General Discussion
Related: Editorials & Other Articles, Issue Forums, Alliance Forums, Region ForumsDear Asus router user: You’ve been pwned, thanks to easily exploited flaw
http://arstechnica.com/security/2014/02/dear-asus-router-user-youve-been-pwned-thanks-to-easily-exploited-flaw/
An Ars reader by the name of Jerry got a nasty surprise as he was browsing the contents of his external hard drive over the weekenda mysterious text file warning him that he had been hacked thanks to a critical vulnerability in the Asus router he used to access the drive from various locations on his local network.
"This is an automated message being sent out to everyone effected (sic)," the message, uploaded to his device without any login credentials, read. "Your Asus router (and your documents) can be accessed by anyone in the world with an Internet connection. You need to protect yourself and learn more by reading the following news article: http://nullfluid.com/asusgate.txt."
It's likely that Jerry wasn't the only person to find the alarming message had been uploaded to a hard drive presumed to be off-limits to outsiders. Two weeks ago, a group posted almost 13,000 IP addresses its members said hosted similarly vulnerable Asus routers. They also published a torrent link containing more than 10,000 complete or partial lists of files stored on the Asus-connected hard drives.
The guerilla-style hacking disclosure comes eight months after a security researcher publicly disclosed the underlying vulnerability that exposed the hard drives of Jerry and so many other Asus router users. The June 22 report found the "ability to traverse to any external storage plugged in through the USB ports on the back of the router," but researcher Kyle Lovett said he went public only after privately contacting Asus representatives two weeks earlier and getting a response that the reported behavior "was not an issue." In July, Lovett published a second disclosure that offered additional technical details.
hobbit709
(41,694 posts)I don't even plug an external drive into a computer until I'm ready to use it. I keep my security locked down pretty tight.
RKP5637
(67,112 posts)2 wires going out of the secured mainframe data center you're at risk! 900 baud modems back then, state of the art! LOL!
hobbit709
(41,694 posts)RKP5637
(67,112 posts)RKP5637
(67,112 posts)Ron Obvious
(6,261 posts)I was running this exact configuration and have now upgraded the firmware.
No text files on the USB drives, but I'll reformat them just the same.
steve2470
(37,481 posts)steve2470
(37,481 posts)
Kick in to the DU tip jar?
This week we're running a special pop-up mini fund drive. From Monday through Friday we're going ad-free for all registered members, and we're asking you to kick in to the DU tip jar to support the site and keep us financially healthy.
As a bonus, making a contribution will allow you to leave kudos for another DU member, and at the end of the week we'll recognize the DUers who you think make this community great.