Warning: Trying to access array offset on value of type bool in /home/sites/3b/7/74de28c56e/public_html/wp-content/plugins/related-posts-thumbnails/related-posts-thumbnails.php on line 846
 

Blog Update: Another Talk Talk security breach and Talk Talk compounds issue by claiming passwords do not need resetting! - InstaHost Solutions

28th November 2016by Andy Mc

New Update 7/12/2016
Further news reaches us from Talk Talk Towers where the ineptitude appears to have no limits! As we previously blogged – despite warnings about Router vulnerabilities (which Talk Talk ignored) some of their routers were indeed breached and the Mirai Worm introduced. Now it seems that this was not all that the hackers did, due to the diligence of cyber-security researchers at Pen Test Partners whom had been investigating the spread of a variant of the Mirai worm, which was causing several makes of routers to stop working properly. During tests of a Talk Talk model, the researchers discovered that the vulnerability exploited by the worm was also being abused to carry out a separate attack that forced the router to reveal its wi-fi password. On Monday morning several “lists” of Talk Talk users credentials (allegedly) we available to buy on Dark Web MarketPlaces.

Predictably, Talk Talk played down the discovery, saying it had “not seen anything to confirm” that users’ router credentials had been stolen.
It said it was also making “good progress” to protect its routers.

Unfortunately for Talk Talk, one of the individuals whom possess a list sent a snapshot of some of the credentials contained in the document (the document is claimed to hold 57,000 different credentials) that had been scraped before any fix had been rolled out. The list contained details of about 100 routers including:
* their service set identifier (SSID) codes and media access control (MAC) addresses. These can be entered into online tools that reveal the physical location of the routers
* the router passwords, which would allow someone who traveled to the identified property to access the wi-fi network

The source said he wanted to highlight the problem because other more malevolent actors might have carried out a similar operation.

The BBC passed the details on to TalkTalk.
“The list that you sent me, I can confirm that they are TalkTalk router IDs,” said its head of corporate communications.
“But we haven’t seen anything to suggest that there are 57,000 of them out there.” Obviously ignoring the fact that multiple documents are on sale which contradicted their claim that Passwords had not been breached!

However, leaked credentials ARE an issue (obviously) as the hackers could:
* snoop in the homeowners’s data, which might be clearly visible or encrypted in ways that still allowed the original information to be easily recovered
* use the internet connection to mount an onward attack. The hacker could do this to hide their own identity or to co-opt the router to join an army of other compromised equipment in later DDoS (distributed denial of service) attacks
* substitute the router’s firmware with a modified version that provided a backdoor for later access even if the device was reset
* log in to the router as the administrator and mount a “man in the middle attack”. In simple terms, a man-in-the-middle attack is a situation in which a malicious eavesdropper (the “man in the middle”) is able to read (or write) data that is being transmitted between you and the website you’re browsing. The attacker is typically a link in the chain through which data travels as it goes from you to the website or vice versa, and they have been able to successfully impersonate each side to the other, hence getting total access to the communication. For this type of attack to be possible, both sides of the conversation need to have a security flaw.

The consequences are that any sensitive personal information (think passwords, personal data, financial information, etc.) can be read by the attacker in such a situation.

Protect Yourself from Man-in-the-Middle Attacks

With any security flaw or data breach, the most important thing is to change your password if you think you could have been breached. This is standard operating policy – unless you are Talk Talk, whom despite being fined £400,000 last month by the Information Commissioner’s Office for a previous breach that led to the theft of nearly 157,000 customers’ personal details, remains unconcerned at this latest, avoidable breach!

TalkTalk asked that its statement be quoted in full:
“As is widely known, the Mirai worm is an industry issue impacting many ISPs around the world, and a small number of TalkTalk customers have been affected.

“We can reassure these customers there is no risk to their personal information as a result of this router issue and there is no need for them to reset their wi-fi password.

“However, any customer with concerns can find out how to change their wi-fi password on our website or in their initial router set up guide. We have made good progress in repairing affected routers, but any customer who is still having any problems should visit our help site where they can find a guide that will show them how to reset their router.
“Alternatively, they can call us and we can talk them through the repair process or send them a new router.”

Our advice for Talk Talk users is simple – CHANGE YOUR PASSWORD NOW – Then call them to ask for a new router. Better yet, consider moving to an ISP whom takes your security seriously.

A new Update: 1/12/2016 18:07 GMT
On Monday 28th November we published the following blog about the Mirai Worm being used against Deutsche Telekom routers and warned that it would likely be used to affect Talk Talk routers, today in the last hour Talk Talk have been forced to announce that along with the Post Office, an unspecified number of customers have been affected by exactly the type of attack they were warned of.

