Author Topic: Router vulnerability to be exploited  (Read 516 times)

Offline Skuzzy

  • Support Member
  • Administrator
  • *****
  • Posts: 31462
      • HiTech Creations Home Page
Router vulnerability to be exploited
« on: July 21, 2010, 08:15:42 AM »
This could affect anyone who has a router on thier home network.  Might want to check this out folks.

http://blogs.forbes.com/firewall/2010/07/13/millions-of-home-routers-vulnerable-to-web-hack/
Roy "Skuzzy" Neese
support@hitechcreations.com

Offline gyrene81

  • Plutonium Member
  • *******
  • Posts: 11629
Re: Router vulnerability to be exploited
« Reply #1 on: July 21, 2010, 10:30:33 AM »
No worries here. Very interesting that the guy is talking about releasing the exploit into the wild though.
jarhed  
Build a man a fire and he'll be warm for a day...
Set a man on fire and he'll be warm for the rest of his life. - Terry Pratchett

Offline fbWldcat

  • Gold Member
  • *****
  • Posts: 2970
Re: Router vulnerability to be exploited
« Reply #2 on: July 21, 2010, 10:41:07 AM »
After reading the chart I don't have the highest chance, but any chance is too much of one. I can't be exploited, apparently. This should be criminal releasing it to the public. Kinda like those new lasers that can blind and burn.

Wow, just wow.
Landing is overrated.
"Two roads diverged in a wood, and I: I took the one less traveled by." - Robert Frost
"Uncommon valor was a common virtue." <S>

Offline Ghastly

  • Silver Member
  • ****
  • Posts: 1756
Re: Router vulnerability to be exploited
« Reply #3 on: July 21, 2010, 10:59:35 AM »
Please note that for the purpose of describing this exploit, your router is considered vulnerable if the external site can use DNS rebinding to open a connection to your router.  Note that once the connection to your router is open, the bad guys on the other end must still "break" the router or the router password to actually exploit it. 

And if your router has open vulnerabilities, is unpatched, and/or is still set to the default password, this particular exploit is utterly moot - you are ALREADY at tremendous risk from a remote control trojan, of which there are PLENTY in the wild. 

Don't let the fact that your router isn't listed on his list for this exploit give you a false sense of security that it's not exploitable - or necessarily freak out if it is.  But do keep it's firmware up to date and change the password from the default to a strong password at the earliest possible stage in the initial setup of the router, and change it periodically after that, regardless.

<S>
"Curse your sudden (but inevitable!) betrayal!"
Grue

Offline Skuzzy

  • Support Member
  • Administrator
  • *****
  • Posts: 31462
      • HiTech Creations Home Page
Re: Router vulnerability to be exploited
« Reply #4 on: July 21, 2010, 11:08:05 AM »
It is alarming how many people do not change the default passwords on routers.  It is even more alarming how many people do not change the encryption key on WiFi routers.
Roy "Skuzzy" Neese
support@hitechcreations.com

Offline Bino

  • Platinum Member
  • ******
  • Posts: 5938
Re: Router vulnerability to be exploited
« Reply #5 on: July 21, 2010, 12:07:07 PM »
It is alarming how many people do not change the default passwords on routers.  It is even more alarming how many people do not change the encryption key on WiFi routers.

Skuzzy, ever read The Cukoo's Egg?  The badguy in that story logged on to servers - at universities and companies - with factory default username/password pairs, like "guest/user" and "field/service".  :O


"The plural of 'anecdote' is not 'data'." - Randy Pausch

PC Specs

Offline 2bighorn

  • Gold Member
  • *****
  • Posts: 2829
Re: Router vulnerability to be exploited
« Reply #6 on: July 21, 2010, 12:09:45 PM »
Add to that windows shell vulnerability and we are set for the fun summer...

Offline Chalenge

  • Plutonium Member
  • *******
  • Posts: 15179
Re: Router vulnerability to be exploited
« Reply #7 on: July 21, 2010, 03:31:26 PM »
I have six homes within range of my wireless that are still set to default.
If you like the Sick Puppy Custom Sound Pack the please consider contributing for future updates by sending a months dues to Hitech Creations for account "Chalenge." Every little bit helps.

Offline fbWldcat

  • Gold Member
  • *****
  • Posts: 2970
Re: Router vulnerability to be exploited
« Reply #8 on: July 21, 2010, 04:45:36 PM »
I have six homes within range of my wireless that are still set to default.

I have two.
Landing is overrated.
"Two roads diverged in a wood, and I: I took the one less traveled by." - Robert Frost
"Uncommon valor was a common virtue." <S>

Offline ImADot

  • Platinum Member
  • ******
  • Posts: 6215
Re: Router vulnerability to be exploited
« Reply #9 on: July 21, 2010, 10:48:09 PM »
Steve Gibson from GRC has some good info and utilities.

ShieldsUP - checks status of your ports
https://www.grc.com/x/ne.dll?bh0bkyd2

GRC's Perfect Passwords - completely random (maximum entropy) without any pattern, and the cryptographically-strong pseudo random number generator we use guarantees that no similar strings will ever be produced again
https://www.grc.com/passwords.htm

Router NAT Explained
http://www.grc.com/nat/nat.htm
My Current Rig:
GigaByte GA-X99-UD4 Mobo w/ 16Gb RAM
Intel i7 5820k, Win7 64-bit
NVidia GTX 970 4Gb ACX 2.0
Track IR, CH Fighterstick, CH Pro Throttle, CH Pro Pedals

Offline Chalenge

  • Plutonium Member
  • *******
  • Posts: 15179
Re: Router vulnerability to be exploited
« Reply #10 on: July 22, 2010, 12:56:18 AM »
Steve Gibson makes McGyver look like a tenderfoot.  :aok
If you like the Sick Puppy Custom Sound Pack the please consider contributing for future updates by sending a months dues to Hitech Creations for account "Chalenge." Every little bit helps.

Offline Anodizer

  • Silver Member
  • ****
  • Posts: 1941
Re: Router vulnerability to be exploited
« Reply #11 on: July 22, 2010, 09:18:51 PM »
I willingly provide free wi-fi to the entire neighborhood..   :angel:
I like classy, beautiful, intelligent woman that say the "F" word a lot....

80th FS "Headhunters"