Owners and administrators of Linksys home routers are being advised
to update and secure their devices following reports of active attacks
on a flaw present in at least two models.
Researchers with the SANS Institutes Internet Storm Center have received reports
of mass attacks on a remote access vulnerability in the Linksys E1000
and E1200. The reports, which were noted by an ISP administrator in
Wyoming, claim that some customers running the Linksys routers have had
their networks compromised.
According to the reports, the compromised routers scanned network
traffic rapidly on port 80/8080, saturating available bandwidth, and in
some cases their DNS settings were modified.
While the exact
nature of the flaw being exploited is not yet known, early speculation
is that the issue could be related to components using the home network
administration protocol (HNAP).
SANS noted that E1200 routers with
the latest 2.0.06 firmware version seemed to be immune to the spotted
attacks, but the E1000s – which are no longer supported – were not, even
with the most recent firmware installed.
Linksys did not return a request to confirm or comment on the reports.
Dr. Johannes Ullrich, chief research officer with the SANS Institute, told The Reg
that in addition to updating firmware, owners and administrators of the
vulnerable routers should look to tighten their administrator access
controls.
"They should either turn off remote admin functionality,
or restrict it to IP addresses from which they need to access the
router if they can," Ullrich said.
The report comes not long after word surfaced of
other security vulnerabilities found in routers made by Linksys' former
parent company, Cisco. Those flaws affected a number of small business
products from Cisco, and did not impact any Linksys branded devices
Information Security, Ethical Hacking, website Security, Database Security, IT Audit and Compliance, Security news, Programming, Linux and Security.
Wednesday, 12 February 2014
Bitcoin exchange halts withdrawals after cyber-attack
A flaw in Bitcoin's software is proving more problematic than had been suggested
Bitstamp - one of the world's largest Bitcoin exchanges - has halted withdrawals after coming under cyber-attack. The Slovenia-based firm said the culprits had exploited a bug
in the virtual currency's underlying software to carry out the assault.
It is the second exchange to suspend operations. Tokyo's MtGox took a similar measure on Friday.A third, Bulgaria's BTC-e, has warned that some transactions may be delayed.
Like Bitstamp, it cited a denial-of-service (DoS) attack as the cause.
It added that people who had funds stored with the affected exchanges should know that their savings were safe, albeit "tied up" for the time being.
"This is a denial-of-service attack; whoever is doing this is not stealing coins, but is succeeding in preventing some transactions from confirming," wrote Gavin Andresen, chief scientist at the foundation.
"It's important to note that DoS attacks do not affect people's Bitcoin wallets or funds."
Mutated IDs
The cause of the problem is an issue called transaction malleability.
It involves someone changing the cryptographic code - known
as a transaction hash - used to create an ID for the exchange of funds
before it is recorded in the blockchain - a database of every
transaction carried out in the currency.On Monday, MtGox had suggested that this technique could be used to fool its systems into repeatedly making a payout because it would seem that it had not occurred.
The Bitcoin Foundation's initial response was that transaction malleability had been known about since 2011, and that MtGox should have prepared for this when developing its own customised software, which was now proving vulnerable.
"This is something that cannot be corrected overnight," wrote Mr Andresen.
But while other exchanges are not complaining about the risk of making unauthorised payouts, it appears their systems can become overwhelmed if they receive too many "mutated versions" of the transaction IDs.
"This is a denial-of-service attack made possible by some misunderstandings in Bitcoin wallet implementations," said Bitstamp's blog.
"These misunderstandings have simple solutions that are being implemented as we speak, and we're confident everything will be back to normal shortly."
The Bitcoin Foundation now says its members and developers from a number of exchanges are working "collectively and collaboratively" to tackle the problem and allow withdrawals to resume.
'Wake-up call' One bitcoin is currently trading for about $665 (£402). That is well below the $830 level it was at last Thursday, reflecting investors' concern at the news.
However, one expert said the virtual currency should emerge from the attacks more robust than before.
Subscribe to:
Posts (Atom)