Networking Forums

Networking Forums > Network Hardware > Network Routers > Potential email DDoS vuln on Netgear Rangemax routers..

Reply
Thread Tools Display Modes

Potential email DDoS vuln on Netgear Rangemax routers..

 
 
testing_h@yahoo.com
Guest
Posts: n/a

 
      06-08-2008, 10:51 AM
Hi all.

I just found something interesting. If someone does not set the
default password to something sensible on many routers including
Netgear Rangemax, it is possible to DDoS a given email address by
setting up automatic email notifications of hacking attempts.

Did this as an experiment accidentally on my router, and had over 1500
emails in less than a day.

Obviously you have to set up an email address to use this "feature"
but these are ten a penny. Hack half a dozen or more routers via
wireless, and the unfortunate victim would be unable to use email at
all until every single router was found and reprogrammed.

the vuln here is that the interval can be set ridiculously short
(<5min) and the router does not care at all, or even warn you of the
potential problem.

Regards, -Q

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Netgear RangeMax 240 Service Blocking ? John Wireless Internet 1 06-15-2008 09:20 PM
Leave Netgear Rangemax powered on? alexanderd79@googlemail.com Home Networking 4 10-13-2007 11:25 AM
NETGEAR RangeMax 240 Wireless Router Bob II Wireless Internet 0 01-26-2006 09:06 AM
[UK-Bug] News .. Potential vunerability on Linksys routers. Andy M Jenkins Broadband 2 06-03-2004 05:36 PM
Netgear Router DDOS Problem Klaatu Linux Networking 0 09-01-2003 11:49 PM



1 2 3 4 5 6 7 8 9 10 11