Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » DSL Reports At Code Red Forefront » Cisco 6xx DSL router vulnerability -- and fix.
 
Search Topic:
  Share Topic:
RSS topic:
 toggle:
flat / full
normal / watch
Post a:
Post a:
Code Red RetroVirus Request »
« Busy busy busy  
AuthorAll Replies


Dan Parslow

@agency.com


Cisco 6xx DSL router vulnerability -- and fix.

Some, if not all models of consumer-level Cisco broadband routers can be taken down by the Code Red worm: the worm sends a malformed HTTP GET, which, if it targets the HTTP port of the router (used by the web configuration tool) , will cause the router to halt. Certain VARs are saying that the way to correct this is to deactivate web configuration. This is not effective, as the router will still accept HTTP requests; it just won't offer the configuration screen in response. Since it still accepts requests, it still crashes.
The way to correct this is to render the HTTP port of the router inaccessible from the outside of your network. Two simple approaches, both effective, are:
1) Change the port from 80 to something obscure, like 8081. Worms don't usually bother with nonstandard ports and this particular worm never does. This is a weak solution but effective in this case.
2) Use the router's own filter rules to deny HTTP access to the router's address from the WAN interface.

If you have a proper firewall, there are even better solutions, but both of these are effective.
It has been suggested (by Cisco, I believe) that upgrading to CBOS 2.41 will correct this vulnerability. I found this to be untrue. The only solution is to completely deny access to the web configuration port.


Nexxus

@prairieinet.net
I am going to try your solution I hope it fixes this problem. I have also found the cisco/qwest solution to be untrue and does not solve the problem.
Forums » DSL Reports At Code Red ForefrontCode Red RetroVirus Request »
« Busy busy busy  

Most commented news this week
· [173] East Coast Verizon Workers Authorize Strike
· [166] Is AT&T Hinting At Usage-Based Pricing This Fall?
· [149] Time Warner Cable Using Fine Print To Foist Caps On Customers
· [125] Is Broadband A Civil Right?
· [111] The Great Landline Exodus Continues
· [97] Update Your Browser, Dummy
· [82] What's Your Favorite Newsgroup Provider?
· [75] Comcast Hit With Another Throttling Lawsuit
· [73] Google's Cerf: Baby Bells Act Like Tots Having Tantrums
· [71] NY AG Will Sue Comcast If They Don't Pretend To Fight Child Porn
Friday, 25-Jul
20:49:55
Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
8th year online! © 1999-2008 dslreports.com.
page compression OFF