Jump to content

Backdoor found in Linksys and Netgear Routers

99vw

 

A hacker has uncovered a backdoor to combination wireless router/DSL modems that could allow an attacker to reset a machine's configuration and gain access to the administrative control panel. The attack, confirmed to work on several Linksys and Netgear devices, exploits an open port accessible over the wireless local network.

 

The backdoor requires that the attacker be on the local network, so this isn’t something that could be used to remotely attack DSL users. However, it could be used to commandeer a wireless access point and allow an attacker to get unfettered access to local network resources.

 

Fortunately, it looks to only be exploitable if your already on the LAN. However, this doesn't necessarily mean it's safe.

 

http://www.arstechnica.com/security/2014/01/backdoor-in-wireless-dsl-routers-lets-attacker-reset-router-get-admin/

Link to comment
Share on other sites

Link to post
Share on other sites

Well i guess my Asus RT N66U is not compromised... it probably helps that it uses a skinned dd-wrt.

Link to comment
Share on other sites

Link to post
Share on other sites

DD-WRT is awesome, can turn a rubbish router into an awesome one that can cost x3 as much.

Intel I9-9900k (5Ghz) Asus ROG Maximus XI Formula | Corsair Vengeance 16GB DDR4-4133mhz | ASUS ROG Strix 2080Ti | EVGA Supernova G2 1050w 80+Gold | Samsung 950 Pro M.2 (512GB) + (1TB) | Full EK custom water loop |IN-WIN S-Frame (No. 263/500)

Link to comment
Share on other sites

Link to post
Share on other sites

DD-WRT is awesome, can turn a rubbish router into an awesome one that can cost x3 as much.

But the DD-WRT router is one of the easiest routers to break into.

My Sig Rig: "X79 (3970X) -Midas"http://pcpartpicker.com/p/wsjGt6"  "Midas" Build Log - https://linustechtips.com/main/topic/59768-build-log-in-progress-code-name-midas/


"The Riddler" Custom Watercooled H440 Build Log ( in collaboration with my wife @ _TechPuppet_ ) - http://linustechtips.com/main/topic/149652-green-h440-special-edition-the-riddler-almost-there/


*Riptide Customs* " We sleeve PSU cables "

Link to comment
Share on other sites

Link to post
Share on other sites

Oooo show me how!

|Casual Rig| CPU: i5-6600k |MoBo: ROG Gene  |GPU: Asus 670 Direct CU2 |RAM: RipJaws 2400MHz 2x8GB DDR4 |Heatsink: H100i |Boot Drive: Samsung Evo SSD 240GB|Chassis:BitFenix Prodigy |Peripherals| Keyboard:DasKeyboard, Cherry MX Blue Switches,|Mouse: Corsair M40

|Server Specs| CPU: i7-3770k [OC'd @ 4.1GHz] |MoBo: Sabertooth Z77 |RAM: Corsair Vengeance 1600MHz 2x8GB |Boot Drive: Samsung 840 SSD 128GB|Storage Drive: 4 WD 3TB Red Drives Raid 5 |Chassis:Corsair 600t 

Link to comment
Share on other sites

Link to post
Share on other sites

Oooo show me how!

 

"A picture is starting to form here... I wonder if it's accurate? Some pieces don't quite seem to fit. Or maybe I just don't like the way it looks."

Link to comment
Share on other sites

Link to post
Share on other sites

Wireless local network... Does not mean just LAN.

 

Could you explain more? I was just going off what the article said.

 

 

The backdoor requires that the attacker be on the local network, so this isn’t something that could be used to remotely attack DSL users. However, it could be used to commandeer a wireless access point and allow an attacker to get unfettered access to local network resources.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×