Categorized | Security

Database of Network Device Private Keys Published

ssl_lock_.gifSometimes you run into something security-related in the computer industry that’s so stupid it’s hard to believe. Here we go again:

Many routers and other network devices use default or hard-coded SSL keys that can be recovered from the device’s firmware. An attacker could then use the keys to listen in on HTTPS traffic to the administration interface of the device. The database has over 2,000 device keys from vendors including Cisco, Linksys, D-Link and Netgear.

So a group has started a project called littleblackbox that contains a database of devices and their private keys.

Strictly speaking, this isn’t a vulnerability; it’s poor implementation. I’d also venture to say that the impact is not all that great, as typically it only allows sniffing of traffic inside the network. If the attacker is already in control of a PC inside the network you’ve already got a big problem and he will have a high rate of success in controlling the network device simply by using default usernames and passwords. There are many databases of these, such as this one.

– on Security Watch

Related Posts

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago