Over 250,000 Home Routers Found with Duplicate SSH Keys

  • 19 February 2015
  • 0 replies
  • 622 views

Userlevel 7
Badge +54
By Ionut Ilascu    19 Feb 2015
 
Most of them are deployed by Telefónica de España
 
http://i1-news.softpedia-static.com/images/news2/Over-250-000-Home-Routers-Found-with-Duplicate-SSH-Keys-473651-2.jpg
 
Starting from a search for one SSH fingerprint, a researcher has discovered that over 250,000 home routers share the same SSH key, allowing an attacker access to all the devices if the key is found.
 
Upon closer investigation, John Matherly, founder of Shodan search engine for Internet-connected devices, discovered that the routers were from Spain and ran a version of Dropbear SSH software package designed for embedded devices.

 

Mass configuration of the devices may be the cause

The Shodan results also revealed that most of the IP addresses of the routers belonged to Internet Service Provider (ISP) Telefónica de España.

“It appears that some of their networking equipment comes setup with SSH by default, and the manufacturer decided to re-use the same operating system image across all devices,” Matherly said in a blog post on Tuesday. Full Article

0 replies

Be the first to reply!

Reply