Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | The next target for virus/trojan writers (+ DD-WRT Vulnerability)


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

The next target for virus/trojan writers (+ DD-WRT Vulnerability)
Reply
 
Thread Tools
Old 17-07-2009, 20:13   #1
altis
The Terminator
 
altis's Avatar
 
Join Date: Jun 2003
Location: Warrington ntl:81304 Altitude: 12m (and falling)
Posts: 4,495
altis has a nice shiny staraltis has a nice shiny star
altis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny star
The next target for virus/trojan writers (+ DD-WRT Vulnerability)

Sorry to spread more doom and gloom but I've a feeling that this could turn out to be a big problem.

http://www.theregister.co.uk/2009/07...terface_peril/

Many appliances (routers, webcams, NAS etc) that we plug into our networks are running long-out-of-date Linux kernels with application software that's out of the door as fast as possible with little regard to security. Many are rarely updated - if at all. Little wonder, then, that many are wide open to attacks from malware.
altis is offline   Reply With Quote
Advertisement
Old 17-07-2009, 20:21   #2
Druchii
Keep smiling! ♥
 
Druchii's Avatar
 
Join Date: Mar 2006
Location: Doncaster, UK.
Age: 24
Services: VM: 20 (18)Mb
Posts: 7,574
Druchii has a nice shiny star
Druchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny star
re: The next target for virus/trojan writers (DD-WRT Vulnerability)

Yep, i was thinking about this years ago, when i managed to somehow get into my router via web-interface, without supplying the set password.
Only happened once... Made me think though.

Personally, i think they big 3rd party firmware creators could do well to protect against as much of this as possible when the Manufacturers aren't.
I'm looking at things like DD-WRT, Tomato and Open-WRT etc... It could pay to be the one to develop and protect against all this... This is just routers though.
Druchii is offline   Reply With Quote
Old 21-07-2009, 20:27   #3
altis
The Terminator
 
altis's Avatar
 
Join Date: Jun 2003
Location: Warrington ntl:81304 Altitude: 12m (and falling)
Posts: 4,495
altis has a nice shiny staraltis has a nice shiny star
altis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny star
re: The next target for virus/trojan writers (DD-WRT Vulnerability)

DD-WRT users beware:

http://www.theregister.co.uk/2009/07...t_router_vuln/
altis is offline   Reply With Quote
Old 22-07-2009, 07:25   #4
Dai
Old dog, New tricks
 
Dai's Avatar
 
Join Date: Dec 2006
Location: Lincoln UK
Age: 64
Services: 50Mb, TV & Phone
Posts: 3,642
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Send a message via MSN to Dai
DDWRT root vulnerability

http://www.theregister.co.uk/2009/07...t_router_vuln/

A hacker has discovered a critical vulnerability in open-source firmware available for wireless routers made by Linksys and other manufacturers that allows attackers to remotely penetrate the device and take full control of it.

__________________
-= David =-

Under socialism ideology always trumps rationality.
Dai is offline   Reply With Quote
Old 22-07-2009, 07:29   #5
Graham M
 
Graham M's Avatar
 
Join Date: Jul 2003
Location: Poole, Dorset
Age: 28
Services: FreeSat+ Tivo V-Box VM 60MBit
Posts: 13,251
Graham M has a pair of shiny starsGraham M has a pair of shiny stars
Graham M has a pair of shiny starsGraham M has a pair of shiny starsGraham M has a pair of shiny starsGraham M has a pair of shiny starsGraham M has a pair of shiny starsGraham M has a pair of shiny stars
Send a message via MSN to Graham M Send a message via Yahoo to Graham M
re: The next target for virus/trojan writers (DD-WRT Vulnerability)

I have merged these 2 threads as they are on the same subject, 2 threads away from each other, in the same forum
__________________
Desktop: Intel i7 SandyBridge 2600k 3.4GHz @ 4.7GHz - 8GB DDR3 - ATI Radeon HD 5770 1GB - OCZ Agility 3 60GB SSD
Graham M is offline   Reply With Quote
Old 22-07-2009, 08:47   #6
Dai
Old dog, New tricks
 
Dai's Avatar
 
Join Date: Dec 2006
Location: Lincoln UK
Age: 64
Services: 50Mb, TV & Phone
Posts: 3,642
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Send a message via MSN to Dai
Re: The next target for virus/trojan writers (+ DD-WRT Vulnerability)

Oops. Time for specsavers..
__________________
-= David =-

Under socialism ideology always trumps rationality.
Dai is offline   Reply With Quote
Old 22-07-2009, 09:16   #7
altis
The Terminator
 
altis's Avatar
 
Join Date: Jun 2003
Location: Warrington ntl:81304 Altitude: 12m (and falling)
Posts: 4,495
altis has a nice shiny staraltis has a nice shiny star
altis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny staraltis has a nice shiny star
Re: The next target for virus/trojan writers (+ DD-WRT Vulnerability)

To be fair, the original title was far more generic and didn't specifically mention DD-WRT so was easy to miss.

A quick fix is available here:
http://www.dd-wrt.com/dd-wrtv2/down....-21-09-r12533/

No doubt there'll be more appliances under attack soon.
altis is offline   Reply With Quote
Old 22-07-2009, 15:20   #8
Druchii
Keep smiling! ♥
 
Druchii's Avatar
 
Join Date: Mar 2006
Location: Doncaster, UK.
Age: 24
Services: VM: 20 (18)Mb
Posts: 7,574
Druchii has a nice shiny star
Druchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny starDruchii has a nice shiny star
Re: The next target for virus/trojan writers (+ DD-WRT Vulnerability)

My WRT54GL V1.1 running V24 SP1 seems not to be vulnerable. I've been hitting it with this attack to reboot and it hasn't done so once.

And i can't find WRT54GL in the update list.
Druchii is offline   Reply With Quote
Old 28-07-2009, 08:21   #9
Raistlin
Been around a while ...
 
Raistlin's Avatar
 
Join Date: Feb 2004
Location: There's no place like 127.0.0.1
Services: Depends on the person and the price they're offering
Posts: 12,365
Raistlin has disabled reputation
Re: The next target for virus/trojan writers (+ DD-WRT Vulnerability)

Just been looking at the exploit code for this and thought it was worth pointing out that (in the default configuration) routers running vulnerable firmware are only available from inside the network.

That is to say that it is only vulnerable from the private interface, and not the public on. The exploit needs to be directed at the router's web management interface, typically this wouldn't be exposed to the public.

That doesn't mean that it isn't an issue though. An attacker could set up some sort of cross-site request forgery attack (a maliciously crafted media file for example) that triggers in the victim's browser, runs the exploit against the router's management interface, and then returns the root shell to the attacker.

Found an interesting little video (you'll need to blow it up to full screen) that shows the proof of concept attack.

http://www.youtube.com/watch?v=UhDcXCVFrvM

By the way, all of this information is public domain - I present it here for the interest of those people that I know are interested in these things. Hopefully if more people are educated to how these things work we might see fewer people affected in the future.
__________________
Citroen Xsara Owners Club
Raistlin is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Google Search




All times are GMT. The time now is 14:36.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.
Copyright © 2003 - 2012, Cable Forum.
(server5.cableforum.co.uk)

SEO by vBSEO 3.3.2