SUBSIM Radio Room Forums



SUBSIM: The Web's #1 resource for all submarine & naval simulations since 1997

Go Back   SUBSIM Radio Room Forums > General > General Topics > PC Hardware/Software forum
Forget password? Reset here

Reply
 
Thread Tools Display Modes
Old 01-15-08, 01:59 PM   #1
SUBMAN1
Rear Admiral
 
Join Date: Apr 2005
Posts: 11,866
Downloads: 0
Uploads: 0
Default Router insecurity

Figured I'd mention this - either turn off uPnP on your router, surf with Firefox and upgrade your flash for it manually, or if you still need uPnP, make sure your router is not at the default address of 192.168.0.1. Part of this hack has a bit of a snag in that they must either guess, or brute force your routers IP address. If it is not at the default of 192.168.0.1, then it makes it difficult to implement.

-S

Quote:
Most home routers 'vulnerable to remote take-over'

Universal plug and prey


Security mavens have uncovered a design flaw in most home routers that allows attackers to remotely control the devices by luring an attached computer to a booby-trapped website.


The weakness could allow attackers to redirect victims to fraudulent destinations that masquerade as trusted sites belonging to banks, ecommerce companies or health care organizations. The exploit works even if a user has changed the default password of the router. And it works regardless the operating system or browser the computer connected to the device is running, as long as it has a recent version of Adobe Flash installed.


"This is a huge problem," Adrian Pastor, of the prolific hacking organization GNUCitizen, said in an instant message.


The problem resides in Universal Plug and Play, a feature built in to most routers used for home networks so machines running games, instant messaging programs and other applications will work seamlessly with the devices. By exposing an end user to a malicious Flash file lurking on a website, attackers can use UPnP, as the technology is usually called, to make significant modifications to the router.


The most serious change that's possible is changing the the server PCs connected to the router use to access websites. That might cause a victim trying to access eBay or Bank of America to see spoofed pages that steal their login credentials.
The hack could also allow attackers to open ports on a victim's router. That would be useful in turning a router into what would amount to a zombie machine by forwarding ports to an external server.


The weakness, which works using the navigatetoURL function and URLRequest object specified in Flash, isn't a security flaw within Flash, the researches say. Rather they are design flaws in UPnP, which doesn't use authentication. PCs using virtually any platform and browser will change router settings, as long as they run version 8 or higher of Flash.


Routers made by Linksys, Dlink and SpeedTouch have been confirmed to be vulnerable, and other manufacturers' products are also likely susceptible to attack, the researchers said. Most routers have UPnP turned on by default. The only way to prevent the attack is to turn the feature off, something that is possible with some, but not all, devices.
__________________
SUBMAN1 is offline   Reply With Quote
Old 01-15-08, 03:08 PM   #2
jumpy
Admiral
 
Join Date: May 2003
Location: Midlands, UK
Posts: 2,139
Downloads: 22
Uploads: 0
Default

Great, just what I need.
Though I do use FireFox with NoScript running constantly - even Subsim.com only has scripts 'partially allowed... google-analitics.com and googlesyndication.com and quantserve.com are forbidden in my settings.
Just about everywhere else is blocked too... all of the crap on youtube, plus other flash media and advertising and other embedded links. At least that's how I think it works.

I seem to remember having to check to see if UPnP was enabled on my router fairly recently. Some gaming thing I believe.
__________________

when you’ve been so long in the desert, any water, no matter how brackish, looks like life


jumpy is offline   Reply With Quote
Old 01-15-08, 03:16 PM   #3
Jimbuna
Chief of the Boat
 
Jimbuna's Avatar
 
Join Date: Feb 2006
Location: 250 metres below the surface
Posts: 180,876
Downloads: 63
Uploads: 13


Default

Thanks for the heads up
__________________
Wise men speak because they have something to say; Fools because they have to say something.
Oh my God, not again!!


GWX3.0 Download Page - Donation/instant access to GWX (Help SubSim)
Jimbuna is offline   Reply With Quote
Old 01-15-08, 03:16 PM   #4
Ducimus
Rear Admiral
 
Ducimus's Avatar
 
Join Date: May 2005
Posts: 12,987
Downloads: 67
Uploads: 2


Default

Glad im one of those assinie people who run a firewall behind the router. :rotfl:
Ducimus is offline   Reply With Quote
Old 01-15-08, 06:25 PM   #5
STEED
Lucky Jack
 
Join Date: Jan 2006
Location: Down Town UK
Posts: 27,695
Downloads: 89
Uploads: 48


Default

Quote:
Originally Posted by Ducimus
Glad im one of those assinie people who run a firewall behind the router. :rotfl:
Make that two.
__________________
Dr Who rest in peace 1963-2017.

