Showing posts with label Router. Show all posts
Showing posts with label Router. Show all posts

Wednesday, 2 September 2015

UPnP Routers Lets You Customize Firewall Attacker



The Universal Plug and Play (UPnP) protocol to make it easier for devices to communicate with each other and connect, but an unknown number of routers, the security is not well regulated, so an attacker can open quietly ports in the firewall or access to the router can get.

Before that warns the CERT Coordination Center (CERT / CC) at Carnegie Mellon University. The UPnP protocol was originally developed for private networks and uses standard therefore no authentication. Later it was decided to draw up a UPnP security standard set yet, but this support is very limited. Because of the lack of security could allow an attacker with access to the private network via UPnP access to the router and to prepare for open ports or services that enable the network to be attacked further.

Although the UPnP problems that the CERT / CC warns alone can be attacked via private networks, it is also possible from the internet here to access it. Via a dedicated website, an attacker, with Chrome and Firefox users who have enabled JavaScript, that any UPnP requests sent to the firewall and thus the network further attacks. The "Filet-O-Firewall"vulnerability has already been demonstrated in early August, but now the CERT / CC decided to issue a warning.

As a solution, users advised to not open unknown links, UPnP off, implement the latest UPnP standards or to the UPnP control arbitrary URL, so that can not be guessed by an attacker. Which models and manufacturers are vulnerable is unknown, but according to the discoverer of the problem involves a "vendor independent vulnerability".

Thursday, 26 March 2015

Site Checks Hijacked DNS Settings Router


The past year has regularly occurred cybercriminals adapted the DNS settings of routers so that they could direct users to malicious Web sites without direct user was clear. The Finnish anti-virus firm F-Secure says it has discovered more than 300,000 residential and business routers in 2014 of which were adapted to the DNS settings.

The Domain Name System (DNS) is similar to the directory and translates among other domain names into IP addresses.By adjusting the DNS of the router can criminals traffic from users via their servers run or redirect user to as phishing sites, even though they have stated in their browser the correct URL.

The anti-virus company therefore has a website launched that can be easily verified that the DNS settings on the router or the system are hijacked. In case the DNS hijacked, users advised to disconnect their router from the Internet and reset, change the password, disable remote management and updating the firmware. In the case of custom DNS settings on the computer that can be restarted in order to empty the DNS cache and is advised to perform a virus scan.

Wednesday, 4 March 2015

IOS App Scans Password And Security Of WiFi Routers


Anti-virus company Avast at the Mobile World Congress in Barcelona announced an app for iPhones and iPads that checks the security of Wi-Fi networks. The free app searches for Wi-Fi networks in the area and then determine whether they are safe. Thus, among other things, to see whether the Wi-Fi router that the wifi connection offers used weak passwords, the WiFi network is encrypted and whether vulnerabilities are present in the router that attackers can exploit.

In the case of unprotected Wi-Fi networks put the SecureMe app a secure VPN connection. Make in case users with an open Wi-Fi network connection, this VPN connection will be switched automatically. The app is free, but whether this also applies to the VPN part is unclear. Avast will first organize a beta test of the app before it appears in the App Store.

Friday, 9 January 2015

Researcher Reveals Leak Asus Routers Vulnerability




A security researcher yesterday evening a leak in different routers manufacturer Asus unveiled the device whereby a local attacker can take over completely and for which no security update is available.The vulnerability is caused by a service called infosvr on UDP port 9999 is listening on the LAN interface.

The service is used by a tool from Asus and should make it easier to set the router to automatically search for routers on the local subnet. Infosvr however shows the MAC address of an application is not good to check. Therefore an attacker to bypass authentication and by sending a packet to UDP port 9999 arbitrary commands to the router.

The vulnerability is present in the Asus RT-AC66U, RT-N66U and other models with the latest firmware. Researcher Joshua Drake discovered the problem advises to remove the ability to remotely execute commands on the router. "Even with strong authentication is sending a password over the LAN is not really desirable." Who still wants to have remote access can do this better over SSH notes the researcher.

Pending to update users have different capabilities. To set David Longenecker for order infosvr service off during startup. via script Eric Sauvageau recommends firewalling port 9999 and Drake gives itself as an option to disable the infosrv service after boot. Something which ironically can be done via the exploit that allows the leak abuse.

Monday, 21 July 2014

First version of Open Wireless Router launched



During the X HOPE conference in New York, the first experimental version of the Open Wireless Router has launched a router update that causes the wifi connection is open for other people put. This open access is controlled by a separate guest area.
This should not only make Internet more accessible, but also improve the privacy and anonymity. An IP address is still almost always traceable to a particular Internet user, if there will be anywhere open Wi-Fi networks that link is not so easy to make more.
User
The software should be easy for users to create finally open while they just own WPA2-protected can hold. Partly for their own Wi-Fi network for others In addition, users will also be able to set how much bandwidth guests get assigned, so that the connection of the owner of the Wi-Fi network does not bother the guests are having.
For now operates the Open Wireless Router Netgear WNDR3800 only on the router. It also includes an experimental version. However, the developers hope that more people will get involved, so the software will soon work on more devices and get more features. Themselves with the project
Thus, it is intended to have an automatic update feature to add that some of the information for the updates will be downloaded, which is a targeted attack on the router "very difficult" to make. Using Tor Owners of a Netgear WNDR3800 who want to go to work with the firmware update can be provided through Openwireless.org download.