Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Dangerous 'Misfortune Cookie' flaw discovered in 12 million home routers
PCWorld ^ | December 19, 2014 | By John E. Dunn

Posted on 12/19/2014 9:29:02 PM PST by Swordmaker

Researchers at Check Point have discovered a serious security vulnerability affecting at least 12 million leading-brand home and SME routers that appears to have gone unnoticed for over a decade.

Dubbed the ’Misfortune Cookie’ flaw, the firm plans to give a detailed account of the issue at a forthcoming security conference but in the meantime it’s important to stress that no real-world attacks using it have yet been detected.

That said, an attacker exploiting the flaw would be able to monitor all data travelling through a gateway such as files, emails and logins and have the power to infect connected devices with malware. Man-in-the-middle attacks would also be possible, according to Check Point.

The precise source of the issue is not known - a chipset software development kit (SDK) is suspected - but Check Point warned that up to 200 unpatched models using the RomPager embedded web server software (which uses a remote service called TR-069) prior to version 4.34 were probably vulnerable.

(Excerpt) Read more at pcworld.com ...


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: computer; hacker; hacking; internet; malware; router; tech
Navigation: use the links below to view more comments.
first 1-2021-24 next last

1 posted on 12/19/2014 9:29:02 PM PST by Swordmaker
[ Post Reply | Private Reply | View Replies]

BKMK


2 posted on 12/19/2014 9:34:13 PM PST by Faith65 (Isaiah 40:31)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ~Kim4VRWC's~; 1234; Abundy; Action-America; acoulterfan; AFreeBird; Airwinger; Aliska; altair; ...
Serious Security Flaw, dubbed "Misfortune Cookie" found in 12 million Internet Routers could explode home and business users to data breaches and malware. . . no known exploits . . . Yet. Apple Airport not included on the list of compromised Routers. — PING!


Internet Router Security Ping!

If you want on or off the Mac Ping List, Freepmail me.

3 posted on 12/19/2014 9:35:06 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users contnue...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

BOOKbump


4 posted on 12/19/2014 9:44:24 PM PST by S.O.S121.500 (Had ENOUGH Yet ? ........................ Enforce the Bill of Rights ......... It's the LAW !!!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Great. So now what?


5 posted on 12/19/2014 9:46:28 PM PST by The Ghost of FReepers Past (Woe unto them that call evil good, and good evil; that put darkness for light..... Isaiah 5:20)
[ Post Reply | Private Reply | To 1 | View Replies]

To: The Ghost of FReepers Past

Install DD-WRT on your router if compatible.


6 posted on 12/19/2014 9:52:56 PM PST by steve86 (Prophecies of Maelmhaedhoc OÂ’Morgair (Latin form: Malachy))
[ Post Reply | Private Reply | To 5 | View Replies]

To: Swordmaker

Gads, we’re Neanderthals with technology. Something every single day. We were never prepared to go global and run our economies and personal lives thru all this mish-mash of electronic hooie. For every security geek there are a million ignoramuses to toy with and steal blind, personal as well as businesses and the mega-corporations (see http://marcrogers.org/2014/12/18/why-the-sony-hack-is-unlikely-to-be-the-work-of-north-korea/) And that is nothing considering our bailing-wired and duck-taped electrical grid and infrastructure.

We are so screwed.


7 posted on 12/19/2014 9:56:28 PM PST by bluejean (The lunatics are running the asylum)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

It’s not a bug. It’s another NSA feature. BTTT.


8 posted on 12/19/2014 10:01:45 PM PST by PA Engineer (Liberate America from the Occupation Media.)
[ Post Reply | Private Reply | To 3 | View Replies]

To: steve86

Mine is a cell phone and dial-up modem (3G!) as well as a router. DD-WRT has no support for either of those features. Based on the Ralink RT5350F chipset, it is otherwise compatible. (16MB RAM, 4MB SSD-HDD)

The two packages available are for routers without the integrated cellular modem module. (Instead, you plug in a separate modem through a USB interface.)


9 posted on 12/19/2014 10:17:07 PM PST by __rvx86 (This Tagline is gluten-free.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: The Ghost of FReepers Past
Great. So now what?

Good question. So far, no exploits. But are we all going to have to replace our WIFI and Broadband routers? Or can this be ameliorated by a software or a firmware update?

10 posted on 12/19/2014 10:47:25 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users contnue...)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Swordmaker

It would be nice if they could list model numbers or something


11 posted on 12/19/2014 10:58:57 PM PST by zeugma (The act of observing disturbs the observed.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Bookmark


12 posted on 12/19/2014 11:01:57 PM PST by Pajamajan ( Pray for our nation. Thank the Lord for everything you have. Don't wait. Do it today.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma

“Given the popularity of RomPager and the list of affected brands - D-Link, Edimax, Huawei, TP-Link, ZTE, and ZyXEL sold mainly to home users - such pessimism is realistic.”


13 posted on 12/19/2014 11:40:45 PM PST by SgtHooper (Anyone who remembers the 60's, wasn't there!)
[ Post Reply | Private Reply | To 11 | View Replies]

To: zeugma
It would be nice if they could list model numbers or something

Check.
It.
Out.

The list of affected models (PDF).

14 posted on 12/19/2014 11:49:02 PM PST by Disambiguator
[ Post Reply | Private Reply | To 11 | View Replies]

To: Swordmaker

Although this is a dated link (Feb 2014), it talks about how this could be prevented and what happened in Poland.

http://news.techworld.com/security/3501091/cybercriminals-compromise-home-routers-to-attack-online-banking-users/


15 posted on 12/20/2014 12:12:15 AM PST by SgtHooper (Anyone who remembers the 60's, wasn't there!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Disambiguator

Thanks for the link to the list.

My LinkSys/Cisco is NOT on the list.

Whew!


16 posted on 12/20/2014 2:02:13 AM PST by BwanaNdege
[ Post Reply | Private Reply | To 14 | View Replies]

To: zeugma

Are D-Link routers one of them?


17 posted on 12/20/2014 2:52:36 AM PST by Tucker39 (Welcome to America! Now speak English; and keep to the right....In driving, in Faith, and politics.)
[ Post Reply | Private Reply | To 11 | View Replies]

To: steve86

While DD-WRT is stable and reliable, it is not flexible (built cathedral style as a monolithic ROM package). It needs a lot of memory for the full version, which a lot of the cheaper routers don’t have. It has also had its own security vulnerabilities in the past.

I use OpenWRT, which is modular by design (built a la carte style) with a ton of selectable downloadable kernel modules that run on a much wider hardware base and let you implement hardcore network security like full IPsec VPN, DNSSEC, and app-level stateful firewall packet inspection. These features are normally only found in commercial grade routers at 10X the cost.

OpenWRT also has a much more active support community and has way better support for the newer hardware SoCs. However, it is not for newbies, as the modularity does mean you need to have some familiarity with network protocols and standards to know which modules to choose to install.


18 posted on 12/20/2014 3:54:53 AM PST by Gideon7
[ Post Reply | Private Reply | To 6 | View Replies]

To: Swordmaker

Sounds like it is easily corrected if you run the most recent firmware/software updates. It’s a problem because most people forget to bother with them or patch them. It works so they kindof forget it’s there.


19 posted on 12/20/2014 4:30:55 AM PST by FunkyZero (... I've got a Grand Piano to prop up my mortal remains)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

“You will live in interesti— virus detected! Click here to remove!!!”


20 posted on 12/20/2014 6:27:59 AM PST by SunkenCiv (https://secure.freerepublic.com/donate/ _____________________ Celebrate the Polls, Ignore the Trolls)
[ Post Reply | Private Reply | To 3 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-24 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson