← Back to context

Comment by pigggg

11 hours ago

Millions of Superboxes and various digital picture frames say different.

https://synthient.com/blog/a-broken-system-fueling-botnets

Kimwolf exploits vulnerable Android Debug Bridge (ADB) services. Many low-cost TV boxes come "pre-infected" with proxy SDKs; Kimwolf then scans these residential proxy networks and exploits the devices within minutes as it propagates.

https://www.cloudflare.com/learning/ddos/glossary/aisuru-kim...

This is like saying that SSH is insecure because some device vendors install SSH, permitting root login with a default password of 'root'.

  • Yeah let's block port 80, too many people expose unprotected api.

    • This is what several cellular ISP to (block ports <1024 and 5555) to protect the users on IPv6.

      You can unlock it with additional free option.

Well yes, but those won't get Google's new updates either. Open ADB on 5555 was a problem we solved almost a decade ago and these devices are still vulnerable. Even further restricting ADB in the latest version won't do anything to prevent that.