On UrbanBaby: Working Mother Confession
BNET Business Network:
BNET
TechRepublic
ZDNet

March 6th, 2008

Router Backdoors: Hacked by Chinese Part 2?

Posted by Nathan McFeters @ 7:06 am

Categories: Exploit code, Hackers, Vulnerability research

Tags: Router, Back Door, SecureTest, Routers & Switches, Network Technology, Networking, Nathan McFeters

We all remember code red, right? Come on, you know you were hit with it…, ok, here’s an image just in case you forgot:

Hacked by Chinese
PCPro News out of the UK has written a story that I classify as xenophobic and unfair. PCPro spoke with the SecureTest company who asserted the following:

SecureTest believes spyware could be easily built into Asian-manufactured devices such as switches and routers, providing a simple backdoor for companies or governments in the Far East to listen in on communications.

“Organisations should change their security policies and procedures immediately,” says Ken Munro, managing director of SecureTest. “This is a very real loophole that needs closing. The government needs to act fast.”

What’s really interesting is that the article goes on to show no proof that this is indeed a very real loophole that needs closing. They site no cases of any backdoors in any current routers sold from China. I will give Ken Munro and SecureTest this, I do believe that a Chinese company could build a backdoor into router firmware. I also believe U.S. companies, French companies, Japanese companies, etc. could do this. In fact, this could be put into any software or hardware that we buy. Actually, one could make the case that by providing such weak protections out of the box (like username=admin password=admin for administrative consoles), many companies already are including backdoors in their routers.225px-is_this_tomorrow.jpg

Unfortunately for SecureTest, and the Chinese people, the article is portrayed as if they’ve already discovered a router that has a backdoor made by the Chinese, which I do not believe was Ken’s point. One would’ve thought that with the Beijing Olympics fast approaching, we would’ve been able to move past the views of McCarthyism and the Red Scare (see the image right in case you can’t remember history class).

My point is this, when it comes to hacking and the security of our nation, there’s very real threats that currently exist coming from China. Let’s not sensationalize and invent new ones until we have to, or else we could have our next hunt for Weapons of Mass Destruction.

Nathan McFeters

Nathan McFeters is a Senior Security Advisor for Ernst & Young's Advanced Security Center in Chicago. The views and opinions expressed in this article are his own and do not represent the views and opinions of Ernst & Young Advanced Security Center or Ernst & Young, LLP. Nathan has performed web application, deep source code, Internet, Intranet, wireless, dial-up, and social engineering engagements for numerous clients in the Fortune 500 during his career at Ernst & Young and has spoken at a number of prestigious conferences, including Black Hat, DEFCON, ToorCon, and Hack in the Box. He can be found at his Pwn* blog and XS-Sniper, a blog with Billy Rios. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 41 Talkback(s)
RE: Router Backdoors: Hacked by Chinese Part 2?
I think the USA should be abit open minded when it comes to trading with foreign countries. The globalisation of industries had led us trade, manufacture and work together. If someone is afraid of Com... (Read the rest)
Posted by: kiazhi@... Posted on: 03/09/08 You are currently: a Guest | | Terms of Use
Typo Alert  GiveMeGizmos | 03/06/08
RE: Router Backdoors: Hacked by Chinese Part 2?  nmcfeters | 03/06/08
Never hit by Code Red  voska1 | 03/06/08
RE: Never hit by Code Red...  nmcfeters | 03/06/08
I wasn't hit either  osreinstall | 03/08/08
xenophobic?  croberts | 03/06/08
Did you actually read the article or is your head in your PC case?  Been_Done_Before | 03/06/08
RE: Did you actually read the article...  nmcfeters | 03/06/08
There's a saying....  bportlock | 03/06/08
Ridiculous relativism  mlambert890@... | 03/08/08
RE: Ridiculous Relativism  nmcfeters | 03/09/08
Ah yes...  bportlock | 03/06/08
Have you walked into a store lately?  croberts | 03/06/08
RE: xenophobic?  nmcfeters | 03/06/08
Point taken, but  bportlock | 03/06/08
Microsoft is different. They have not yet  hkommedal | 03/07/08
Agreed  croberts | 03/06/08
RE: Agreed  nmcfeters | 03/06/08
China is pretty good at selling.  hkommedal | 03/07/08
Applies to drug dealers too  croberts | 03/08/08
Hackers: Auf vieter zeine  D. T. Schmitz | 03/06/08
Denyhosts? That's no fun!  toadlife | 03/06/08
Anyone who would  ShadeTree | 03/07/08
Ok, that settles it then...  D. T. Schmitz | 03/07/08
By the way: Auf wiedersehen = see you again ! (nt)  hkommedal | 03/07/08
Ich bin ein Berliner!  D. T. Schmitz | 03/07/08
That is OK. Just this: when you say "see you  hkommedal | 03/07/08
Xenophobic?  Hemlock Stones | 03/06/08
It said: "culminated in an exploit . .  hkommedal | 03/07/08
This is ridiculous  craneleeon@... | 03/06/08
Where is your logic?  pa2004 | 03/08/08
Excellent points made  nucrash | 03/07/08
"McCarthyism and the Red Scare"  ElderEagle | 03/07/08
RE: McCarthyism and the Red Scare  nmcfeters | 03/09/08
Another Risk: Operation Cisco Raider?  jalles | 03/07/08
Hang on a moment. That was COPYRIGHT -  hkommedal | 03/07/08
RE: Hang on a moment...  nmcfeters | 03/09/08
We didn't get hit with Code Red  John L. Ries | 03/07/08
It is time that Cisco makes their firmware HERE!  osreinstall | 03/08/08
RE: Router Backdoors: Hacked by Chinese Part 2?  znewt | 03/09/08
RE: Router Backdoors: Hacked by Chinese Part 2?  kiazhi@... | 03/09/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline