzee Sri Lanka Bebuzee Sudan Bebuzee Suriname Bebuzee Sweden Bebuzee Switzerland Bebuzee Syria Bebuzee Taiwan Bebuzee Tajikistan Bebuzee Tanzania Bebuzee Thailand Bebuzee Timor-Leste Bebuzee Togo Bebuzee Tonga Bebuzee Trinidad and Tobago Bebuzee Tunisia Bebuzee Turkey Bebuzee Turkmenistan Bebuzee Tuvalu Bebuzee Uganda Bebuzee Ukraine Bebuzee United Arab Emirates Bebuzee United Kingdom Bebuzee Uruguay Bebuzee Uzbekistan Bebuzee Vanuatu Bebuzee Venezuela Bebuzee Vietnam Bebuzee World Wide Bebuzee Yemen Bebuzee Zambia Bebuzee Zimbabwe
Blog Image

Schools warned over hackable heating systems

Concerns have been raised that hackers could attack schools' heating systems during a cold spell

Dozens of British schools' heating systems have been found to be vulnerable to hackers, according to a probe by a security research firm.

Pen Test Partners says the problem was caused by the equipment's controllers being connected to the wider internet, against the manufacturer's guidelines.

It says it would be relatively easy for mischief-makers to switch off the heaters from afar.

But an easy fix, pulling out the network cables, can address the threat.

Even so, the company suggests the discovery highlights that building management systems are often installed by electricians and engineers that need to know more about cyber-security.

"It would be really easy for someone with basic computer skills to have switched off a school's heating system - it's a matter of clicks and some simple typing," Pen Test's founder Ken Munro told the BBC.

"It's a reflection of the current state of internet-of-things security.

"Installers need to up their game, but manufacturers must also do more to make their systems foolproof so they can't be set up this way."

The cyber-security company made its discovery by looking for building management system controllers made by Trend Control Systems via the internet of things (IoT) search tool Shodan.

It knew that a model, released in 2003, could be compromised when exposed directly to the net, even if it was running the latest firmware.

Mr Munro said it had taken him less than 10 seconds to find more than 1,000 examples.

In addition to the schools, he said he had seen cases involving retailers, government offices, businesses and military bases.

Pen Test blogged about its findings earlier in the week, but the BBC delayed reporting the issue until it had contacted and alerted all of the schools that could be identified by name.

West Sussex-based Trend Control Systems advises its customers to use skilled IT workers to avoid the problem.

But it responded to criticism that it could have done more to check its kit had been properly installed after the fact.

"Trend takes cyber-security seriously and regularly communicates with customers to make devices and connections as secure as possible," said spokesman Trent Perrotto.

"This includes the importance of configuring systems behind a firewall or virtual private network, and ensuring systems have the latest firmware and other security updates to mitigate the risk of unauthorised access."

He added, however, that the company would "assess and test the effectiveness" of its current practices.

One independent security researcher played down the threat to those still exposed, but added that the case raised issues that should be addressed.

"The risk is limited because criminals have little incentive to carry out such attacks, and even if they did it should be possible for building managers to notice what is happening and manually override," said Dr Steven Murdoch, from University College London.

"However, these problems do show the potential for far more dangerous scenarios in the future, as more devices get connected to the internet, whose failure might be harder to recover from.

"And we still need manufacturers to design secure equipment, because even if a device is not directly connected to the internet, there almost certainly is an indirect way in."

Previous Post

iMac Pro: Apple releases its most expensive computer – starting at £4,899

Next Post

Lord Adonis says Ofcom must tackle 'deplorable' mobile coverage

Comments


Related Blogs

Blog Image
Education

Dilemma Of Delocalized Heads Without Schools To Head As Others Refuse To Go Back To Their Homes


BY Elinah Kawira
Blog Image
Education

At the beginning of the school year, a strike in 500 schools, classes for 30 minutes


BY Turner Booth
Blog Image
Education

Educators hope to see end of decile system in schools


BY Daniella Chapman
Blog Image
Education

Education minister criticises “irresponsible” principals for allowing LGBT day in Polish schools


BY Margaret Miller