Broadband Routers and Botnets: Being Proactive

May 11, 2007 4:26 PM PST | Comments: 0
Print
By Gadi Evron

In this post I’d like to discuss the threat widely circulated insecure broadband routers pose today. We have touched on it before.

Today, yet another public report of a vulnerable DSL modem type was posted to bugtraq, this time about a potential WIRELESS flaw with broadband routers being insecure at Deutsche Telekom. I haven’t verified this one myself but it refers to “Deutsche Telekom Speedport w700v broadband router”:

http://seclists.org/bugtraq/2007/May/0178.html

If you all remember, there was another report a few months ago about a UK ISP named BeThere with their wireless router being accessible from the Internet and exploitable, as another example:

http://blogs.securiteam.com/index.php/archives/826

Two issues here:
1. Illegitimate access to broadband routers via wireless communication.
2. Illegitimate access to broadband routers via the WAN.

I’d like to discuss #2.

Some ISPs which provide such devices (as in the example of #2 above) use them as bridges only, preventing several attack vectors (although not all). Many others don’t. Most broadband ISPs have a vulnerable user-base on some level.

Many broadband ISPs around the world distribute such devices to their clients.

Although the general risk is well known, like with many other security issues many of us remained mostly quiet in the hope of avoiding massive exploitation. As usual, we only delayed the inevitable. I fear that the lack of awareness among some ISPs for this “not yet widely exploited threat” has resulted in us not being PROACTIVE and taking action to secure the Internet in this regard. What else is new, we are all busy with yesterday’s fires to worry about tomorrow’s.

Good people will REACT and solve the problem when it pops up in wide-exploitation, but what we may potentially be facing is yet another vector for massive infections and the creation of eventual bot armies on yet another platform.

My opinion is, that with all these public disclosures and a ripe pool of potential victims, us delaying massive exploitation of this threat may not last. I believe there is currently a window of opportunity for service providers to act and secure their user-base without rushing. Nothing in security is ever perfect, but actions such as changing default passwords and preventing connections from the WAN to these devices would be a good step to consider if you haven’t already.

My suggestion would be to take a look at your infrastructure and what your users use, and if you haven’t already, add some security there. You probably have a remote login option for your tech support staff which you may want to explore - and secure. That’s if things were not left at their defaults.

Then, I’d also suggest scanning your network for what types of broadband routers your users make use of, and how many of your clients have port 23 or 80 open. Whether you provide with the devices or not, many will be using different ones set to default which may pose a similar threat. Being aware of the current map of vulnerable devices of this type in your networks can’t hurt.

It is not often that we can predict which of the numerous threats out there that we do not address currently, is going to become exploited next. If you can spare the effort, I’d strongly urge you to explore this front and be proactive on your own networks.

The previous unaddressed threat which most of us chose to ignore was spoofing. We all knew of it for a very long time, but some of us believed it did not pose a threat to the Internet or their networks for no other reason than “it is not currently being exploited” and “there are enough bots out there for spoofing to not be necessary”. I still remember the bitter argument I had with Randy Bush over that one. This is a rare opportunity, let’s not waste it.

We are all busy, but I hope some of you will have the time to look into this.

I am aware of and have assisted several ISPs, who spent some time and effort exploring this threat and in some cases acting on it. If anyone can share their experience on dealing with securing their infrastructure in this regard publicly, it would be much appreciated.

Thanks.

Gadi Evron.

Source Credit: This has been a featured post from Gadi Evron, Security Architect. To learn more, visit this participant's full profile page.

More Under: Access Providers, Broadband, Regional Registries, Security

Stay Updated: To receive weekly email updates from CircleID sign up here or see the list of RSS feeds and mobile version of this site.

Comments

+ Add your comments here.

Login or Sign Up to add your comments here, get access to CircleID Directory, browse the most popular posts, and more.

Start Your AdAds

Sponsored LinksMarketplace

Industry Updates

May 15, 2008 11:28 AM PST

Overstock.com Chooses NeuStar’s UltraDNS for Managed DNS Service

NeuStar, Inc. has announced that Overstock.com, a popular online closeout retailer, has chosen NeuStar's UltraDNS Managed DNS Service to provide Overstock.com with a global DNS infrastructure that significantly enhances end-user experience and operational security -- and protects revenue in the highly competitive online retail market. ›››

By NeuStar | Views: 64

May 14, 2008 11:37 AM PST

Inside Your Domain Portfolio

We've seen a lot of changes in the domain industry over the last year, some positive, some challenging. Whether you're an old pro or just beginning, this spring is a great time to take inventory and make sure your domain business is on the right track for success this year and beyond. ›››

By Sedo | Views: 108

May 14, 2008 11:32 AM PST

Sedo at Domain Roundtable 2008, San Francisco

Domain Roundtable 2008 was an all-around successful event for Sedo. The conference was attended by the domain industry's best and brightest and the Sedo team was right there in the thick of it. ›››

By Sedo | Views: 97

May 14, 2008 11:27 AM PST

Sedo’s New Brokerage Application

Have you ever wanted to buy or sell a domain or a portfolio of domains but just didn't have the time to market it, manage and negotiate the best possible price? You can now request this premium service and work with an experienced Sedo domain broker. ›››

By Sedo | Views: 132

May 13, 2008 3:00 PM PST

ICANN Unanimously Approves RegistryPro Proposal to Expand the .Pro TLD

RegistryPro, the exclusive operator of the .Pro top level domain (TLD), has received approval from ICANN to greatly expand the scope and availability of the .Pro TLD. The newly ratified terms of service increases the number of professionals who are eligible for the TLD, extends the availability globally, and streamlines the registration process. ›››

By Hostway | Views: 243

May 06, 2008 10:16 AM PST

Oversee.net’s DomainSponsor Presents 3rd Annual DOMAINfest Global

The third annual DOMAINfest Global, the premier conference and networking event for the domain name industry, will be held at the Renaissance Hollywood Hotel in Hollywood, California from January 28-30, 2009. Event registration will open later this year. ›››

By DomainSponsor | Views: 462

May 02, 2008 10:21 AM PST

.NL Auction Sneak Peak!

Join Sedo for our much anticipated .NL auction, being held from May 2nd 4pm (EST) until May 9th at approximately 4pm (EST). As the worth of the .NL continues to increase, so does the demand. ›››

By Sedo | Views: 549

Apr 30, 2008 10:01 AM PST

dotMobi Requests Proposals for find.mobi

dotMobi today announced that is accepting proposals for find.mobi, a consumer-facing mobile search tool; find.mobi was created by dotMobi's research and development team to demonstrate an operational mobile search engine that made the most of the mobile web and needs of on-the-go users. ›››

By dotMobi | Views: 753

Apr 28, 2008 2:08 PM PST

dotMobi Offers Prime Selection of Generic Domain Names to Spur Mobile Web Growth

As part of its ongoing series of unique methods of allocating Internet domain names, dotMobi is bringing 16 "premium names" to market at Moniker's T.R.A.F.F.I.C. East Auction on May 23, 2008. ›››

By dotMobi | Views: 981

Apr 28, 2008 11:41 AM PST

Sedo’s Better-than-Ever Brokerage Service!

Sedo's brokerage services are being updated with a new process for submitting both buyer and seller side brokerage requests and enhanced communications tools.  ›››

By Sedo | Views: 823

Start Your AdAds