Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Cisco Says 77 Routers Open to 'Drive-By Pharming'
PC World ^ | uesday, February 20, 2007 | Gregg Keizer, Computerworld

Posted on 02/20/2007 6:19:29 PM PST by xcamel

Cisco Systems Inc. is warning users that nearly 80 of its routers are vulnerable to a hack tactic that got play last week.

Dubbed "drive-by pharming" by Symantec Corp. and university researchers who first publicized the danger in a paper, the attack involves luring users to malicious sites where a device's default password is used to redirect them to bogus sites. Once they are at those sites, their identities could be stolen or malware could be force-fed to their computers.

In an advisory posted Thursday, Cisco listed 77 vulnerable routers in the lines sold to small offices, home offices, branch offices and telecommuters. The advisory recommended that users change the default username and password required to access the router's configuration settings, and disable the device's HTTP server feature.

The paper, co-written by a Symantec researcher and two other researchers from Indiana University, urged a similar move by router owners.

"Owners of home routers who set a moderately secure password -- one that is non-default and non-trivial to guess -- are immune to router manipulation via JavaScript," the report read.

The researchers also argued that router makers should stop using blank or easy-to-guess passwords, such as "admin," and switch to the device's serial number. "This value, which is unique to each individual router, would comprise a very secure and unpredictable password," the report stated.


TOPICS: Business/Economy; Crime/Corruption; Extended News
KEYWORDS: cisco; networks; routers; soho
Navigation: use the links below to view more comments.
first 1-2021-4041-52 next last
this isn't good...
1 posted on 02/20/2007 6:19:33 PM PST by xcamel
[ Post Reply | Private Reply | View Replies]

To: xcamel

Considering that Cisco is the Internet … you are right, this is not good.


2 posted on 02/20/2007 6:26:55 PM PST by doc1019 (If Obama is elected as President, we will become an “Obama Nation”.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: xcamel

somebody call al gore, quick!


3 posted on 02/20/2007 6:28:21 PM PST by flashbunny (<----- Click here if you hate RINOs! 2008 GOP RINO cards!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: doc1019
"Owners of home routers who set a moderately secure password -- one that is non-default and non-trivial to guess -- are immune to router manipulation via JavaScript," the report read.

So be a smart shopper, and for about $20 or so you don't need to worry.

4 posted on 02/20/2007 6:32:52 PM PST by Slump Tester ( What if I'm pregnant Teddy? Errr-ahh Calm down Mary Jo, we'll cross that bridge when we come to it)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Slump Tester

?


5 posted on 02/20/2007 6:36:08 PM PST by doc1019 (If Obama is elected as President, we will become an “Obama Nation”.)
[ Post Reply | Private Reply | To 4 | View Replies]

To: xcamel

Hype from a "security" company. This is hardly anything new. Anybody running an HTTP interface on their router with a default password is probably already hacked anyway.


6 posted on 02/20/2007 6:36:10 PM PST by sigSEGV
[ Post Reply | Private Reply | To 1 | View Replies]

To: xcamel
Speaking of Cisco/Linksys routers, what could cause a new router to repeatedly drop the DSL connection about every minute? It connects, authenticates, lets me view a couple of web pages then DSL link fails. I also get a brief popup in Windows "a network cable is unplugged". Then it reconnects. Over and over.

I got new network cables, tried all sorts of config settings, can't get it to stay online. Everything works fine without the router. My ISP and Linksys tech support were not so good. ISP said "not us, call Linksys" and Linksys said "gee, I dunno, maybe it's a bad router."

7 posted on 02/20/2007 6:40:30 PM PST by Sender ("Great powers should never get involved in the politics of small tribes.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Sender

sounds like an overheated chip - ie: bad router.


8 posted on 02/20/2007 6:42:10 PM PST by xcamel (Press to Test, Release to Detonate)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Sender

My brother's on DSL and he's always dropping out. Not every minute but too much for my liking.


9 posted on 02/20/2007 6:43:58 PM PST by Keeper of the Turf (Fore!!!)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Sender
Speaking of Cisco/Linksys routers, what could cause a new router to repeatedly drop the DSL connection about every minute? It connects, authenticates, lets me view a couple of web pages then DSL link fails. I also get a brief popup in Windows "a network cable is unplugged". Then it reconnects. Over and over.

