Is your Linksys or Netgear router open to attack?
- 04 August, 2009 04:06
- Comments
If you have a Linksys model WRT160N or Netgear RP614v4 router, it may be time to worry a little. At least according to a report out of Defcon from The Register. The vulnerability is based on CSRF, or cross-site request forgery, an issue with the cPanel web-based control software used to administrate the devices.
Basically, if you're logged into the router as an admin while you visit a seemingly benign site that contains a malicious cross-site request forgery, they can do all kinds of nasty stuff. They can change your admin login, load custom firmware, or change basically any setting they want.
cPanel is a fairly popular web-based hosting application, and of course companies like Linksys and Netgear often use similar code across a product line, so there may be quite a few other products compromised - the two mentioned above are just the two singled out by the security researchers.
Will it get fixed? Probably not. Researcher Mike Bailey is quoted saying, "The response I got from cPanel was we can't fix this because it's a feature. Apparently, they're worried it's going to break integration with third party billing software, so they can't fix this."
So if you use cPanel to administer your web site or router, for starters, only ever log in when you're not visiting any other websites and log out fully before you do anything else. The Register has more...
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- Linksys Hopes New Designs and Lower Prices Boost 802.11n Sales - PC World
- Stories About Netgear Inc. - PC World
- Defense Department Eyes Hacker Con for New Recruits - PC World
- The Register: Sci/Tech News for the World
- Stories About Linksys Group Inc. - PC World
- cPanel, Netgear and Linksys susceptible to nasty attack o The Register
- site
- Agile: Transforming small-team thinking into big business results
- Managing IBM License Complexity
- Backup and Recovery as we Know it is Changing
- Maximise Software Cost Savings by License Reharvesting, Recycling & Applying Product Use Rights
- IDC Whitepaper: Generating Proven Business Value with EMC Next-Generation Backup and Recovery
-
CSIRO claims world's fastest wireless link
-
CeBit 2012: Social media a legal minefield
-
VOIP a wake-up call for global phone competition
-
CeBIT 2012: Will NBN speed up freight delivery times?
-
HTC announces Titan 4G
-
Windows 7 for Dummies® Dvd+book Bundle
-
Computers for Seniors for Dummies, 2nd Edition
-
MYOB Software for Dummies 6E Australian Edition
-
Office 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Dummies®
-
Windows 7 for Seniors for Dummies®
-
Microsoft Office
-
Office 2007 for Dummies
-
Excel 2007 All-In-One Desk Reference for Dummies









Comments
Post new comment