Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
FBI Warns Users to Reboot All SOHO Routers
Newest First  |  Oldest First  |  Threaded View
johnsmith247
50%
50%
johnsmith247,
User Rank: Apprentice
10/31/2018 | 4:12:51 AM
Re: The FBI is widening its guidance
I read some news before some days ago, According to the FBI warning, "the malware targets IP Address Conflict  routers produced by several manufacturers and network-attached storage devices by at least one manufacturer." 
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
5/31/2018 | 3:37:45 PM
Re: SOHO Only?
Many SOHO's have also already released patches for the exploit. The reboot will allow those patches to be applied. But you are definitely correct, you would be hard pressed to see Commercial grade networking gear and SOHO's sharing the same threat landscape.
Norman.Neil
50%
50%
Norman.Neil,
User Rank: Apprentice
5/31/2018 | 8:43:32 AM
Re: SOHO Only?
SOHO = small office, home office

It is meant to include all consumer-grade routers.

Commercial-grade routers (i.e. CISCO, HP, etc.) generally have much stronger security associated with their operation, like requiring administrative privileges to install anything on them.   
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
5/30/2018 | 6:24:39 PM
SOHO Only?
Is this only about this router, what about others?
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
5/30/2018 | 6:23:53 PM
Re: The FBI is widening its guidance
rather than just more "Russia! Russia! Russia!" in order to distract domestic attention Good point, never thought in that way.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
5/30/2018 | 6:23:05 PM
Re: The FBI is widening its guidance
Perhaps the concentrated volume of reestablishing connections with the botnet ... Or giverment know something and they do not let us know.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
5/30/2018 | 6:21:46 PM
Re: The FBI is widening its guidance
Hard to see the rationale behind call for reboot of all SOHO routers I am also not sure about the real objective of this action.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
5/30/2018 | 6:20:24 PM
Reboot?
Wondering how reboot would remove the flow, how did happen in the first place?
BrianN060
50%
50%
BrianN060,
User Rank: Ninja
5/30/2018 | 3:48:48 PM
The FBI is widening its guidance
Hard to see the rationale behind call for reboot of all SOHO routers (given ...that the first-stage loader for the botnet is persistent...).  Perhaps the concentrated volume of reestablishing connections with the botnet command/control will be useful, at least as an indication of scope and scale.  Hope it's something like that, rather than just more "Russia! Russia! Russia!" in order to distract domestic attention away from other issues and concerns. 


Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
Black Hat Q&A: Hacking a '90s Sports Car
Black Hat Staff, ,  11/7/2019
The Cold Truth about Cyber Insurance
Chris Kennedy, CISO & VP Customer Success, AttackIQ,  11/7/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-18923
PUBLISHED: 2019-11-13
Insufficient content type validation of proxied resources in go-camo before 2.1.1 allows a remote attacker to serve arbitrary content from go-camo's origin.
CVE-2010-4664
PUBLISHED: 2019-11-13
In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their privileges by initiating a remote VNC session.
CVE-2010-4817
PUBLISHED: 2019-11-13
pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.
CVE-2013-3097
PUBLISHED: 2019-11-13
Unspecified Cross-site scripting (XSS) vulnerability in the Verizon FIOS Actiontec MI424WR-GEN3I router.
CVE-2013-3366
PUBLISHED: 2019-11-13
Undocumented TELNET service in TRENDnet TEW-812DRU when a web page named backdoor contains an HTML parameter of password and a value of j78G�DFdg_24Mhw3.