Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Home Routers Under Attack by NSA-Spawned Malware: What to D
tomsguide.com ^ | 11/29/2018 | Marshall Honorof ยท Editor

Posted on 11/30/2018 6:44:46 AM PST by BenLurkin

What you should do is factory-reset your router, disable UPnP, then check for firmware updates, since some companies have patched the vulnerability out. This won’t fix any other compromised systems, but it’s a necessary first step.

After that, you can factory-reset any other internet-connected device that you’re concerned about. You might also want to just buy a new router, as recent models do not appear to be susceptible to this type of attack.

This information comes from a blog post entitled "UPnProxy: EternalSilence" penned by researchers at Cambridge, Massachusetts-based data management firm Akamai.

Cybercriminals have learned how to take advantage of the UPnP protocols on older routers and get past the routers to directly attack Windows PCs on home and small-business networks. Akamai has dubbed this flaw “UPnProxy.” The most recent slew of attacks comes from an exploit that Akamai calls “EternalSilence” in a nod to the NSA-developed “Eternal” family of malicious code injections.

The bottom line is clear enough: Your router is the gateway to every connected device in your home, from your computer, to your phone, to your smart TV, to your smart light bulbs. If your router has been compromised, it’s possible that every other device in your home has followed suit.

Unfortunately, checking to see if you’ve been infected is hard, as antivirus software doesn’t normally scan routers. (A few products have begun to do so.) If malware makes it as far as your computer or game console, though, it’ll be easier to notice.

Dozens of routers could fall prey to this scheme, including models from Asus, D-Link and Netgear. The majority of models listed, though, are business-oriented devices that are popular in Europe and Asia, such as those from Axler, EFM, Netis and Ubiquiti.

(Excerpt) Read more at tomsguide.com ...


TOPICS: Computers/Internet
KEYWORDS: kmg; malware; routers; spyware; tomsguide
Navigation: use the links below to view more comments.
first previous 1-2021-4041-50 next last
To: Pravious; BenLurkin

... simply disable UPnP on your router?


21 posted on 11/30/2018 7:38:51 AM PST by Mr Radical (In times of universal deceit, telling the truth is a revolutionary act)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Stevenc131
My Netgear router is 3 or so years old, so I guess it’s vulnerable. We have to get the enclosed, boxy wi-fi routers with the hidden antennas because the cat chews up the antennas if they are exposed.

Here's the affected Netgear models:

NETGEAR
R2000, WNDR3700, WNDR4300v2, WNR2000v4

22 posted on 11/30/2018 8:01:05 AM PST by Ol' Dan Tucker (For 'tis the sport to have the engineer hoist with his own petard., -- Hamlet, Act 3, Scene 4)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Pravious

Sounds like a press release from Cisco Systems.


23 posted on 11/30/2018 8:05:03 AM PST by Carriage Hill (A society grows great when old men plant trees, in whose shade they know they will never sit.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: BenLurkin

Gibson Research Corporation

I used to use GRC’s ShieldsUp! ports scanner.

GRC has a UPnP Exposure Test link on their home page. Arrow down to the second yellow-background box.

https://www.grc.com/default.htm

==

The scan indicated that my UPnP was not exposed.

I bought my cable/modem router last year and did not make any adjustments. Netgear AC1750, Model C6300.


24 posted on 11/30/2018 8:05:10 AM PST by TomGuy
[ Post Reply | Private Reply | To 1 | View Replies]

To: Pravious
It’s impossible to tell if you’re infected - but the answer is to go out, spend $100 and buy a new router.

Akamai has a white paper that lists the affected manufacturers and models. (See: UPnProxy: Blackhat Proxies via NAT Injections)

25 posted on 11/30/2018 8:05:50 AM PST by Ol' Dan Tucker (For 'tis the sport to have the engineer hoist with his own petard., -- Hamlet, Act 3, Scene 4)
[ Post Reply | Private Reply | To 7 | View Replies]

To: BenLurkin

bbb


26 posted on 11/30/2018 8:09:26 AM PST by thinden
[ Post Reply | Private Reply | To 1 | View Replies]

To: reed13

For use when I get home


27 posted on 11/30/2018 8:31:48 AM PST by reed13k
[ Post Reply | Private Reply | To 15 | View Replies]

To: BenLurkin

Again? Didn’t this happen some months ago?


28 posted on 11/30/2018 8:32:48 AM PST by usconservative (When The Ballot Box No Longer Counts, The Ammunition Box Does. (What's In Your Ammo Box?))
[ Post Reply | Private Reply | To 1 | View Replies]

To: Afterguard
Heh, another Windows problem eh? Don’t see any Apple products listed in the article.

