General Discussion
  >> General Broadband Chatter


Register (or login) on our website and you will not see this ad.


Pages in this thread: 1 | [2] | (show all)   Print Thread
Standard User Zadeks
(experienced) Sun 11-Oct-15 09:35:58
Print Post

Re: NetGear Router Exploit?


[re: Andrue] [link to this post]
 
http://seclists.org/fulldisclosure/2015/Oct/29

It's an authentication bypass. Vulnerabilities in router web servers are incredibly common. Never enable remote web administration on a router.
Standard User bobble_bob
(fountain of knowledge) Sun 11-Oct-15 10:26:32
Print Post

Re: NetGear Router Exploit?


[re: Zadeks] [link to this post]
 
Says no fix as of yet. Surely a simple fix is to disable remote acess?
Standard User dragon2611
(experienced) Sun 11-Oct-15 14:13:10
Print Post

Re: NetGear Router Exploit?


[re: Zadeks] [link to this post]
 
http://www.ispreview.co.uk/index.php/2015/10/hackers... has a list of some of the affected models.


Register (or login) on our website and you will not see this ad.

Standard User cymru123
(learned) Sun 11-Oct-15 14:59:19
Print Post

Re: NetGear Router Exploit?


[re: Andrue] [link to this post]
 
I've got a VPN server running on our network in order to configure,administrate and access the network remotely so basically you've to create a secure tunnel with a certificate into the network first.

The only open ports are for the web servers and HTTPS NAS access (via proxy server).

I think it's more secure to do it that way rather than opening the Netgear router or any other device on the network to be configured by WAN admin access.
Standard User Oliver341
(eat-sleep-adslguide) Sun 11-Oct-15 16:05:48
Print Post

Re: NetGear Router Exploit?


[re: Zadeks] [link to this post]
 
In reply to a post by Zadeks:
http://seclists.org/fulldisclosure/2015/Oct/29

It's an authentication bypass. Vulnerabilities in router web servers are incredibly common. Never enable remote web administration on a router.

Similar to the D-Link one then, unauthenticated access to WAN-side admin. I use remote admin only when I can firewall all addresses other that the one that needs access.

But still, there's no excuse for such vulnerabilities.

Oliver.
Standard User ian72
(eat-sleep-adslguide) Mon 12-Oct-15 09:09:04
Print Post

Re: NetGear Router Exploit?


[re: Andrue] [link to this post]
 
However, Mr Wu added that attackers would have to get access to the network first and then guess the admin password.


That sentence doesn't seem to be in the article? Was it in there and they've deleted it?

The article suggests the password is not needed as the vulnerability is you can access the router bypassing the security. If the password is needed then it is not a security flaw as such as they were just changing DNS settings which is something you can do if you have the password.
Standard User Andrue
(eat-sleep-adslguide) Mon 12-Oct-15 15:09:24
Print Post

Re: NetGear Router Exploit?


[re: ian72] [link to this post]
 
In reply to a post by ian72:
However, Mr Wu added that attackers would have to get access to the network first and then guess the admin password.


That sentence doesn't seem to be in the article? Was it in there and they've deleted it?
Yes, they've edited it. It now more closely reflects the information posted here.

---
Andrue Cope
Brackley, UK
Standard User Moto
(fountain of knowledge) Tue 13-Oct-15 10:33:21
Print Post

Re: NetGear Router Exploit?


[re: Andrue] [link to this post]
 
after trying to login without the right credentials and failing, the attacker just needs to hit http://<ROUTER-IP>/BRS_netgear_success.html �multiple times�, and the router will roll over and grant access.

laugh A friend surfing in laugh
Pages in this thread: 1 | [2] | (show all)   Print Thread

Jump to