Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Many home routers supplied by ISPs can be compromised en masse, researchers say
CSO ^ | 10 August, 2014 23:33 | Lucian Constantin (IDG News Service)

Posted on 08/11/2014 9:36:34 PM PDT by Utilizer

Specialized servers used by many ISPs to manage routers and other gateway devices provisioned to their customers are accessible from the Internet and can easily be taken over by attackers, researchers warn.

By gaining access to such servers, hackers or intelligence agencies could potentially compromise millions of routers and implicitly the home networks they serve, said Shahar Tal, a security researcher at Check Point Software Technologies. Tal gave a presentation Saturday at the DefCon security conference in Las Vegas.

At the core of the problem is an increasingly used protocol known as TR-069 or CWMP (customer-premises equipment wide area network management protocol) that is leveraged by technical support departments at many ISPs to remotely troubleshoot configuration problems on routers provided to customers.

According to statistics from 2011, there are 147 million TR-069-enabled devices online and an estimated 70 percent of them are residential gateways, Tal said. Based on scans of the Internet Protocol version 4 address space, the 7547 port, which is associated with TR-069, is the second most frequently encountered service port after port 80 (HTTP), he said.

TR-069 devices are set up to connect to Auto Configuration Servers (ACS) operated by ISPs. These servers run specialized ACS software developed by third-party companies that can be used to re-configure customer devices, monitor them for faults and malicious activity, run diagnostics and even silently upgrade their firmware.

(Excerpt) Read more at cso.com.au ...


TOPICS: Computers/Internet; Conspiracy
KEYWORDS: computers; hacking; isp; routers
Navigation: use the links below to view more comments.
first previous 1-2021-4041-45 next last
To: Utilizer

Set up an old computer with fild names like “my bank accout password” and hooked to an old router with default password.


21 posted on 08/12/2014 2:31:05 AM PDT by gunsequalfreedom (Conservative is not a label of convenience. It is a guide to your actions.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

BFL And bookmarking


22 posted on 08/12/2014 7:36:27 AM PDT by goodnesswins (R.I.P. Doherty, Smith, Stevens, Woods)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Rodamala
...rename your wireless router NSA Surveillance Network #1492

There's a cheery thought. I'd probably not go with "1492", and the wireless is disabled for now, but I might just do that to discourage anyone attempting to access it from the net just to make them nervous about making the attempt.

23 posted on 08/12/2014 8:31:18 AM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them-)
[ Post Reply | Private Reply | To 17 | View Replies]

To: TheCipher

The information on the article site seems to indicate you need root access to the router before you can access it to disable any ports, which are not accessible to the customer on the ISP-supplied routers.


24 posted on 08/12/2014 8:32:52 AM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them-)
[ Post Reply | Private Reply | To 18 | View Replies]

To: Tainan

Thanks. I was hoping to get some helpful advice from fellow FReepers once I came across the article, and so far some excellent suggestions and advice have already been posted.

Hope to see a few more at least.


25 posted on 08/12/2014 8:35:20 AM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them-)
[ Post Reply | Private Reply | To 19 | View Replies]

To: ShadowAce

ping...


26 posted on 08/12/2014 9:29:42 AM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them-)
[ Post Reply | Private Reply | To 1 | View Replies]

To: rdb3; Calvinist_Dark_Lord; JosephW; Only1choice____Freedom; amigatec; Still Thinking; ...

27 posted on 08/12/2014 9:34:13 AM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: drunknsage

LOL! I do the exact same thing—only I only need one router.


28 posted on 08/12/2014 9:35:52 AM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 5 | View Replies]

To: texas booster

Depending on how their networks are configured, if you block access to the ACS server, you could possibly kill your internet, if your “router”(they aren’t REALLY routers, they’re more like ‘smart transceivers’) has to ‘call home’ and pull down configuration when they are booted up.

I would hope they don’t have their networks setup to run that way though. That would be one hell of a central point of failure if there are ever issues on their end. They probably have a hierarchy of servers; local/regional/central to reduce overhead and build in redundancy.

As an end user, I wouldn’t be terribly concerned about this. Well, maybe a little. It might be good to be aware of it.


29 posted on 08/12/2014 9:56:00 AM PDT by KoRn (Department of Homeland Security, Certified - "Right Wing Extremist")
[ Post Reply | Private Reply | To 2 | View Replies]

To: drunknsage

Always bridge your network from the ISP. It doesn’t insulate you from an attack, but it insulates the damage they could do. The ISPs are going to mandate that you use CWMP if you want support. I personally bought a Motorola Surfboard and told my ISP that I just need the bridge information. They don’t support anything unless the connection drops. This isn’t ideal for most home users.

