Page 1 of 1

chromecast hack

Posted: Tue Jan 01, 2019 12:17 pm
by tatere
Posting this here as Sonic Support says it's outside their baliwick:

So I don't know if you've been seeing this, or if maybe it's an old hack come around again, but someone hacked into my Sony Braviaterre through the built-in Chromecast - some examples of people who got bit by it here:

https://twitter.com/hashtag/chromecasthack?src=hash

The TV device listing in gateway.sonic.net was in the DMZ. I must have put it there but I don't remember why. I took it out, I'll see what problems that causes I guess. If you all are familiar with why a TV might need to not be behind the firewall, any information would be useful.

Do you have any other suggestions for what to do to secure my network now? People are saying "turn off UPnP" but as far as I can tell that's not something the PACE 5268AC supports anyway. (Maybe that's why the TV was outside the firewall.)

Re: chromecast hack

Posted: Wed Jan 02, 2019 5:41 pm
by rtrinh
Don't think it would've gone on the DMZ on it's own.

Article about the hack targeting chromecast/smart TV exposed on ports opened 8008, 8009, and 8443 through UPnP.
https://www.zdnet.com/article/hacker-hi ... diepie-ad/