So the real question is why companies whom display such a blatant disregard for customers data security are allowed to continue to operate. What meaningful action if any, is the Information Commissioners Office going to take against Talk Talk who were warned about a vulnerability and chose to ignore the warnings? At the current time Talk Talk are “working on a fix” It really is time for UK regulators to actually take action against these companies who clearly prioritise profit over data security.

**Original Blog Post**
A new version of Mirai, a malware that’s been enslaving poorly secured IoT devices has found a new victim: Hundreds of thousands of Deutsche Telekom broadband customers’ vulnerable internet routers from Germany’s Deutsche Telekom. Resulting in the malware crashing their routers and the spread of the new strain of Mirai has caused internet connection problems for close to a million Deutsche Telekom customers, the company reported on Monday.

The telco said as many as 900,000, or about 4.5 percent of its 20 million fixed-line customers, began to have problems connecting to its network on Sunday afternoon. “The attack attempted to infect routers with a malware, but failed, which caused crashes or restrictions for 4 to 5 percent of all routers,” the company said in an email. However, initial findings suggest that the new strain of Mirai succeeded in ensnaring at least some devices. To track the malware’s spread, Johannes Ullrich, a security researcher with the SANS Technology Institute, established a web server early on Monday designed to act as a honeypot that can lure in the attack.

“Once Mirai infects a system, it goes off looking for more victims,” he said.

As of Monday morning, he’d found 100,000 unique IP addresses attempting to infect his honeypot.

An automatic software update for the affected routers is being rolled out. Deutsche Telekom said the malware did not survive a reboot.

Kaspersky researcher Stefan Ortloff gathered technical details from affected users as well as samples of the malware which he said was a variant of the Mirai botnet.

Analysing the malware-generated network traffic, it was directed at transmission control protocol (TCP) port 7547 on the routers. That port is used for the TR-064 protocol that internet providers and telcos connect to over their networks to configure customer DSL routers remotely – so just to make that clear -the Telco and the router maker were fully aware of the vulnerability as it simply made their life easier;  remarkably two routers provided by UK ISP TalkTalk are vulnerable and yes, they are aware of the vulnerability, but whether they take appropriate actions remains to be seen (yes the same Talk Talk which lost thousands of customers personal data when their own system was hacked!) – a ZyXEL modem and the D-Link DSL-3780. Devices from T-Com/T-home (SpeedPort), MitraStar, Digicom, and Aztech are also at risk.

The command and control server domains for the attack were pointed to United States military networks in the 6.0.0.0/8 IP address range. There is, however, no Mirai-related infrastructure on that network, meaning any remaining bots will not receive further commands until the attackers change the domain name system records for the malware configuration.

What is Mirai?
For our readers unfamiliar with Mirai (Japanese for “the future”), this is a malware family that turns computer systems running Linux into remotely controlled “bots”, that can be used as part of a botnet in large-scale network attacks. It primarily targets online consumer devices such as remote cameras and home routers.that targets embedded systems and Internet of Things (IoT) devices and has been used in the past two months to launch the largest DDoS attacks known to date.

Previous high-profile victims included French Internet service provider OVH (1.1 Tbps), managed DNS service provider Dyn (size unknown), and the personal blog of investigative journalist Brian Krebs (620 Gbps), who at the time, had just recently uncovered an Israeli DDoS-for-Hire service called vDos.


Warning: Trying to access array offset on value of type bool in /home/sites/3b/7/74de28c56e/public_html/wp-content/themes/applauz/views/prev_next.php on line 10
previous
Top 5 qualities of Project Managers who excel
next
The Periodic Table of SEO Success Factors

Warning: Trying to access array offset on value of type bool in /home/sites/3b/7/74de28c56e/public_html/wp-content/plugins/related-posts-thumbnails/related-posts-thumbnails.php on line 846
https://www.instahost.solutions/wp-content/uploads/2018/10/logo1.png
https://www.instahost.solutions/wp-content/uploads/2017/03/logo_white.png
Insta Security
Website Secured by InstaHost.co.uk
InstaHost Solutions

Our Mission is to deliver an industry leading, comprehensive service to all of our clients regardless of client size or complexity of services required, we are committed to continually striving to develop new, innovative services and technologies in order to continue deliver cutting edge service solutions to all of our clients. We give our clients full control of their digital business without a ridiculous price tag, and our friendly team offers their expertise at all times!

Subscribe

If you wish to receive our latest news in your email box, just subscribe to our newsletter. We won’t spam you, we promise!

    Applauz

    As the pioneer of the lean startup movement, APPLAUZ has dedicated it’s time to sharing effective business strategies that help new businesses and enterpreneurs put their money to work in the right way.

    2021 Copyright by InstaHost Solutions, Powered by InstaHost.co.uk. All rights reserved.