{"id":78873,"date":"2013-05-28T22:39:15","date_gmt":"2013-05-28T20:39:15","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=78873"},"modified":"2013-05-29T08:28:13","modified_gmt":"2013-05-29T06:28:13","slug":"adsl-router-security-concern-in-sa","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/78873-adsl-router-security-concern-in-sa.html","title":{"rendered":"ADSL router security concern in SA"},"content":{"rendered":"<p>A large number of ADSL routers from South African Internet users are relatively easily accessible from the web thanks to default passwords for remote support accounts remaining unchanged.<\/p>\n<p>Using the website ShodanHQ, a MyBroadband member was able to easily get a list of routers in South Africa accessible from the Internet.<\/p>\n<p>The router that came up most often in the first 50 results to the user\u2019s query (which returned over 100,000 results in total) was the D-Link DSL\u20132750U on the Telkom Internet network.<\/p>\n<p>According to the MyBroadband forum member, they randomly tested a few of these routers and found that all of them were accessible using the default username and password for remote management.<\/p>\n<p><a title=\"Telkom\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/227037-Telkom\">Telkom<\/a> Internet currently has 3 different brands of ADSL routers listed on its website: D-Link (specifically the 2750U), Netgear, and Billion.<\/p>\n<p>A quick survey of popular consumer ADSL Internet Service Providers (ISPs) indicated that only <a title=\"Vox Telecom\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/222673-Vox-Telecom\">Vox Telecom<\/a>\u2019s Atlantic offers D-Link kit as an option to its customers. Atlantic\u2019s head office explained that only branches offer it though, and that they mainly supply customers Billion routers.<\/p>\n<p><a title=\"Mweb\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/226947-MWeb\">Mweb<\/a>, <a title=\"Web Africa\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/307429-WebAfrica\">Web Africa<\/a>, and <a title=\"Afrihost\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/307435-Afrihost\">Afrihost<\/a> don\u2019t currently offer <a title=\"D-Link\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/533899-D-Link\">D-Link<\/a> ADSL routers at all.<\/p>\n<div id=\"attachment_78893\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-78893\" class=\"size-full wp-image-78893\" alt=\"D-Link DSL\u20132750U press shot\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2013\/05\/D-Link-DSL\u20132750U-press-shot.jpg\" width=\"600\" height=\"400\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2013\/05\/D-Link-DSL\u20132750U-press-shot.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2013\/05\/D-Link-DSL\u20132750U-press-shot-250x166.jpg 250w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><p id=\"caption-attachment-78893\" class=\"wp-caption-text\">D-Link DSL\u20132750U press shot<\/p><\/div>\n<h3 class=\"my-4\">Security is a personal decision: Telkom<\/h3>\n<p>Asked about the security of these D-Link routers, Telkom explained that ADSL routers may be dispatched with factory default settings and passwords.<\/p>\n<p>\u201cAbuse and interception is preventable by changing the admin\/default usernames and passwords,\u201d a Telkom spokesperson told MyBroadband.<\/p>\n<p>Instructions to do this are published in the user guides for the Telkom-supplied modems, the spokesperson said.<\/p>\n<p>\u201cSecurity is a personal decision and while modems have the functionality to provide a safe environment, it is reliant on the user to activate the built in security measures to limit the risk of intrusion.\u201d<\/p>\n<h3 class=\"my-4\">Remote management blocked by default: D-Link<\/h3>\n<p>D-Link\u2019s technical supervisor, <a title=\"Altus Lourens\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/533901-Altus-Lourens\">Altus Lourens<\/a>, explained that by default all of their routers have the remote management feature on port 80 disabled.<\/p>\n<p>Lourens added that this is also true for the firmware supplied to Telkom Internet for the D-Link routers they sell.<\/p>\n<p>\u201cIf a client enables the remote management, D-Link Technical Support always recommends changing the default Support account password,\u201d Lourens said.<\/p>\n<p>\u201cFrom D-Link Technical Support side we have had a lot of queries from clients on how to do it,\u201d Lourens said.<\/p>\n<p>As an added security measure, should clients accidentally enable remote management they will only be able to log on remotely with the support account, which has limited permissions on the router.<\/p>\n<p>\u201cFor example: anyone remotely logged on will not be able to change anything on the NAT side like opening ports,\u201d Lourens said.