>20, 000 Linksys routers leak historic record of every device ever connected

Peter Reutemann <[email protected]>
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12JS=YgRSfY2vOW=icTz4ZZ0uwi3HE36i8=LD+72TvHKJA@mail.gmail.com>
'This post has been updated to add comments Linksys made online, which
says company researchers couldn't reproduce the information disclosure
exploit on routers that installed a patch released in 2014.
Representatives of Belkin, the company that acquired Linksys in 2013,
didn't respond to the request for comment that Ars sent on Monday. Ars
saw the statement only after this article went live.

More than 20,000 Linksys wireless routers are regularly leaking full
historic records of every device that has ever connected to them,
including devices' unique identifiers, names, and the operating
systems they use. The data can be used by snoops or hackers in either
targeted or opportunistic attacks.

Independent researcher Troy Mursch said the leak is the result of a
flaw in almost three dozen models of Linksys routers. It took about 25
minutes for the Binary Edge search engine of Internet-connected
devices to find 21,401 vulnerable devices on Friday. A scan earlier in
the week found 25,617. They were leaking a total of 756,565 unique MAC
addresses. Exploiting the flaw requires only a few lines of code that
harvest every MAC address, device name, and operating system that has
ever connected to each of them.

The flaw allows snoops or hackers to assemble disparate pieces of
information that most people assume aren’t public. By combining a
historical record of devices that have connected to a public IP
addresses, marketers, abusive spouses, and investigators can track the
movements of people they want to track. The disclosure can also be
useful to hackers. The Shadowhammer group, for instance, recently
infected as many as 1 million people after hacking the software update
mechanism of computer maker ASUS. The hackers then used a list of
about 600 MAC addresses of specific targets that, if infected, would
receive advanced stages of the malware.'

-- source: https://arstechnica.com/information-technology/2019/05/33-linksys-router-models-leak-full-historic-record-of-every-device-ever-connected/

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list | [email protected]
Unsubscribe: https://list.waikato.ac.nz/mailman/listinfo/wlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.