Saturday, April 15, 2006

If you want something done right do it yourself 

There have been way too many incidents like this.

Netgear makes a box for plugging into a DSL line which shared your connection among multiple computers, and which also shares it over a wireless network. They make lots of boxes like that, but the one we're talking about today is the NETGEAR WGT624 Wireless DSL router.

Someone who goes by the handle "Tranceformer" just discovered that no matter what password you set to secure the WGT624, there's still something in the device's configuration that looks like this:
super_username=Gearguy
super_passwd=Geardog

People on the hostile side of your firewall can use this to log in and change settings.

In any normal industry you'd get a recall notice.

If there's a manufacturer of cheap firewall appliances who gives a *&(&^%! about security, I wish they'd advertise it. Meantime I'm stuck trying to figure out what to recommend. There have been a lot of problems just like this one and they've shown up in multiple brands.

Maybe the only hope is to take a spare computer, put in a second network card, and install some respectable free firewall and security software.

|

This page is powered by Blogger. Isn't yours?