Hotel hybrid broadband internet and TV-on-demand entertainment systems are open to attack, security researchers warn. Penetration testing firm SecureTest has identified a number of vulnerabilities in the implementation of hotel broadband systems delivered using Cisco's LRE (long-reach Ethernet) technology. Using a laptop connected to a hotel network, SecureTest found it was possible to control the TV streams sent to each room or gain access to other user’s laptops.

The security holes uncovered call to mind the security exploits in hotel infra-red controls recently uncovered by Adam Laurie, technical director at secure hosting outfit The Bunker. Ken Munro, managing director of SecureTest, said that its research covered security weaknesses in IP (as opposed to infra-red) systems.

During a stay in a hotel belonging to an unnamed worldwide chain, a SecureTest staffer paid for internet connectivity. He found TCP port 5001 open on the in-room IP enabled TV providing the service. Connecting to this port a full TV maintenance menu was displayed over which it was possible to carry out test procedures, change channels or turn the TV on and off.

Get the full story at The Register