This article is from the source 'bbc' and was first published or seen on . It last changed over 40 days ago and won't be checked again for changes.

You can find the current article at its original source at http://www.bbc.co.uk/news/technology-34491583

The article has changed 3 times. There is an RSS feed of changes available.

Version 0 Version 1
Netgear router exploit detected Netgear router exploit detected
(about 17 hours later)
A security researcher in the US has said his Netgear router was hacked after attackers exploited a flaw in the machine.A security researcher in the US has said his Netgear router was hacked after attackers exploited a flaw in the machine.
Joe Giron told the BBC that he discovered altered admin settings on his personal router on 28 September.Joe Giron told the BBC that he discovered altered admin settings on his personal router on 28 September.
The compromised router was hacked to send web browsing data to a malicious internet address.The compromised router was hacked to send web browsing data to a malicious internet address.
Netgear says the vulnerability is "serious" but affects fewer than 5,000 devices.Netgear says the vulnerability is "serious" but affects fewer than 5,000 devices.
Mr Giron found that the Domain Name System (DNS) settings on his router had been changed to a suspicious IP address.Mr Giron found that the Domain Name System (DNS) settings on his router had been changed to a suspicious IP address.
"Normally I set mine to Google's [IP address] and it wasn't that, it was something else," he said."Normally I set mine to Google's [IP address] and it wasn't that, it was something else," he said.
"For two or three days all my DNS traffic was being sent over to them.""For two or three days all my DNS traffic was being sent over to them."
This means that the attacker could have tracked what websites Mr Giron was visiting, or even redirected him to malicious sites had they chosen to do so.This means that the attacker could have tracked what websites Mr Giron was visiting, or even redirected him to malicious sites had they chosen to do so.
He has decided to turn off the router and not use it for the time being.He has decided to turn off the router and not use it for the time being.
'Serious' bug'Serious' bug
The vulnerability itself has been documented by security researchers at Compass Security and Shellshock Labs in recent months.The vulnerability itself has been documented by security researchers at Compass Security and Shellshock Labs in recent months.
"Is it serious? Yes it definitely is," said Jonathan Wu, senior director of product management at Netgear, one of the top three router brands in the US."Is it serious? Yes it definitely is," said Jonathan Wu, senior director of product management at Netgear, one of the top three router brands in the US.
"Because whenever anybody gets access to your router, they can alter settings to direct traffic to places you don't want it to go to.""Because whenever anybody gets access to your router, they can alter settings to direct traffic to places you don't want it to go to."
However, Mr Wu added that attackers would have to get access to the network first and then guess the admin password. The vulnerability allows attackers to gain access to the router settings without needing to provide login credentials, according to security researchers Daniel Haake and Alexandre Herzog of Compass Security in Switzerland.
Mr Giron thinks that in his case, access was gained because his router settings had been configured so that they could be accessed remotely. Mr Giron thinks that in his case, access was gained remotely because his router settings had been configured so that they could be accessed from outside his network.
Imminent patchImminent patch
While a patch has not been available for the firmware on the affected devices to date, Netgear has confirmed to the BBC that one will be released on 14 October.While a patch has not been available for the firmware on the affected devices to date, Netgear has confirmed to the BBC that one will be released on 14 October.
Mr Wu said that Netgear router owners would be prompted to update their firmware if they logged into their router's admin settings or if they had the Netgear genie app installed on their computer, tablet or smartphone.Mr Wu said that Netgear router owners would be prompted to update their firmware if they logged into their router's admin settings or if they had the Netgear genie app installed on their computer, tablet or smartphone.
It's problematic that firmware updates can't be automatically "pushed" to routers, according to Mark James, IT security specialist at Eset.It's problematic that firmware updates can't be automatically "pushed" to routers, according to Mark James, IT security specialist at Eset.
"The average user will throw the router in place and just use it," he told the BBC."The average user will throw the router in place and just use it," he told the BBC.
"The biggest problem that we have with these types of scenarios are people don't keep the software up-to-date.""The biggest problem that we have with these types of scenarios are people don't keep the software up-to-date."
What's more, anti-virus software for computers doesn't generally cover vulnerabilities on routers meaning that it would not detect such problems.What's more, anti-virus software for computers doesn't generally cover vulnerabilities on routers meaning that it would not detect such problems.