Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Many home routers supplied by ISPs can be compromised en masse, researchers say
CSO ^ | 10 August, 2014 23:33 | Lucian Constantin (IDG News Service)

Posted on 08/11/2014 9:36:34 PM PDT by Utilizer

Specialized servers used by many ISPs to manage routers and other gateway devices provisioned to their customers are accessible from the Internet and can easily be taken over by attackers, researchers warn.

By gaining access to such servers, hackers or intelligence agencies could potentially compromise millions of routers and implicitly the home networks they serve, said Shahar Tal, a security researcher at Check Point Software Technologies. Tal gave a presentation Saturday at the DefCon security conference in Las Vegas.

At the core of the problem is an increasingly used protocol known as TR-069 or CWMP (customer-premises equipment wide area network management protocol) that is leveraged by technical support departments at many ISPs to remotely troubleshoot configuration problems on routers provided to customers.

According to statistics from 2011, there are 147 million TR-069-enabled devices online and an estimated 70 percent of them are residential gateways, Tal said. Based on scans of the Internet Protocol version 4 address space, the 7547 port, which is associated with TR-069, is the second most frequently encountered service port after port 80 (HTTP), he said.

TR-069 devices are set up to connect to Auto Configuration Servers (ACS) operated by ISPs. These servers run specialized ACS software developed by third-party companies that can be used to re-configure customer devices, monitor them for faults and malicious activity, run diagnostics and even silently upgrade their firmware.

(Excerpt) Read more at cso.com.au ...


TOPICS: Computers/Internet; Conspiracy
KEYWORDS: computers; hacking; isp; routers
Navigation: use the links below to view more comments.
first previous 1-2021-4041-45 last
To: tophat9000

They still can’t get past my firewall. They can’t get into my pc.


41 posted on 08/12/2014 6:35:20 PM PDT by driftdiver (I could eat it raw, but why do that when I have a fire.)
[ Post Reply | Private Reply | To 39 | View Replies]

To: ducttape45
I never use ISP provided modem/routers. I purchase my own. I don’t trust Comcast enough to use their equipment in my residence.

My case, I had already had the SBC/Yahoo DSL modem for a couple of years but was not entirely sure I was getting all the throughput I wanted out of it so I was considering a new one.

The Netgear refurb combo unit was on sale quite soon after, and it included the DSL modem, four-port LAN jacks, and added wireless as well which came in handy for when relatives came to visit and had poor reception on their devices. Just enabled the wireless function with some simple encryption and a randomly-generated password for them to use, and everything worked very well indeed.

42 posted on 08/12/2014 6:56:12 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them-)
[ Post Reply | Private Reply | To 35 | View Replies]

To: RitchieAprile
hang a share called “warez” on it..

Or something like "cthultu awaits". *grin*

43 posted on 08/12/2014 6:57:34 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them-)
[ Post Reply | Private Reply | To 36 | View Replies]

To: driftdiver
They still can’t get past my firewall. They can’t get into my pc.

Mine either.

Although I did have to go out and purchase some more tinfoil once I finished protecting it. ;)

44 posted on 08/12/2014 6:59:12 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzlims trying to kill them-)
[ Post Reply | Private Reply | To 41 | View Replies]

To: Utilizer

I also run an ids. There are hundreds of attempts each day. Most are basic scans to see if you left something simple open.


45 posted on 08/12/2014 7:05:05 PM PDT by driftdiver (I could eat it raw, but why do that when I have a fire.)
[ Post Reply | Private Reply | To 44 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-45 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson