Showing posts with label Netgear. Show all posts
Showing posts with label Netgear. Show all posts

Saturday, 10 October 2015

10,000 Netgear Routers Hacked Via Zero-Day Flaw


More than 10,000 routers network manufacturer Netgear been hacked via a zero-day vulnerability for which no security update is made ​​available. That says Alexandre Herzog of the Swiss security company Compass Security. Through the vulnerability could allow an attacker without a valid password or user access to the admin panel.

The problem was reported to Netgear in July. In September, the network manufacturer announced that it had developed firmware for routers in which the problem was solved. It was, however, this is a beta version. Netgear did however not know when the final version would appear. On September 29, however, made another investigator same security issue known.Then Herzog decided Tuesday to place the vulnerability of details on the company website and Full Disclosure mailing list. Netgear user then let the mailing list know that he was hacked by the leak.

Herzog then asked for information from the victim, to step up the pressure on the Netgear. From the user's information appeared that his router was adapted so that all DNS requests were forwarded to the server of the attacker. The attacker would the user will have to send them to phishing sites or sites containing malware. Researchers from the Swiss security managed with a server that is to make up for the control of the infected routers compound was used. Then they found data indicating that more than 10,000 routers via the vulnerability were hacked, Herzog as late as compared Threat Post know.

The Swiss government GOVCERT would now be trying to get the server from the air and warned the providers of most victims. Which would are located mainly in the United States. To attack the vulnerability, the attack must be run from the internal network. In case the remote management is enabled, this can also be done directly from the Internet. Remote administration is not enabled by default. The problem is present in Netgear routers with the router firmware: N300_1.1.0.31_1.0.1.img and N300-1.1.0.28_1.0.1.img. This firmware is used among others in the WNR1000v4 Router.

Tuesday, 24 February 2015

Research: Thousands Of Netgear Routers Accessible via FTP


Thousands manufacturer Netgear routers with attached storage accessible to anyone via FTP. The problem is independent of a vulnerability that was recently revealed in Netgear routers. In this case it is the WNDR4700 router that is also sold in the Netherlands. On devices running an old version of the ProFTPd FTP server. Not only is it possible to log in as "anonymous". The version in question contains a leak which allows an attacker to execute arbitrary code on the router.

A user of Reddit reports how he found more than 2,000 open routers via the Shodan search engine. Only specify the IP address was enough to log in using the FileZilla FTP program and to gain full read and write permissions. The connected storage media medical information, tax information, private photos, found academic research and business information.

Also, the user could own words 10 to 15 download movies. He hopes that Netgear quickly comes with an update to turn down the FTP access to anonymous users. The problem is reminiscent of earlier incidents where FTP servers unsecured bleaching and so could gain access to sensitive data.
Other vulnerability

A few days ago revealed security researcher Peter Adkins in different Netgear routers another vulnerability which allows an attacker to retrieve information from the device. For this, remote management must be enabled. If this is the case, then an attacker can view and modify certain settings, including the login information for the Wi-Fi network and connected devices.

Adkins had the problem on 18 January reported to Netgear, but the company said that the routers on a security feature that enable users are not at risk. Then the case was closed by Netgear and the researcher decided to make its findings public.Users of NetGear WNDR3700v4, WNR2200 WNR2500 and are advised to disable remote management. The problem probably plays into the WNDR3800, WNDRMAC, WPN824N and WNDR4700.

Monday, 21 July 2014

First version of Open Wireless Router launched



During the X HOPE conference in New York, the first experimental version of the Open Wireless Router has launched a router update that causes the wifi connection is open for other people put. This open access is controlled by a separate guest area.
This should not only make Internet more accessible, but also improve the privacy and anonymity. An IP address is still almost always traceable to a particular Internet user, if there will be anywhere open Wi-Fi networks that link is not so easy to make more.
User
The software should be easy for users to create finally open while they just own WPA2-protected can hold. Partly for their own Wi-Fi network for others In addition, users will also be able to set how much bandwidth guests get assigned, so that the connection of the owner of the Wi-Fi network does not bother the guests are having.
For now operates the Open Wireless Router Netgear WNDR3800 only on the router. It also includes an experimental version. However, the developers hope that more people will get involved, so the software will soon work on more devices and get more features. Themselves with the project
Thus, it is intended to have an automatic update feature to add that some of the information for the updates will be downloaded, which is a targeted attack on the router "very difficult" to make. Using Tor Owners of a Netgear WNDR3800 who want to go to work with the firmware update can be provided through Openwireless.org download.