Looks like a Bonus Year for Pen-testers

Forumite Members General Topics Tech Security Talk Looks like a Bonus Year for Pen-testers

Viewing 1 post (of 1 total)
  • Author
    Posts
  • #9202
    Ed PEd P
    Participant
      @edps
      Forumite Points: 39

      Vault 7 have released yet another old CIA exploit. This one is slightly different in that it interferes with the normal firewall security that you would expect on your router. In simple terms it pwns your whole network, so an attacker can keylog, poison the DNS or alter router settings,, open ports etc. DNS poisoning of course allows a vast range of malware to be installed.

      Twenty-five routers are known to be affected but probably hundreds more could be attacked. In principle this is not very different from the host of malware that can attack badly secured routers, the big difference is that this malware can bypass even a secure admin password.

      The only security advice given is to turn off UPnP in your router (if you can!) and install your own custom firmware – e.g. tomato or dd-wrt.

      Ars Technica has some more details. El Reg has similar details with a slightly different slant.

      All this looks like adding up to a gang-buster year for security auditors and pen-testers! Probably means a big hike is required in a lot of IT budgets too.

    Viewing 1 post (of 1 total)
    • You must be logged in to reply to this topic.