Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

February 8th, 2012, 13:53 GMT · By Eduard Kovacs

Hacker Shows How Easily Eircom Connections Can Be “Destroyed”

SHARE:

Adjust text size:


ZyXEL P-660HW router
Enlarge picture
An amateur hacker revealed how easy it would be for someone to exploit one of Ireland’s most popular modems and routers. Ross Canpolat showed that, with the use of a simple software and a few other basic steps, almost anyone could access a device and cause serious damage.

Even though the technique may work on other devices as well, Canpolat tested a very popular router from Eircom, specifically the ZyXEL P-660, claiming that by exploiting it a hacker could change and create administrator passwords, enable local admin login, restart the device, change the machine’s firmware and much more.

All an attacker needs to do to gain access to the router is to obtain the victim’s IP address, a task not that difficult for anyone, let alone a skilled hacker. In case the IP is dynamic, the attacker can set up a special software such as DynDNS to make sure he can still access the device once the address is changed.

The IP address is needed for the piece of software that does the rest of the work. RouterPWN is a software presented by researcher and security consultant Pedro Joaquin at Shmoocon 2012 as part of a presentation called “A Mobile Router Exploitation Framework.”

The simple application allows anyone to access a router within seconds and perform operations such as unauthorized reset or privilege escalation.

“Getting Admin access will allow you to destroy the box (requiring a hard reset), it will blatantly show you the WiFi Encryption Key, it will allow you to bring down the networks Firewall, it will blatantly show you others on the network giving you a guaranteed target for some NMAP Scanning & Metasploit Exploitation to literally hack into their computer and steal data,” Canpolat wrote.

Eircom has been notified on the issue, but the hacker says he plans on making tests on Vodafone and UPC devices as well.
FILED UNDER:
hacked
router
Ireland

TELL US WHAT YOU THINK:

1,724 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Kaspersky Anti-Virus and Internet Security 2012 Vulnerable to Hackers

Hackers Around the World: Eastern European SEPO

Video PoC: Attackers Post on Google+ on User’s Behalf

PHP 5.3.9 Regression Allows HTTP Header Attacks and 32/64-Bit OS Detection

TeamHav0k Hackers Find XSS in NASA Website

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM