Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

steve2470

(37,457 posts)
Fri Mar 6, 2015, 10:27 AM Mar 2015

Broadband routers: SOHOpeless and vendors don't care

http://www.theregister.co.uk/2015/03/05/broadband_routers_sohopeless_and_vendors_dont_care

(yes that's the original article title)

Home and small business router security is terrible. Exploits emerge with depressing regularity, exposing millions of users to criminal activities.

Many of the holes are so simple as to be embarrassing. Hard-coded credentials are so common in small home and office routers, comparatively to other tech kit, that only those with tin-foil hats bother to suggest the flaws are deliberate.

Hacker gang Lizard Squad crystallised the dangers – and opportunities – presented by router vulnerabilities when over the Christmas break they crafted a slick paid denial of service stresser service that operated on hacked boxes. Customers were found paying to flood targets of choice with gigabits of bandwidth stolen from what the black hats claimed were a fleet of half a million vulnerable and subsequently hacked routers.

A year earlier, security boffins at Team Cymru warned that an unknown ganghad popped 300,000 routers in a week, altering the DNS settings to point to malicious web entities. Those routers were hacked through a self-propagating worm (PDF) that researchers had already warned about, but not yet seen. It used a mix of brute force password guessing of web admin consoles, cross-site request forgery, and known un-patched vulnerabilities.

more at link above
2 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Broadband routers: SOHOpeless and vendors don't care (Original Post) steve2470 Mar 2015 OP
If you can, run 3rdParty firmware... ChromeFoundry Mar 2015 #1
yep, I just installed DD-WRT on my D-Link 880L steve2470 Mar 2015 #2

ChromeFoundry

(3,270 posts)
1. If you can, run 3rdParty firmware...
Fri Mar 6, 2015, 04:00 PM
Mar 2015

Tomato, OpenWRT and DD-WRT are terrific alternatives to the stock firmware offerings on many supported routers/access points. There are even builds for the Raspberry PI with a wireless USB, to serve as a router. SOHO router vendors should be ashamed of themselves.

steve2470

(37,457 posts)
2. yep, I just installed DD-WRT on my D-Link 880L
Sun Mar 8, 2015, 03:01 AM
Mar 2015

It's 1000000000% better than the stock firmware. Hopefully one day the router vendors will realize that, yes, we ordinary consumers crave security also.

Latest Discussions»Help & Search»Computer Help and Support»Broadband routers: SOHOpe...