tech2news around U

Just another WordPress.com weblog

Posts Tagged ‘router’

Dlink Launches Xtreme N Router

Posted by mylow on April 3, 2008

D-Link launched its Xtreme N router DIR-655, using the latest Draft 802.11n wireless technology, in the Indian market.

The D-Link Xtreme N Gigabit Router (DIR-655) is designed for consumers, small businesses and gamers. The Xtreme N family is designed for larger homes and offices with high-speed Internet using multiple PCs, game consoles and other digital home devices such as streaming media adapters.

With faster speeds and further range than that found in 802.11g wireless products, the D-Link Xtreme N Router claims to be industry’s first Gigabit Draft N router to incorporate Intelligent Wireless Quality of Service (QoS) Technology that automatically prioritizes high-bandwidth, latency-sensitive wireless data traffic, allowing users to experience smooth streaming HD video, lag-free gaming and jitter-free voice over Internet (VoIP) calls. The D-Link XtremeN QoS is powered by StreamEngine technology from Ubicom.

The Xtreme N router also ships with Gigabit local area network (LAN) and Gigabit wide area network (WAN) ports. In addition, the Xtreme N router comes with an integrated wireless security wizard, Windows Connect Now (WCN) support for easily connecting WCN-enabled devices, Network Magic’s management features from Pure Networks, removable antennas for flexible installation, and a wall-mount option.

The D-Link DIR-655 router is available for Rs. 12,500.

Posted in Dlink | Tagged: , , , , | Leave a Comment »

Symantec Suspects Bot in Attacks on D-Link Routers

Posted by mylow on March 26, 2008

Suspicious port scanning that’s been tracked back to D-Link routers may mean a worm or bot is on the loose and infiltrating the popular brand’s devices using a three-year-old vulnerability, security researchers at Symantec said.

The security company issued a warning Monday night to customers of its DeepSight threat notification service saying that there were “reliable reports” of an in-the-wild worm or bot that was attacking, then installing itself, on D-Link routers. By today, however, Symantec had taken a step back.

“After looking into it further, we decided that that was a little misleading,” said Oliver Friedrichs, a director of Symantec’s security response team. “It’s unconfirmed at this point. But we have definitely seen an increase in attack activity, and that activity appears to be coming from other D-Link devices.”

In other words, although Symantec’s researchers haven’t gotten their hands on a worm or bot sample, all the evidence points in that direction. “We suspect that it’s a bot,” he said.

According to Friedrichs, the attacks against the D-Link routers begin with hackers scanning TCP port 23 for an active SNMP (Simple Network Management Protocol) service, a flaw that first showed up in D-Link router firmware in 2005. “It looks like they’re exploiting the SNMP vulnerability to reset and reconfigure the administrative password on the routers,” said Friedrichs, perhaps to conduct “drive-by pharming” attacks that change a router’s settings so its users are unknowingly directed to bogus or malicious Web sites instead of the real URLs.

“Having port 23 open on the Internet-facing side is a bad idea in general,” said Petko Petkov, a prolific penetration tester from the U.K who, with a partner, Adrian Pastor, has published research on hacking routers. “But I guess this is due to the fact that the attacked devices have only one Ethernet port and users can unwillingly expose otherwise privileged services on the Internet.”

Router vulnerabilities are up and attacks against routers are on the upswing — especially attacks that target devices used by consumers and small businesses to create wireless networks, said Friedrichs. “Attackers are increasingly looking beyond the desktop,” he said, for new places to install — and hide — their malware.

Petkov wasn’t shocked to hear of Symantec’s warning. “We’re not surprised at all, as all embedded-device(s) we have tested so far are vulnerable to all kinds of interesting vulnerabilities,” Petkov said in an e-mail today. Nor would creating a worm or bot Trojan be tough. “Anybody can code a worm which attacks routers on a massive scale quite easily. Most of the research information is out there, so it is a matter of putting the pieces of the puzzle together.”

Friedrichs characterized the port 23 scanning activity Symantec is seeing as “moderate” and said the researchers will continue to investigate. He and his team, however, had not been able to verify that the vulnerability had been patched, and if so, when, or which specific models of D-Link’s routers might be at risk.

D-Link officials did not respond to a call for comment.

For the moment, the best advice Friedrichs had for D-Link router owners is to make sure that the SNMP service was not exposed to the Internet.

Posted in Symantec | Tagged: , , , , , | Leave a Comment »