Funny, I have this exact same problem and it started several months ago. It does it every morning for an hour or so and then stops.

I bought a new router but I can't make it work with my DSL connection, all I get is "low connectivity" message from Windows. Same message I get if I plug the DSL modem into the computer. Verizon tech support is useless and says the problem is with my PC. The PC is less than 2 months old.

10 posted on 02/20/2007 6:45:38 PM PST by COEXERJ145 (Bush Derangement Syndrome Has Reached Pandemic Levels on Free Republic.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Sender

I had a client with that problem. LinkSYS finally had a BIOS update that fixed it.


11 posted on 02/20/2007 6:51:23 PM PST by quikdrw (Life is tough....it's even tougher if you are stupid.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: sigSEGV

Can you explain why a router maker would allow someone on the external internet to connect to the http interface? Surely, such a router should only allow a dhcp client to do this, and it should certainly know their IP addresses.

What is this stuff about malicious sites? Does that just give them an IP address to attack by trying to connect back to the router?


12 posted on 02/20/2007 6:52:39 PM PST by proxy_user
[ Post Reply | Private Reply | To 6 | View Replies]

To: Sender

Have your provider send a tech out to run a test on your phone lines back to the DSLAM. Are you using line filters on your phones or are you using a line splitter?

Do you have any satellite receivers plugged into a phone jack?


13 posted on 02/20/2007 7:04:54 PM PST by KoRn
[ Post Reply | Private Reply | To 7 | View Replies]

To: xcamel
...and switch to the device's serial number. "This value, which is unique to each individual router, would comprise a very secure and unpredictable password," the report stated.

If the "serial number" is really what its name implies i.e. a number that increases serially with each product shoved out the door, then it can't be all that secure, as it's a monotonic increasing series.

14 posted on 02/20/2007 7:08:16 PM PST by 2 Kool 2 Be 4-Gotten
[ Post Reply | Private Reply | To 1 | View Replies]

To: xcamel

This sucks.


15 posted on 02/20/2007 7:09:26 PM PST by bmwcyle (It is time to stop the left at the wall.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Sender
...what could cause a new router to repeatedly drop the DSL connection about every minute?

I have exactly the same problem, too, but with broadband! It happened once in November, several times in December, and now happens every few days. It drives me nuts, but I don't know how to troubleshoot it.

16 posted on 02/20/2007 7:12:03 PM PST by BlessedBeGod (Benedict XVI = Terminator IV)
[ Post Reply | Private Reply | To 7 | View Replies]

To: xcamel
this isn't good...

It's neither good nor bad; it's just another example of the stupid getting the abuse they so richly deserve. I've bought plenty of Cisco products, like the new Linksys router right in front of me. Right there in the instructions it tells you to CHANGE THE F-F-F-FLIPPING PASSWORD. (Or words to that effect : ) All of them have that in the instructions. Those who fall victim to this "flaw" do so because they refused to follow instructions. If they wind up seeing 37 cases of vodka purchased from a Moscow liquor store on their Visa bill, they deserve it!

17 posted on 02/20/2007 7:21:51 PM PST by Redcloak (The 2nd Amendment isn't about sporting goods.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: doc1019
Not certain what SlumpTester means by it either.

The most annoying thing about my router -- can't change login name. Have a very random password, though.
18 posted on 02/20/2007 7:32:09 PM PST by dhs12345
[ Post Reply | Private Reply | To 5 | View Replies]

To: Sender
Is there some kind of a ping to stay alive option? I know that my router is constantly hitting my modem with a ping. The Ethernet light on both the modem and router flash at about 4x per second if there is or isn't data.

Have cable.
19 posted on 02/20/2007 7:36:39 PM PST by dhs12345
[ Post Reply | Private Reply | To 7 | View Replies]

To: xcamel
Cisco Says 77 Routers Open to 'Drive-By Pharming'

What does Pancho say?

20 posted on 02/20/2007 7:38:04 PM PST by Mike Bates (Irish Alzheimer's victim: I only remember the grudges.)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-52 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson