Submitted via IRC for AnonymousLuser
Over 21,000 Linksys routers leaked their device connection histories
Over 21,000 Linksys routers leaked their device connection historiesLinksys, however, says it can't replicate the apparent flaw.Sponsored Links
Certain Linksys WiFi routers might be sharing far more data than their users would like. Security researcher Troy Mursch has reported that 33 models, including some Max-Stream and Velop routers, are exposing their entire device connection histories (including MAC addresses, device names and OS versions) online. They also share whether or not their default passwords have changed. Scans have shown between 21,401 and 25,617 vulnerable routers online, 4,000 of which were still using their default passwords.
The attack appear to be relatively straightforward and involves little more than visiting an exposed router's internet address and running a device list request. It works whether or not the router's firewall is turned on, Mursch toldArs Technica, and isn't affected by a patch Linksys released in 2014.
There are potentially serious consequences. Complete connection histories could tell hackers if there are juicy targets on a given network, such as a phone running outdated software, while stalkers might find out if their victim had visited a given location. The password status, meanwhile, could make it easy to hijack devices for the sake of botnets and other online crimes.
(Score: 0) by Anonymous Coward on Monday May 20 2019, @03:10PM (1 child)
Very beautiful copypasta. A new low SN.
(Score: 0) by Anonymous Coward on Monday May 20 2019, @07:49PM
I know, right? And this article was clearly written by Cisco and proofed by D-Link to trash their competitor!
Our "intrepid" reporters, Buzzard, Takyon, Janrinok and Fnord are just rolling in the cash from those five figure monthly checks they get for their employment.
They were hired to do investigative journalism, but all they do is copy corporate propaganda they were likely paid to promote here.
Except for Buzzard. He doesn't even do copypastas.
This place has gone completely to hell. Where's the original content? Where's the investigative reporting?
It's not like SN is a "news aggregator and discussion site" or anything.
Oh, wait, that's exactly what SN is. But you knew that and just wanted to be an asshole. Good job. You've succeeded!
Oh, and the last paragraph of TFA goes like this: