Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi all,
Vanilla are planning an update to the site on April 24th (next Wednesday). It is a major PHP8 update which is expected to boost performance across the site. The site will be down from 7pm and it is expected to take about an hour to complete. We appreciate your patience during the update.
Thanks all.

Major vulnerability in virtually all cable TV modems

Options
  • 18-01-2020 12:10pm
    #1
    Registered Users Posts: 1,667 ✭✭✭


    A new malware has been discovered, which if used can allow anybody in the world to get into your cable modem and into your connected computer systems and read data, encrypt the data and ask you for bitcoin to decrypt the data, and stop your phone system. It can also lock your cable company out of updating the firmware on the modem to fix the bug. Really nasty stuff.

    https://cablehaunt.com. A Danish researcher has created an entire website on this one issue.

    Video: https://youtu.be/STWo0iMqSTs?t=5745

    Mod : Snip


Comments

  • Moderators, Education Moderators Posts: 2,604 Mod ✭✭✭✭horgan_p


    I think you're blowing this up a little bit. That isn't to say this isn't serious.
    This is a vulnerability on your cable modem. Not windows. you can do some bad stuff (DNS redirects, lock out network and WiFi etc), but you need to leverage a further vulnerability to access a machine.

    To be affected you need to go to a malicious website or click on a malicious advert.
    This in and of itself will not infect your machine with ransomware.


    Its also a bit much to accuse Virgin Media of gross negligence. This is a bug in the firmware from the manufacturer. VM dont manufacture their boxes. If VM don't issue a warning or if they don't contact customers once a fix has been found, then its a different story.


  • Moderators, Home & Garden Moderators, Technology & Internet Moderators Posts: 24,789 Mod ✭✭✭✭KoolKid


    Post edited please refrain from such wild accusations.


  • Posts: 0 [Deleted User]


    From the website:

    Cable Haunt is exploited in two steps. First, access to the vulnerable endpoint is gained through a client on the local network, such as a browser. Secondly the vulnerable endpoint is hit with a buffer overflow attack, which gives the attacker control of the modem.

    The first step starts on the local network. So the attacker has to already be on the inside of the network to launch the attack.

    In the words of Catherine Tate, Am I bovvered?


  • Closed Accounts Posts: 1,862 ✭✭✭un5byh7sqpd2x0


    From the website:

    Cable Haunt is exploited in two steps. First, access to the vulnerable endpoint is gained through a client on the local network, such as a browser. Secondly the vulnerable endpoint is hit with a buffer overflow attack, which gives the attacker control of the modem.

    The first step starts on the local network. So the attacker has to already be on the inside of the network to launch the attack.

    In the words of Catherine Tate, Am I bovvered?

    And from the OP....
    "A new malware has been discovered, which if used can allow anybody in the world to get into your cable modem and into your connected computer systems and read data, encrypt the data and ask you for bitcoin to decrypt the data, and stop your phone system."

    Why would you bother getting "into your cable modem and into your connected computer systems" when you've already pwned something on the inside to exploit the modem vulnerability in the first place?


  • Posts: 0 [Deleted User]


    And from the OP....
    "A new malware has been discovered, which if used can allow anybody in the world to get into your cable modem and into your connected computer systems and read data, encrypt the data and ask you for bitcoin to decrypt the data, and stop your phone system."

    Why would you bother getting "into your cable modem and into your connected computer systems" when you've already pwned something on the inside to exploit the modem vulnerability in the first place?

    Yea. I mean, it's a bit like saying, your car is at risk of theft if you leave your car keys on the hall table.

    Step one, the thief is in your hall
    Step two, he takes the keys and drives off in your car.


  • Advertisement
Advertisement