<\/p>\n<div id=\"attachment_42303\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-42303\" class=\"size-full wp-image-42303\" alt=\"Roelf Diedericks\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2012\/01\/Roelf-Diedericks.png\" width=\"600\" height=\"399\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2012\/01\/Roelf-Diedericks.png 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2012\/01\/Roelf-Diedericks-100x66.png 100w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2012\/01\/Roelf-Diedericks-185x123.png 185w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2012\/01\/Roelf-Diedericks-250x166.png 250w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><p id=\"caption-attachment-42303\" class=\"wp-caption-text\">Roelf Diedericks<\/p><\/div>\n<h3 class=\"my-4\">Easily accessed routers used in DDoS attacks<\/h3>\n<p><a title=\"Roelf Diedericks\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/209726-Roelf-Diedericks\">Roelf Diedericks<\/a>, chief technology officer at <a title=\"Neology\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/308453-Neology\">Neology<\/a>, and <a title=\"Cybersmart\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/226185-Cybersmart\">Cybersmart<\/a> CEO <a title=\"Laurie Fialkov\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/278903-Laurie-Fialkov\">Laurie Fialkov<\/a>, recently told MyBroadband that DSL modems of unwitting users are often brought to bear in DNS Amplification attacks.<\/p>\n<p>This is a type of distributed denial of service attack (DDoS) that reportedly \u201c<a href=\"http:\/\/mybroadband.co.za\/news\/internet\/74281-biggest-cyber-attack-in-history-slows-global-internet.html\">almost broke the Internet<\/a>\u201d. Fialkov said that they have also seen it dramatically degrade the speeds of their ADSL customers.<\/p>\n<p>\u201cWe have seen various levels of DNS DDoS attacks originating from infected customers on networks we are involved with,\u201d Diedericks said. \u201cThe activity has certainly increased over the past few weeks,\u201d he added.<\/p>\n<p>Diedericks went on to explain that attackers find a foothold largely due to open resolvers, poorly configured DSL modems, and buggy firmware.<\/p>\n<div id=\"attachment_69338\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-69338\" class=\"size-full wp-image-69338\" alt=\"Laurie Fialkov\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2013\/01\/Lauri-Fialkov-2.jpg\" width=\"600\" height=\"400\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2013\/01\/Lauri-Fialkov-2.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2013\/01\/Lauri-Fialkov-2-100x66.jpg 100w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2013\/01\/Lauri-Fialkov-2-185x123.jpg 185w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2013\/01\/Lauri-Fialkov-2-250x166.jpg 250w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><p id=\"caption-attachment-69338\" class=\"wp-caption-text\">Laurie Fialkov<\/p><\/div>\n<h3 id=\"related\">More on information security in South Africa<\/h3>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/security\/78809-beware-sa-facebook-profiles-clones-used-for-fraud.html\">Beware: SA Facebook profiles clones, used for fraud<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/security\/78753-saps-website-still-vulnerable-hacker.html\">SAPS website still vulnerable: hacker<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/internet\/78368-slow-adsl-it-could-be-a-cyber-attack.html\">Slow ADSL? It could be a cyber-attack<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/security\/78242-internet-bank-fraud-affects-few-absa.html\">Internet bank fraud affects few: Absa<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you use a router to connect to the Internet, you should ensure that remote administration is only switched on if you absolutely need it<\/p>\n","protected":false},"author":15,"featured_media":77036,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[2954,19562,19568,19564,35,4358,1067,12973],"class_list":["post-78873","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-cybersmart","tag-distributed-denial-of-service-ddos","tag-dns-amplification-attack","tag-domain-name-system-dns","tag-headline","tag-laurie-fialkov","tag-neology","tag-roelf-diedericks"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/78873"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=78873"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/78873\/revisions"}],"predecessor-version":[{"id":78891,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/78873\/revisions\/78891"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/77036"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=78873"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=78873"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=78873"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}