bk99.de entertain the web since 1997

New security hole in internet routers

Summary

In 2001 the configuration password of DrayTek’s Vigor2000 and Vigor2200 DSL and ISDN routers could be spied out from the local network. Attackers on the LAN could use it to reconfigure the router; only firmware 1.07 helped. The hole could not be exploited from the internet and was therefore less dangerous than the insecure default configuration of many routers.

Ideas

  • The local network is not a trusted zone either.
  • A spied-out admin password allows the router to be completely reconfigured.
  • German firmware versions were distributed by the importers TwoCom and Dr. Bott.

Insights

  • Insecure defaults often endanger more devices than individual software bugs.
  • The reach of a hole, LAN or internet, determines its urgency.

Facts

  • The Vigor2000 and Vigor2200 series were affected.
  • The hole was closed with firmware version 1.07.

References

Critique

  • The report does not describe how the password could be spied out, which makes checking without an update harder.

Recommendations

  • Restrict access to router management to a separate management network or specific hosts.
  • Change routers’ default configurations and passwords when you put them into operation.

Read the original article

Search the Web Archive