Stories
Slash Boxes
Comments
typodupeerror delete not in

Comments: 4 +-   All Home Routers are Hackable! on Sunday January 13 2008, @05:56PM Anonymous

Submitted by Anonymous on Sunday January 13 2008, @05:56PM
security
Anonymous writes "The GNUCITIZEN guys have posted a very interesting research. It seems that all Wireless/Home Routers are remotely exploitable. From the article:



When the victim visits the malicious SWF file, the [a 6 step attack] will silently execute in the background. At that moment the attacker will have control over the service the portforwarding rule was assigned for. Keep in mind that no XSS is required, it is a matter of visiting the wrong resource at the wrong time. Also, keep in mind that 99% of home routers are vulnerable to this attack as all of them support UPnP to one degree or another.

I repeat myself far too much, but I guess I have another opportunity to mention that adding a portforwarding is only one of the many things someone can do to your router. The most malicious of all malicious things is to change the primary DNS server. That will effectively turn the router and the network it controls into a zombie which the attacker can take advantage of whenever they feel like it. It is also possible to reset the admin credentials and create the sort of onion routing network all the bad guys want. We hope that by exposing this information, we will drastically improve the situation for the future. I think that this is a lot better than keeping it for ourselves or risking it all by given the criminals the opportunity to have in possession a secret which no one else is aware of.
"
submission

This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More
Loading... please wait.
    • We call it "Shrug and Pray", which is all most people do when they plug their computer into the Internet anyway.
  • 99% of them might support UPnP, but 90% of those allow you to turn it off, and any reputable company should be setting it to "off" by default anyway.
    • Those same 90% are the ones who also don't enable some kind of wireless security by default.

      I wouldn't have that much faith in them.

Paul Revere was a tattle-tale.