Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Netgear router exploit detected
BBC ^ | 9 October 2015 | Chris Baraniuk, Technology reporter

Posted on 10/09/2015 10:56:42 PM PDT by WhiskeyX

A security researcher in the US has said his Netgear router was hacked after attackers exploited a flaw in the machine.

Joe Giron told the BBC that he discovered altered admin settings on his personal router on 28 September.

The compromised router was hacked to send web browsing data to a malicious internet address.

Netgear says the vulnerability is "serious" but affects fewer than 5,000 devices.

Mr Giron found that the Domain Name System (DNS) settings on his router had been changed to a suspicious IP address.

"Normally I set mine to Google's [IP address] and it wasn't that, it was something else," he said.

"For two or three days all my DNS traffic was being sent over to them."

(Excerpt) Read more at bbc.com ...


TOPICS: Crime/Corruption; News/Current Events
KEYWORDS: computer; exploit; hack; netgear; router; windowspinglist

1 posted on 10/09/2015 10:56:43 PM PDT by WhiskeyX
[ Post Reply | Private Reply | View Replies]

To: WhiskeyX; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; Alas Babylon!; amigatec; ...
Exploit active in the wild for Netgear router ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

2 posted on 10/09/2015 11:15:25 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker; ShadowAce; ThunderSleeps

Tech / apple / android pings


3 posted on 10/09/2015 11:16:35 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 2 | View Replies]

To: WhiskeyX
Additional technical info:

http://www.shellshocklabs.com/2015/09/part-1en-hacking-netgear-jwnr2010v5.html

http://www.csnc.ch/misc/files/advisories/CSNC-2015-007_Netgear_WNR1000v4_AuthBypass.txt

4 posted on 10/09/2015 11:19:50 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 1 | View Replies]

Gotta love the ‘concerned’ reporting of an exploit.


5 posted on 10/10/2015 12:08:00 AM PDT by Gene Eric (Don't be a statist!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: WhiskeyX
He has decided to turn off the router and not use it for the time being.

Okay, guess that's what I'll do, too. Damn!

6 posted on 10/10/2015 12:19:33 AM PDT by LibWhacker
[ Post Reply | Private Reply | To 1 | View Replies]

To: WhiskeyX
From http://www.tomsguide.com/us/netgear-router-vulnerability,news-21699.html:

The vulnerability itself is an authentication bypass that affects the N300_1.1.0.31_1.0.1.img and N300-1.1.0.28_1.0.1.img versions of the firmware. If users have remote administration turned on (it's off by default), anyone with Internet access could theoretically hack into a Netgear router and pick up information from it, as well as install tracking or keylogging software. If remote administration is turned off, an attacker can still take advantage of the flaw, assuming that he or she is physically connected to the router, or on the same Wi-Fi network.

7 posted on 10/10/2015 12:52:44 AM PDT by TChad
[ Post Reply | Private Reply | To 1 | View Replies]

To: WhiskeyX

When I’m on the road I use a Netgear WiFi hotspot. Is that the same thing? It’s a Boost mobile through Sprint.


8 posted on 10/10/2015 5:39:56 AM PDT by SkyDancer ("Nobody Said I Was Perfect But Yet Here I Am")
[ Post Reply | Private Reply | To 1 | View Replies]

To: WhiskeyX

huh... I’m thinking a goverment that interprets laws to accommodate their actions might use this exploit to say...

...put child porn on a government critics computer, then hold this embarrassing breech of the law over the critics head to make them dance to another tune. Like BO’s tune.


9 posted on 10/10/2015 6:30:44 AM PDT by exPBRrat
[ Post Reply | Private Reply | To 1 | View Replies]

To: SkyDancer

“According to Shellshock, this vulnerability affects Netgear JNR1010v2, JNR3000, JWNR2000v5, JWNR2010v5, N300, R3250, WNR2020, WNR614, and WNR618 models.”


10 posted on 10/10/2015 6:44:26 AM PDT by palmer (Net "neutrality" = Obama turning the internet over to foreign enemies)
[ Post Reply | Private Reply | To 8 | View Replies]

To: palmer

Thanks for posting those!


11 posted on 10/10/2015 7:02:38 AM PDT by LostInBayport (When there are more people riding in the cart than there are pulling it, the cart stops moving...)
[ Post Reply | Private Reply | To 10 | View Replies]

To: WhiskeyX

So as I read it, if I don’t have the remote operation turned on, I’m in the clear.


12 posted on 10/10/2015 7:04:21 AM PDT by Poser (Cogito ergo Spam - I think, therefore I ham)
[ Post Reply | Private Reply | To 1 | View Replies]

To: palmer

Now I’m trying to unfreeze my NOOK book reader. Went on-line and all their help hasn’t done it. It shows the screen saver but the battery is out and plugged into its charger. Just can’t turn it off. Weird.


13 posted on 10/10/2015 7:14:46 AM PDT by SkyDancer ("Nobody Said I Was Perfect But Yet Here I Am")
[ Post Reply | Private Reply | To 10 | View Replies]

To: WhiskeyX

Bump to the top


14 posted on 10/10/2015 8:02:25 AM PDT by GOPJ (Democrats want gun legislation? Fine. Pass a Bill outlawing 'gun free' zones.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: SkyDancer

I don’t have a nook, but it’s probably looking for power events in SW so if the SW is hosed it won’t respond to a power switch. My kindle uses the power switch a suggestion, not a command. But it has never frozen.


15 posted on 10/10/2015 3:07:24 PM PDT by palmer (Net "neutrality" = Obama turning the internet over to foreign enemies)
[ Post Reply | Private Reply | To 13 | View Replies]

To: palmer

Thanks for checking. Further research said to remove battery. Did that, can’t now figure out how the screen saver is showing with no power. Was told that removing battery then replacing it would make it reboot. Talked to NOOK tech and advised to take it to B&N for testing and/or get an upgrade. Figgers.


16 posted on 10/10/2015 6:08:25 PM PDT by SkyDancer ("Nobody Said I Was Perfect But Yet Here I Am")
[ Post Reply | Private Reply | To 15 | View Replies]

To: SkyDancer

Screen saver doesn’t need power. It’s one of the main design features of readers, they only use power when changing the screen.


17 posted on 10/10/2015 7:07:24 PM PDT by palmer (Net "neutrality" = Obama turning the internet over to foreign enemies)
[ Post Reply | Private Reply | To 16 | View Replies]

To: palmer

Well that solves that mystery.So I guess the battery is really dead then.


18 posted on 10/11/2015 5:16:43 AM PDT by SkyDancer ("Nobody Said I Was Perfect But Yet Here I Am")
[ Post Reply | Private Reply | To 17 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson