Showing posts with label Default Passwords. Show all posts
Showing posts with label Default Passwords. Show all posts

Sunday, 25 October 2015

Botnet Security Cameras Used For DDoS Attack


It is not just routers and computers that need to be secured, because researchers have identified a botnet of hacked about 900 security cameras discovered that was used to carry out DDoS attacks on a cloud service. This was reported by security firm Imperva.


The cameras are located in various countries, but were concentrated primarily in India. Investigators found the cameras malware that searches for certain devices via Telnet and SSH. This relates to devices on BusyBox run a Linux distribution for embedded systems, and are vulnerable to brute force attacks. In this case it appeared that all hacked cameras were accessible via the default login password. The researchers therefore call on administrators to always change default passwords, whether it's a router, access point or security.

Thursday, 15 October 2015

ZyXEL Routers Vulnerable To Password '1234'



Different routers manufacturer ZyXEL contain multiple vulnerabilities, including a weak default password, which allows remote attackers access to the devices can get. It says the CERT Coordination Center (CERT / CC) at Carnegie Mellon University.

The first problem concerns the default password "1234" for the administrator account on the ZyXEL P-660HW-T1 v2, PMG5318-B20A and NBG-418N. The latter model is also sold in the Netherlands. There are many more models that share the same password. Further, the P-660HW-T1 v2 vulnerable to cross-site scripting.

The PMG5318-B20A show imports of users not to check well, allowing an attacker could execute commands with root privileges, and this router shows users do not log out properly. Even if the user is logged off, the session remains active at least one hour, where an attacker can abuse it. The PMG5318-B20A proves not further restrict the normal user. Therefore, a normal user has full administrative access, instead of limited access.

ZyXEL has remedied some of the problems via firmware updates, and this month will overcome some of the other vulnerabilities. In addition, certain models are no longer supported. Regarding the weak default password of "1234" enables ZyXEL users be wise to change the password after the first login. In different models would be the setting of a new password in the meantime are required.

Monday, 28 September 2015

Backdoor Account In Popular IP Cameras Discovered


A researcher has discovered in potentially tens of thousands of IP cameras undocumented telnet port on the internet so there is a known default password can log on to the devices. The problem would play in inexpensive IP cameras from different manufacturers.

Which manufacturers will want Zoltan Balazs not disclose. Through a network scan, he managed to find the undocumented telnet port. Balazs let know, however, that other researchers have found the same problem before, only through an analysis of the firmware. The problem is that the password to login to the telnet port can not be changed via a graphical user interface.

This may be through the console, but the password change is not permanent. After a reboot the default password will be replaced. "I think it can be said that this is a backdoor," said Balazs. Through access to the password for the FTP server, SMTP server, and Wi-Fi network can be obtained. Also, it is possible to gain access to the normal administrator interface of the camera.

In most cases, the IP camera is protected by a firewall or NAT, so the telnet port is not accessible over the internet, says the researcher. "But there are always exceptions," he observes. Balazs says that users can create a script to change the password on reboot or telnet service completely off. "99% of people who think buys this IP cameras that they are safe," says the researcher. On Reddit sets a reader that up to 70,000 devices on the Internet have to do with the issue.