Slashdot Mirror


Millions of Home Routers Are Hackable

Julie188 writes "Craig Heffner, a researcher with Maryland-based security consultancy Seismic, plans to release a software tool at the Black Hat conference later this month that he says could be used on about half the existing models of home routers, including most Linksys, Dell, and Verizon FiOS or DSL versions. The tool apparently exploits the routers through DNS rebinding. While this technique has been discussed for 15 years or more, Heffner says, 'It just hasn't been put together like this before.'" Notebooks.com has a list of routers tested and some advice on securing vulnerable routers.

1 of 179 comments (clear)

  1. 30 router models info by llZENll · · Score: 0, Redundant

    The important info

    Heffner tested his attack against 30 router models and found that about half were vulnerable. Here's his chart of which are and aren't subject to attack. ("Successful" in the far right column means that the router was successfully hacked.)

    Vendor Model H/W Version F/W Version Successful
    ActionTec MI424-WR Rev. C 4.0.16.1.56.0.10.11.6 YES
    ActionTec MI424-WR Rev. D 4.0.16.1.56.0.10.11.6 YES
    ActionTec GT704-WG N/A 3.20.3.3.5.0.9.2.9 YES
    ActionTec GT701-WG E 3.60.2.0.6.3 YES
    Asus WL-520gU N/A N/A YES
    Belkin F5D7230-4 2000 4.05.03 YES
    Belkin F5D7230-4 6000 N/A NO
    Belkin F5D7234-4 N/A 5.00.12 NO
    Belkin F5D8233-4v3 3000 3.01.10 NO
    Belkin F5D6231-4 1 2.00.002 NO
    D-Link DI-524 C1 3.23 NO
    D-Link DI-624 N/A 2.50DDM NO
    D-Link DIR-628 A2 1.22NA NO
    D-Link DIR-320 A1 1 NO
    D-Link DIR-655 A1 1.30EA NO
    DD-WRT N/A N/A v24 YES
    Dell TrueMobile 2300 N/A 5.1.1.6 YES
    Linksys BEFW11S4 1 1.37.2 YES
    Linksys BEFSR41 4.3 2.00.02 YES
    Linksys WRT54G3G-ST N/A N/A YES
    Linksys WRT54G2 N/A N/A NO
    Linksys WRT160N 1.1 1.02.2 YES
    Linksys WRT54G 3 3.03.9 YES
    Linksys WRT54G 5 1.00.4 NO
    Linksys WRT54GL N/A N/A YES
    Netgear WGR614 9 N/A NO
    Netgear WNR834B 2 2.1.13_2.1.13NA NO
    OpenWRT N/A N/A Kamikaze r16206 YES
    PFSense N/A N/A 1.2.3-RC3 YES
    Thomson ST585 6sl 6.2.2.29.2 YES

    from http://blogs.forbes.com/firewall/2010/07/13/millions-of-home-routers-vulnerable-to-web-hack/