Is your Linksys or Netgear router open to attack?
- 04 August, 2009 04:06
- Comments
If you have a Linksys model WRT160N or Netgear RP614v4 router, it may be time to worry a little. At least according to a report out of Defcon from The Register. The vulnerability is based on CSRF, or cross-site request forgery, an issue with the cPanel web-based control software used to administrate the devices.
Basically, if you're logged into the router as an admin while you visit a seemingly benign site that contains a malicious cross-site request forgery, they can do all kinds of nasty stuff. They can change your admin login, load custom firmware, or change basically any setting they want.
cPanel is a fairly popular web-based hosting application, and of course companies like Linksys and Netgear often use similar code across a product line, so there may be quite a few other products compromised - the two mentioned above are just the two singled out by the security researchers.
Will it get fixed? Probably not. Researcher Mike Bailey is quoted saying, "The response I got from cPanel was we can't fix this because it's a feature. Apparently, they're worried it's going to break integration with third party billing software, so they can't fix this."
So if you use cPanel to administer your web site or router, for starters, only ever log in when you're not visiting any other websites and log out fully before you do anything else. The Register has more...
Nominations for the 2012 ARN IT Industry Awards open on Tuesday, June 12.
- Bookmark this page
- Share this article
- Got more on this story? Email ARN
- Follow ARN on twitter
- Linksys Hopes New Designs and Lower Prices Boost 802.11n Sales - PC World
- Stories About Netgear Inc. - PC World
- Defense Department Eyes Hacker Con for New Recruits - PC World
- The Register: Sci/Tech News for the World
- Stories About Linksys Group Inc. - PC World
- cPanel, Netgear and Linksys susceptible to nasty attack o The Register
- site
- Aberdeen Group: Building Business Resilience Through Active Archive
- Market Potential-Strategy Guide to the Active Archive Market
- In Search of the Long-Term Archiving Solution —Tape Continues to Be a Major Player
- Spectra Logic and Australian National University Success Story - March 2012
- Premier Media Group Fast Study
-
First look: Samsung Galaxy S III
-
Spotify tunes into Australia
-
Telstra and Navman Wireless extend GPS tracking partnership
-
World’s eyes on Aussie NBN: Conroy
-
iPhone 5 rumour rollup for the week ending May 27













Comments
Post new comment