Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

RSA Conference: Web Page Can Take Over Your Router
PCWorld.com (excerpt) ^ | April 7, 2008

Posted on 04/07/2008 11:12:15 PM PDT by HAL9000

Excerpt -

Researcher Dan Kaminsky tomorrow will show attendees of the RSA security conference how a Web-based attack could be used to seize control of certain routers.

Kaminsky has spent the past year studying how design flaws in the way that browsers work with the Internet's Domain Name System (DNS) can be abused in order to get attackers behind the firewall.

But at the RSA Conference in San Francisco, he will demonstrate how this attack would work on widely used routers, including those made by Cisco's Linksys division and D-Link.

The technique, called a DNS rebinding attack, would work on virtually any device, including printers, that uses a default password and a Web-based administration interface, said Kaminsky, who is director of penetration testing with IOActive.

Here's how it would work. ...

~ snip ~


(Excerpt) Read more at pcworld.com ...


TOPICS: Computers/Internet
KEYWORDS: dns; passwords; router; routers; security

1 posted on 04/07/2008 11:12:16 PM PDT by HAL9000
[ Post Reply | Private Reply | View Replies]

To: HAL9000

Bookmark.


2 posted on 04/07/2008 11:21:14 PM PDT by Man50D (Fair Tax, you earn it, you keep it!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

Tech ping


3 posted on 04/07/2008 11:32:23 PM PDT by rabscuttle385 (I have great faith in the American people. I have no faith in the American government, however.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: HAL9000

bfl


4 posted on 04/08/2008 1:16:00 AM PDT by Smokin' Joe (How often God must weep at humans' folly.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: HAL9000
.....would work on virtually any device, including printers, that uses a default password.....

Yes, it's always a good idea to replace the default password.

5 posted on 04/08/2008 3:03:03 AM PDT by jimtorr
[ Post Reply | Private Reply | To 1 | View Replies]

To: HAL9000

Found this thread through a key word search and have a question.

I got a wireless router a few days ago and it is pass word protected, I carefully wrote down the pass word and the web site URL to go to to change the pass word. I want to change the pass word now, so I try to go to the web site by typing in the URL, which is:

http://www.routerlogin.com

It does not go to the web site, instead a window opens and asks for my user name and pass word. I type it in and get no access.

Any hints on what to do? It is “NETGEAR WGR614v9” router.


6 posted on 07/09/2008 8:17:29 AM PDT by Graybeard58
[ Post Reply | Private Reply | To 1 | View Replies]

To: Graybeard58

I have a Netgear FVS318.
Default user name - admin
Default password - password

Of course my router is not wireless, and I have changed my password to something more elaborate.

Here’s a link to a support page for your WGR614v9
http://kbserver.netgear.com/products/wgr614v9.asp


7 posted on 07/09/2008 8:36:30 AM PDT by auboy (Men who cannot deceive others are very often successful at deceiving themselves. Samuel Johnson)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Graybeard58

routerlogin.net does seem to belong to NetGear, according to the DNS records, so it seems to be the safe and proper way to do it.

If all else fails, there may be a reset button on your router to restore it to the factory configuration. Then you could log on with the default password and change it to something more secure.


8 posted on 07/09/2008 9:42:44 AM PDT by HAL9000 ("No one made you run for president, girl."- Bill Clinton)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Graybeard58

The router probably has a local http server for when the internet isn’t connected or configured. It should be written on your router. Something like http://192.168.0.1/ is what I would expect to see.

Also, if there is a problem getting access, like you forgot your password, you can reset everything back to factory settings by pressing a small recessed button on the back or bottom of the router with a pin.


9 posted on 07/09/2008 10:05:14 AM PDT by dan1123 (If you want to find a person's true religion, ask them what makes them a "good person".)
[ Post Reply | Private Reply | To 6 | View Replies]

To: HAL9000

Makes me glad I changed the password on our router a while ago. It really was one of the easiest of things to do when trying to protect my fledgling server.


10 posted on 07/09/2008 10:13:04 AM PDT by Toki
[ Post Reply | Private Reply | To 1 | View Replies]

To: dan1123; auboy; HAL9000

I first tried the link in number 7. I used my password and login that I know were correct when I first set it up a few days ago, it told me my password was wrong, so I tried the default password and user name and that was wrong too, then it completely disconnected me from the internet, no matter what I did, it was no go.

So I disconnected the router and reconnected to my modum and it still would not let me on line. After turning off the modem and back on again several tries, I finally got back on line.

So now I will reconnect my router and reset to default as suggested in number 9 and hope that works. Thanks for the help.


11 posted on 07/09/2008 1:45:08 PM PDT by Graybeard58
[ Post Reply | Private Reply | To 9 | View Replies]

To: Graybeard58

I’m sorry if my #7 messed you up. For a long time I used the default password. Back in April I changed it. Good luck!


12 posted on 07/09/2008 2:28:43 PM PDT by auboy (Men who cannot deceive others are very often successful at deceiving themselves. Samuel Johnson)
[ Post Reply | Private Reply | To 11 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson