this post was submitted on 26 Mar 2024
31 points (100.0% liked)

Cybersecurity

5753 readers
263 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 1 year ago
MODERATORS
top 4 comments
sorted by: hot top controversial new old
[–] [email protected] 4 points 8 months ago* (last edited 8 months ago) (2 children)

Wondering if this can affect routers running custom firmware as well, such as AdvancedTomato.

[–] kid 10 points 8 months ago

In this particular case, the method of infection of the router was not disclosed. However, typically, the most common methods involve an open administration port to the internet (user interface or TR-069) or through the internal interface, in case a network host has been compromised.

They often perform brute-force password attacks, and once access is obtained, they look for typical Linux administrative tools (such as bash, etc.) and proceed to compromise the router.

So I understand that a router with custom firmware can be compromised if it has a weak password and resources to maintain the infection, or of course, a vulnerability that is exploitable.

[–] [email protected] 2 points 8 months ago

typically, these old soho routers use ancient firmware with multiple known vulns. add to that the silly practice of opening the management ports to the public internet, and you have a potential disaster.

if your older hardware is capable of running an open source, maintained OS build, then do it. added functionality plus updated protection keeps these devices useful and out of landfills.

[–] [email protected] 4 points 8 months ago

No mention of the affected models?