Vulnerable terminal servers could let bad guys hack stoplights, gas pumps

Industrial control systems, traffic signal controllers, fuel pumps are easily hacked via poorly configured serial port systems, Rapid7 says

Thousands of older systems, including those used to manage critical industrial control equipment, traffic lights, fuel pumps, retail point-of-sale terminals and building automation are vulnerable to tampering because they're insecurely connected to the Internet via terminal servers.

A terminal server, or a network access server, basically provides an easy way to connect any equipment that has a serial port to the Internet.

In a recent study, security firm Rapid7 found more than 114,000 terminal servers on the Internet configured in a way that could allow anyone to gain access to the underlying systems. Most of the systems were from Digi International and Lantronix, two leading manufactures of terminal server devices.

About 95,000 of those servers connected to the Internet via cellular mobile connections and 3G network cards, making them hard to protect, monitor and secure, according to H.D. Moore, the chief research officer at Rapid7 and the author of the study.

Among the systems was one responsible for monitoring humidity and temperature in oil pipelines, another designed to notify the public of emergencies and one used to control temperature and ventilation systems in a building. In one instance, the company discovered a terminal server that provided direct Internet access to confidential payment information contained in a server belonging to a national chain of dry cleaners.

The exposed systems run the gamut from corporate VPNs to traffic signal monitors, Moore said. In more than 13,000 cases, the terminal servers provided a way for anyone on the Internet to gain some form of administrative control of the attached device.

The problem largely involves how organizations configure terminal servers to connect to the Internet, Moore said. They can connect to the Internet via Ethernet, 3G and 4G wireless modems, GSM and satellite connectivity.

Terminal servers allow remote access to connected devices and allow administrators to manage a connected device, monitor it or to extract information from it. In some cases, terminal servers are used to provide an extra "out-of-band" way to access a system or network component in the event of disruption or outage.

Many organizations appear to be unaware of the security risks they face using terminal servers, Moore said, noting that they haven't paid enough attention to authentication measures to control access to the servers and connected systems.

For instance, while terminal servers support authentication, that authentication often applies only to the terminal server itself -- not to the attached serial port, he said. So organizations may have a mistaken sense of security over access to serially attached ports, he said.

Serial port enabled devices also often require users to actively log off a system once they are done. If a user fails to do so, the service console is left in an authenticated state and can be used by an attacker to take control, Moore said.

One port-enabled device uncovered during the research had remained in a fully authenticated state for more than 990 straight hours because an administrator failed to log off the system, he said.

In addition, terminal server devices often come with default passwords and backdoors that are left in place. Many of these systems also have weak or non-existent encryption technologies to protect communications, he said.

The fact that a large number of terminal servers connect via cellular and 3G networks means that they are outside a traditional firewall and, therefore, much harder to protect, he said.

Moore's recommendations for protecting terminal servers include the use of strong passwords and non-default user names, authentication to access serial ports and the use of encrypted services such as SSL and SSH to access the devices.

Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at @jaivijayan or subscribe to Jaikumar's RSS feed. His e-mail address is

See more by Jaikumar Vijayan on

Read more about malware and vulnerabilities in Computerworld's Malware and Vulnerabilities Topic Center.

Join the CSO newsletter!

Error: Please check your email address.

Tags Cybercrime and HackingRapid7securityMalware and Vulnerabilities

More about Digi InternationalDigi InternationalLantronixRapid7SSHTopic

Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Stories by Jaikumar Vijayan

Latest Videos

  • 150x50

    CSO Webinar: Will your data protection strategy be enough when disaster strikes?

    Speakers: - Paul O’Connor, Engagement leader - Performance Audit Group, Victorian Auditor-General’s Office (VAGO) - Nigel Phair, Managing Director, Centre for Internet Safety - Joshua Stenhouse, Technical Evangelist, Zerto - Anthony Caruana, CSO MC & Moderator

    Play Video

  • 150x50

    CSO Webinar: The Human Factor - Your people are your biggest security weakness

    ​Speakers: David Lacey, Researcher and former CISO Royal Mail David Turner - Global Risk Management Expert Mark Guntrip - Group Manager, Email Protection, Proofpoint

    Play Video

  • 150x50

    CSO Webinar: Current ransomware defences are failing – but machine learning can drive a more proactive solution

    Speakers • Ty Miller, Director, Threat Intelligence • Mark Gregory, Leader, Network Engineering Research Group, RMIT • Jeff Lanza, Retired FBI Agent (USA) • Andy Solterbeck, VP Asia Pacific, Cylance • David Braue, CSO MC/Moderator What to expect: ​Hear from industry experts on the local and global ransomware threat landscape. Explore a new approach to dealing with ransomware using machine-learning techniques and by thinking about the problem in a fundamentally different way. Apply techniques for gathering insight into ransomware behaviour and find out what elements must go into a truly effective ransomware defence. Get a first-hand look at how ransomware actually works in practice, and how machine-learning techniques can pick up on its activities long before your employees do.

    Play Video

  • 150x50

    CSO Webinar: Get real about metadata to avoid a false sense of security

    Speakers: • Anthony Caruana – CSO MC and moderator • Ian Farquhar, Worldwide Virtual Security Team Lead, Gigamon • John Lindsay, Former CTO, iiNet • Skeeve Stevens, Futurist, Future Sumo • David Vaile - Vice chair of APF, Co-Convenor of the Cyberspace Law And Policy Community, UNSW Law Faculty This webinar covers: - A 101 on metadata - what it is and how to use it - Insight into a typical attack, what happens and what we would find when looking into the metadata - How to collect metadata, use this to detect attacks and get greater insight into how you can use this to protect your organisation - Learn how much raw data and metadata to retain and how long for - Get a reality check on how you're using your metadata and if this is enough to secure your organisation

    Play Video

  • 150x50

    CSO Webinar: How banking trojans work and how you can stop them

    CSO Webinar: How banking trojans work and how you can stop them Featuring: • John Baird, Director of Global Technology Production, Deutsche Bank • Samantha Macleod, GM Cyber Security, ME Bank • Sherrod DeGrippo, Director of Emerging Threats, Proofpoint (USA)

    Play Video

More videos

Blog Posts

Market Place