Hacking an ADSL router is this easy

What I like about the article is the fact that there's a video demonstrating what they are trying to say, giving it a more "practical" approach to sharing information, a step in the right direction for things that most people find very hard to grasp at the best of times.

However, as hacks go this is a pretty lame one. For this hack to work, quite a lot of things need to come together for absolutely zero gain. If all I wanted to do was jump onto your internet, I would certainly be a lot more focused on unsecured networks or networks with weak security. I can hack those and jump onto your WIFI without needing to be able to take a sip from your coffee, which is much less risk. Once on your WIFI, I don't care about your router if I'm after your data. If I'm after your data, well, why bother with your ADSL router if I'm already in your house!?

If we're talking about simply the act of hacking your ADSL router, well sure. I could also upload a video demonstrating a denial of service on your kettle, which involves me pulling the plug out of the socket in the wall...
 
Hi, I'm the guy in the video (@singe) and thought I'd answer some of the claims made in the comments and forum. It's a repost from the comments though.

* The attacker wouldn't need access to the router for the initial attack. A Cross Site Request Forgery is proxied through the victim's browser, just the victim needs access and to have been logged on. The attack would be distributed through something like an ad network.

* The preconditions required are: the attack must cater for the brand/version of the router (multiple CSRF's can be attempted however), the victim must have auth'ed to the router previously and not logged out (as most people don't clear cookies this doesn't need to have been recently) and the attacker must know the network location of the router on the victim's network. This is usually 192.168.1.1

* These attacks are rarely targeted, they're done en masse for things like pharming campaigns. i.e. They're not looking for your MP3 collection. Here's an example from Brazil in Feb https://threatpost.com/pharming-attack-targets-home-router-dns-settings/111326

* The attack wasn't old 4 years ago, it was old 9 years ago when Symantec first wrote the paper http://www.symantec.com/avcenter/reference/Driveby_Pharming.pdf

* The attack was chosen over many other for a variety of reasons. MyBB wanted it to be simple (so a 9yr old could do it) and something an average user could actually be taken with. The numerous point specific router exploits wouldn't have been general enough and something like a WPS brute requires physical proximity instead of "over the Internet".

* Most consumer routers *can* prevent access from wifi but don't by default. During the filming of this we did a quick check and were able to find over 4k DLink & Linksys routers available to the *public* Internet in ZA DSL ranges alone.
 
Hi, I'm the guy in the video (@singe) and thought I'd answer some of the claims made in the comments and forum. It's a repost from the comments though.

* The attacker wouldn't need access to the router for the initial attack. A Cross Site Request Forgery is proxied through the victim's browser, just the victim needs access and to have been logged on. The attack would be distributed through something like an ad network.

* The preconditions required are: the attack must cater for the brand/version of the router (multiple CSRF's can be attempted however), the victim must have auth'ed to the router previously and not logged out (as most people don't clear cookies this doesn't need to have been recently) and the attacker must know the network location of the router on the victim's network. This is usually 192.168.1.1

* These attacks are rarely targeted, they're done en masse for things like pharming campaigns. i.e. They're not looking for your MP3 collection. Here's an example from Brazil in Feb https://threatpost.com/pharming-attack-targets-home-router-dns-settings/111326

* The attack wasn't old 4 years ago, it was old 9 years ago when Symantec first wrote the paper http://www.symantec.com/avcenter/reference/Driveby_Pharming.pdf

* The attack was chosen over many other for a variety of reasons. MyBB wanted it to be simple (so a 9yr old could do it) and something an average user could actually be taken with. The numerous point specific router exploits wouldn't have been general enough and something like a WPS brute requires physical proximity instead of "over the Internet".

* Most consumer routers *can* prevent access from wifi but don't by default. During the filming of this we did a quick check and were able to find over 4k DLink & Linksys routers available to the *public* Internet in ZA DSL ranges alone.

Welcome to the forum mate. Don't despair, most comments are well intended even though it might not sound like it :D
If I could ask anything, keep posting on the forums and be active here with us...
 
Although an issue there is a way around it. Keep everything in http or get them to install a fake root CA

Have you ever tried getting a user to install a real CA? Bit of a mission.
But ja, once you have a CA in place bobs your uncle, piss easy to get what you want.
 
I sit down at my favourite coffeshop a while ago. Messa bout with my phone while waiting for my Americano.
Connect to their hotspot, and on a whim type 192.168.01 in the browser.
Netgear login screen appears.
"They can't be that dumb' I think - while typing in Admin and Password.
Seems it was set up for them by the Afrihost tech. And he left everything default.
Yes - some places really need to work on their security.
On the plus side - I don't think they had any risk of hacking. All the other users are on Macbooks.
 
I have enjoyed much free internet at many coffee shops, courtesy of routers where the username and password = admin/admin

All the other users are on Macbooks
That is no guarantee LOL some people still think just because they have a Mac or Linux, they are immune to hacking :whistle:
 
Top
Sign up to the MyBroadband newsletter
X