I don't know of any routers running Microsoft Windows ... do you?

29 posted on 11/30/2018 8:33:52 AM PST by usconservative (When The Ballot Box No Longer Counts, The Ammunition Box Does. (What's In Your Ammo Box?))
[ Post Reply | Private Reply | To 10 | View Replies]

To: BenLurkin

The Internet of Things is a stupid idea that’s going to blow up in our face one day.


30 posted on 11/30/2018 8:36:39 AM PST by dfwgator (Endut! Hoch Hech!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

Bkmk


31 posted on 11/30/2018 8:37:59 AM PST by farming pharmer
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

I’m a fan of DD-WRT router firmware. Matter of fact, several years ago I bought a buffalo router because it came stock with the DD-WRT firmware image. Unfortunately, it has been somewhat problematic for me in that there doesn’t seem to be any firmware updates for it pretty much since I set it up.

Is there anyone in freeperland who can recommend a good 5/2.4 router that is compatible with DD-WRT that I can actually keep current on security updates?


32 posted on 11/30/2018 11:18:43 AM PST by zeugma (Power without accountability is fertilizer for tyranny.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: House Atreides; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; AppyPappy; arnoldc1; ...
Router [in]security ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

Thanks to House Atreides for the ping!

33 posted on 11/30/2018 4:01:16 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 19 | View Replies]

To: texas booster

Bkmrk.


34 posted on 11/30/2018 4:04:30 PM PST by lysie
[ Post Reply | Private Reply | To 15 | View Replies]

To: Ol' Dan Tucker

Yay! Amped Wireless doesn’t have a router on the list. They did have some DNS thing I had to turn off a while back, though.


35 posted on 11/30/2018 5:24:58 PM PST by Still Thinking (Freedom is NOT a loophole!)
[ Post Reply | Private Reply | To 25 | View Replies]

To: zeugma
"I’m a fan of DD-WRT router firmware. Matter of fact, several years ago I bought a buffalo router because it came stock with the DD-WRT firmware image. Unfortunately, it has been somewhat problematic for me in that there doesn’t seem to be any firmware updates for it pretty much since I set it up.

Is there anyone in freeperland who can recommend a good 5/2.4 router that is compatible with DD-WRT that I can actually keep current on security updates?"

The creation and maintaining of the 3rd-party firmwares for each individual model of rooter is almost always a one-man operation. The developer/maintainers are a finite resource, and most do this for the love of it, so they have limited resources to apply to the individual rooter model.

Pick a rooter you're interested in that's supported by DD-WRT, Open-WRT, Tomato, etc, then track him down and ask the maintainer himself his intentions. Most maintain a presence in the forum of their particular firmware (my ASUS's Merlin firmware was created by screenname 'john9527' at github, the snbforums, asuswrt and others). That's the closest you can come to knowing the potential development schedule. If you're satisfied with his answers, buy the rooter.

Then pray he doesn't catch ebola, get hit by lightning, marry someone named Kardashian or have his life cut short or otherwise ruined in general.

36 posted on 11/30/2018 5:42:51 PM PST by Paal Gulli
[ Post Reply | Private Reply | To 32 | View Replies]

To: usconservative; dfwgator
USconservative, I do not know of any routers running Windows, but there are plenty of routers that no longer get upgrades from the manufacturer. But there are lots of IoT devices that run one of the Embedded Windows OS, and that is just the start of problems.

Much of the IoT junk coming from Asia may be running a Linux variant but poor programming practices will leave a device wide open.

Just as on a Mac, the underlying OS may be secure in a certain configuration but any dependent programs also need to be secured and regularly updated.

37 posted on 11/30/2018 6:13:35 PM PST by texas booster (Join FreeRepublic's Folding@Home team (Team # 36120) Cure Alzheimer's!)
[ Post Reply | Private Reply | To 29 | View Replies]

To: BenLurkin

i have an Arris- and that wasn’t listed- wonder if they tested all models, or not?


38 posted on 11/30/2018 8:37:52 PM PST by Bob434
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

Through no fault or accomplishment of my own, all mine come up “stealthed”.

No idea how I did that, if *I* even did.

Maybe it’s just my router.


39 posted on 11/30/2018 8:45:07 PM PST by Salamander (My Soul's On Fire...)
[ Post Reply | Private Reply | To 33 | View Replies]

To: dayglored

Thanks


40 posted on 11/30/2018 9:25:55 PM PST by GOPJ (When YOU see drum circles and hear drums at protests - you're looking at communists.)
[ Post Reply | Private Reply | To 33 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-50 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson