Computer ForumsComputers  

Go Back   Computer Forums > The World Wide Web > Virus - Spyware Protection / Detection

Reply
 
LinkBack Thread Tools Display Modes
Old 10-09-2007, 12:12 PM   #1 (permalink)
Osiris
Security/Hacking Mod
 
Osiris's Avatar
 
Join Date: Jan 2005
Location: USA
Posts: 23,579
Default BT home router wide open to hijackers

If you rely on BT for high-speed internet or VoIP, there's a good chance a pair of UK-based researchers know how to enable a backdoor in your router that leaves you wide open to eavesdropping, caller spoofing and other nasty attacks.
The vulnerability resides in the BT Home Hub, one of the UK's most popular home routers, according to Adrian Pastor and Petko D. Petkov. A constellation of bugs in the router, which is made by Thomson/Alcatel, make it possible to bypass the device's password authentication system and gain complete administrative control.

All an attacker needs to do to exploit the weaknesses is lure the victim to a maliciously crafted website, according to this post on the GNUCitizen blog. The exploit doesn't require knowledge of the administrator password.
"The BT Home Hub is vulnerable to an authentication bypass that allows us to make any administrative requests to the router from a malicious website WITHOUT needing username and password," Pastor wrote in an email to The Reg. He and Petkov have confirmed the vulnerability in the BT Home Hub running the most recent firmware. They believe the exploit will work on all Thomson/Alcatel Speedtouch 7G routers.
US-based BT representatives didn't immediately respond to requests for comment.
The scope of the vulnerability and the ease in carrying it out means that a remote attacker can quietly gain full administrator control over a device simply by social engineering a user into visiting a website. The exploit makes it possible to steal a user's WPA key, listen in on VoIP calls, steal VoIP credentials or change DNS settings so users are silently redirected to fraudulent websites.
Thomson/Alcatel's Speedtouch 780, a similar router used by Bethere, shares some of the same cross-site-scripting and cross-site-request forgery bugs found on the BT Home Hub. But because it's not vulnerable to authentication bypass, attackers have to know the router's password in order to gain administrative control, Pastor said.


BT home router wide open to hijackers | The Register
__________________
Osiris is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Along came a hub, a switch, and a router....Aren't they the same? ReikokuKo Articles 17 07-01-2008 05:25 AM
A switch, and a router....Aren't they the same? ReikokuKo Networking Tips, Tricks & FAQ 9 03-24-2008 09:44 PM
Bonds slugs No. 756 to pass Aaron as home run king Osiris Off Topic Discussion 20 08-14-2007 07:56 PM
Don't forget Newegg Open Box's people :P Sora Building, Buying, or Upgrading High Performance PC Systems 16 05-21-2007 03:21 PM
2 Router setup...possible? BoysNightOut Computer Networking & Internet Access 13 03-31-2007 10:37 PM


All times are GMT. The time now is 12:50 AM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 RC8