To borrow Davros saying...I NAME YOU CHIBNALL THE DESTROYER OF DR WHO YOU KILLED IT!
STEED is offline   Reply With Quote
Old 01-15-08, 07:31 PM   #6
jumpy
Admiral
 
Join Date: May 2003
Location: Midlands, UK
Posts: 2,139
Downloads: 22
Uploads: 0
Default

correction... 3
__________________

when you’ve been so long in the desert, any water, no matter how brackish, looks like life


jumpy is offline   Reply With Quote
Old 01-15-08, 08:01 PM   #7
SUBMAN1
Rear Admiral
 
Join Date: Apr 2005
Posts: 11,866
Downloads: 0
Uploads: 0
Default

A firewall won't do you a whole lot of good in this scenario since uPnP is allowed to punch holes and open up ports in it if you allow it to operate properly.

Sorry for the bad news.

-S

PS. This is why professional firewalls like Monowall will not even allow uPnP and they have no plans to support it.
__________________
SUBMAN1 is offline   Reply With Quote
Old 01-15-08, 08:12 PM   #8
Ducimus
Rear Admiral
 
Ducimus's Avatar
 
Join Date: May 2005
Posts: 12,987
Downloads: 67
Uploads: 2


Default

I also do not use IE.

IE, is like fitting a submarine with a screen door.

edit:

BTW, ive always loved this site:
http://www.grc.com/default.htm
Ducimus is offline   Reply With Quote
Old 01-15-08, 08:17 PM   #9
SUBMAN1
Rear Admiral
 
Join Date: Apr 2005
Posts: 11,866
Downloads: 0
Uploads: 0
Default

Quote:
Originally Posted by Ducimus
I also do not use IE.

IE, is like fitting a submarine with a screen door.

edit:

BTW, ive always loved this site:
http://www.grc.com/default.htm
Firefox is also vulnerable if you do not manually upgrade its flash to the latest version.

-S
__________________
SUBMAN1 is offline   Reply With Quote
Old 01-15-08, 09:01 PM   #10
jumpy
Admiral
 
Join Date: May 2003
Location: Midlands, UK
Posts: 2,139
Downloads: 22
Uploads: 0
Default

hmm, how do I do that... automatic update ie. 'you need latest version to view content' message has failed to 'update' in the past... with no link to 'install this file manually'

Do you just dl the installer ?
http://plugindoc.mozdev.org/windows.html#Flash
__________________

when you’ve been so long in the desert, any water, no matter how brackish, looks like life


jumpy is offline   Reply With Quote
Old 01-15-08, 09:09 PM   #11
SUBMAN1
Rear Admiral
 
Join Date: Apr 2005
Posts: 11,866
Downloads: 0
Uploads: 0
Default

Quote:
Originally Posted by jumpy
hmm, how do I do that... automatic update ie. 'you need latest version to view content' message has failed to 'update' in the past... with no link to 'install this file manually'

Do you just dl the installer ?
http://plugindoc.mozdev.org/windows.html#Flash
http://fpdownload.macromedia.com/get...ash_player.exe

The above link is to install the latest.

This link is to show you what version is currently running - http://kb.adobe.com/selfservice/view...nalId=tn_15507

9.0.115.0 combined with Firefox is the immune version.

-S
__________________
SUBMAN1 is offline   Reply With Quote
Old 01-15-08, 09:24 PM   #12
jumpy
Admiral
 
Join Date: May 2003
Location: Midlands, UK
Posts: 2,139
Downloads: 22
Uploads: 0
Default

Thanks mate.

Quote:
your player version: WIN 9,0,28,0
It would appear that I am somewhat behind the times...
__________________

when you’ve been so long in the desert, any water, no matter how brackish, looks like life


jumpy is offline   Reply With Quote
Old 01-15-08, 09:48 PM   #13
SUBMAN1
Rear Admiral
 
Join Date: Apr 2005
Posts: 11,866
Downloads: 0
Uploads: 0
Default

Quote:
Originally Posted by jumpy
Thanks mate.

Quote:
your player version: WIN 9,0,28,0
It would appear that I am somewhat behind the times...
Yep - upgrade already.

-S
__________________
SUBMAN1 is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 07:05 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright © 1995- 2024 Subsim®
"Subsim" is a registered trademark, all rights reserved.