Akamai Technologies revealed that hackers are exploiting a 12-year-old bug in OpenSSH to hack into millions of IoT devices. The SSHowDowN Proxy attack exploits the CVE-2004-1653 flaw to enable TCP forwarding and port bounces when a proxy is in use. At least 11 of its customers in various industries, including financial services, hospitality, retail, and gaming, have been hit with SSHowHowDOWN Proxy attacks. The vast majority of devices is exposed due to lax security, it is quite common to find smart objects configured with vendor default passwords or keys.”]
Source: http://securityaffairs.co/wordpress/52254/hacking/sshowdown-proxy-attacks.html

