Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
Computer Forums > The World Wide Web > Virus - Spyware Protection / Detection » BT home router wide open to hijackers
Closed Thread
Old 10-09-2007, 08:12 AM   #1 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,064

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default BT home router wide open to hijackers

If you rely on BT for high-speed internet or VoIP, there's a good chance a pair of UK-based researchers know how to enable a backdoor in your router that leaves you wide open to eavesdropping, caller spoofing and other nasty attacks.
The vulnerability resides in the BT Home Hub, one of the UK's most popular home routers, according to Adrian Pastor and Petko D. Petkov. A constellation of bugs in the router, which is made by Thomson/Alcatel, make it possible to bypass the device's password authentication system and gain complete administrative control.

All an attacker needs to do to exploit the weaknesses is lure the victim to a maliciously crafted website, according to this post on the GNUCitizen blog. The exploit doesn't require knowledge of the administrator password.
"The BT Home Hub is vulnerable to an authentication bypass that allows us to make any administrative requests to the router from a malicious website WITHOUT needing username and password," Pastor wrote in an email to The Reg. He and Petkov have confirmed the vulnerability in the BT Home Hub running the most recent firmware. They believe the exploit will work on all Thomson/Alcatel Speedtouch 7G routers.
US-based BT representatives didn't immediately respond to requests for comment.
The scope of the vulnerability and the ease in carrying it out means that a remote attacker can quietly gain full administrator control over a device simply by social engineering a user into visiting a website. The exploit makes it possible to steal a user's WPA key, listen in on VoIP calls, steal VoIP credentials or change DNS settings so users are silently redirected to fraudulent websites.
Thomson/Alcatel's Speedtouch 780, a similar router used by Bethere, shares some of the same cross-site-scripting and cross-site-request forgery bugs found on the BT Home Hub. But because it's not vulnerable to authentication bypass, attackers have to know the router's password in order to gain administrative control, Pastor said.


BT home router wide open to hijackers | The Register
__________________
Osiris is offline  
 
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
A switch, and a router....Aren't they the same? ReikokuKo Networking Tips, Tricks & FAQ 10 04-10-2009 06:24 PM
Along came a hub, a switch, and a router....Aren't they the same? ReikokuKo Articles 16 06-23-2008 08:24 AM
Bonds slugs No. 756 to pass Aaron as home run king Osiris Off Topic Discussion 20 08-14-2007 03:56 PM
Don't forget Newegg Open Box's people :P Sora Building, Buying, or Upgrading High Performance PC Systems 16 05-21-2007 11:21 AM
2 Router setup...possible? BoysNightOut Computer Networking & Internet Access 13 03-31-2007 06:37 PM