My suggestion to most FReepers is to NOT use your ISP’s router for direct connections to computers or the ISP wireless connection. You might be sold a bill of goods on what they support if you use their native wireless, but it’s not worth the security headache. Buy a cheap Linksys or Netgear wireless router/switch and learn how to configure it yourself. Don’t let ANY company say they’re securing you. They’re not.


30 posted on 08/12/2014 10:47:59 AM PDT by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: rarestia

Thanks for the advice. I feel better about this Netgear router already, although at about ten years old I am trying harder and harder to find a suitable replacement before its EOL becomes clear.


31 posted on 08/12/2014 11:02:39 AM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them-)
[ Post Reply | Private Reply | To 30 | View Replies]

To: Utilizer

Linksys E3000 with DDWRT firmware is rock solid. It’s a pricey piece of equipment (>$100), but it’s worth the money. DDWRT allows you to lock it down even more without compromising speed.


32 posted on 08/12/2014 11:16:22 AM PDT by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 31 | View Replies]

To: Utilizer

It is a bookmark, just shorter to spell.


33 posted on 08/12/2014 11:34:57 AM PDT by ansel12 (LEGAL immigrants, 30 million 1980-2012, continues to remake the nation's electorate for democrats)
[ Post Reply | Private Reply | To 13 | View Replies]

To: ansel12

*laugh*

Like “bkmk” is too long? *grin*


34 posted on 08/12/2014 11:49:12 AM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them-)
[ Post Reply | Private Reply | To 33 | View Replies]

To: Utilizer

I never use ISP provided modem/routers. I purchase my own. I don’t trust Comcast enough to use their equipment in my residence.


35 posted on 08/12/2014 5:00:40 PM PDT by ducttape45
[ Post Reply | Private Reply | To 1 | View Replies]

To: gunsequalfreedom

hang a share called “warez” on it..


36 posted on 08/12/2014 5:50:57 PM PDT by RitchieAprile
[ Post Reply | Private Reply | To 21 | View Replies]

To: driftdiver
Im not sure how you would not need their device if there fiber?
home routers will have an Ethernet interface for the WAN (there are some that have ADSL or Cable interface but rare)

so Verizon would have to have something that takes fiber on one side and gives you an Ethernet drop on the other side.

The point of ip is to give a common global networking addressing scheme (layer 3) to dissimilar data link physical layer devices (layer 2/1)

in other words your home router doesn't know how to talk to a fiber data link ...Verizon provide you a box that has a fiber interface on one slide in an Ethernet interface on the other and each of those interfaces gets an IP address ...or maybe just the ethernet interface.. but the verzion box still does the translation between fiber and Ethernet protocol at the datalink Layer 2

37 posted on 08/12/2014 5:56:32 PM PDT by tophat9000 (An Eye for an Eye, a Word for a Word...nothing more)
[ Post Reply | Private Reply | To 16 | View Replies]

To: tophat9000

There’s modem on the outside that coverts fiber to ethernet. This then terminates on a small wifi router inside. So instead of taking their cheap little router that has the backdoor built in you use your own.

They don’t have any access past the new device.


38 posted on 08/12/2014 5:58:58 PM PDT by driftdiver (I could eat it raw, but why do that when I have a fire.)
[ Post Reply | Private Reply | To 37 | View Replies]

To: driftdiver
Ok.. but its the modem that has the exploit.. the isp have to be able to manage the modem and provision it ..that what the protocol and open port is for .

So the isp modem has an open port at listening for the isp management server. At least if what i read is right on this protocol and how in being hacked.

I think what confuses people is the article using the term router.. people think of their home router as the only router.. but the isp modem is also a router if forwards L3 traffic from one L3 interface to another L3 interface.

L3= network = IP Address in this case

39 posted on 08/12/2014 6:29:16 PM PDT by tophat9000 (An Eye for an Eye, a Word for a Word...nothing more)
[ Post Reply | Private Reply | To 38 | View Replies]

To: Utilizer

BFL


40 posted on 08/12/2014 6:34:12 PM PDT by Lurkina.n.Learnin (It's a shame nobama truly doesn't care about any of this. Our country, our future, he doesn't care)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-45 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson