If you ever find yourself locked out of your Linksys router don't worry. Resetting a Linksys router back to it's default factory configuration is easy.
#1 - Prepare for the reset by removing any Ethernet connections attached to the router.
#2 - Locate the reset button on the back of the router. If you press and release the reset button the router restarts.
#3 - Press and hold the reset button while you count to 10. At "10" continue pressing the switch and turn off the power to the router (turn off the switch or pull the power plug). Count to 10 again. Turn the power back on. When any of the LEDs (lights) on the front of the router turn on (the power LED should turn on first) then let go of the reset button.
#4 - Connect one PC back to the Linksys router via the Ethernet. This PC should be set up to acquire an IP address via DHCP. After connecting the PC it should have an IP address with 30 seconds. You can check to see if the PC has an IP address using the command "IPCONFIG" at a DOS prompt. By default the Linksys will set it's IP address to 192.168.1.1. You can verify this by typing "IPCONFIG" and looking at the IP address of the default gateway (it should be 192.168.1.1).
#5 - Open a browser and enter the URL "http://192.168.1.1" (without the quotes). If asked for a username leave that field blank. If asked for a password enter "admin".
# 6 - The first thing you should do is to change the default password on the Linksys router. The next thing is write the new password down. If you've lost or forgotten the password for your router let me suggest taping the new password to the bottom of the unit. This is not the most secure means of recording this information; but if your router is locked inside your house you have already removed much of the associated risk.
#7 - The next thing you should do is check the Linksys web site to find out if you are running the latest version of Linksys firmware.
"On the Firewall" is a online journal on the subject of network Firewalls and all things Internet security.
September 28, 2005
December 26, 2004
Under attack Linux Lives Longer?
Just a few days after the release of the USA Today / Avantgarde study about how long an unprotected PC might survive on a network before experiencing a variety of un-targeted attacks; the folks at the Honeynet Project released the results of a similar study that looks at the "time to live" for various Linux distributions. The study finds that Most Linux PCs are much less vulnerable to attack than PCs running Microsoft operating system products. The study suggests that a Linux PC could last up to 3 months on the Internet without being compromised.
I don't think there is any "me too" factor here. The folks over at the Honeynet Project have been doing their work and producing good results for several years. Even though these latest results were published a couple of days after the USA Today study there are clear differences in the work.
The title of the Honeynet Project report is "Know Your Enemy - Trend Analysis". The Honeynet folks did a much more thoughtful job of looking at the various Linux distributions that were out there and talking about where the problems are. The reality seems to be that the older Linux distributions that #1 turned on more services by default, and #2 have more documented vulnerabilities simply because they have been around longer are more vulnerable to un-targeted attacks.
An interesting note (#2) in the section of the "Know Your Enemy" or KYE study titled 'Reasons" was the rise in network based phishing (social engineering) attacks where the target isn't the asset (the PC) but the personal data on the PC or the personal information of the user.
I don't think there is any "me too" factor here. The folks over at the Honeynet Project have been doing their work and producing good results for several years. Even though these latest results were published a couple of days after the USA Today study there are clear differences in the work.
The title of the Honeynet Project report is "Know Your Enemy - Trend Analysis". The Honeynet folks did a much more thoughtful job of looking at the various Linux distributions that were out there and talking about where the problems are. The reality seems to be that the older Linux distributions that #1 turned on more services by default, and #2 have more documented vulnerabilities simply because they have been around longer are more vulnerable to un-targeted attacks.
An interesting note (#2) in the section of the "Know Your Enemy" or KYE study titled 'Reasons" was the rise in network based phishing (social engineering) attacks where the target isn't the asset (the PC) but the personal data on the PC or the personal information of the user.
December 14, 2004
How long can a PC survive on the Net?
USA Today recently sponsored some testing to determine how long various types of unprotected PCs could survive on the Internet. In at l;east one instance an unprotected PC running Windows XP was broken in to within 4 minutes of being started and attached to the Internet. It should be clear to all that this type of research is valuable in a couple of ways.
First off for USA Today it sells lots of papers and results in many, many hits at their web site. When a news outlet like USA Today gets behind a study like this many, many people will be able to get to the results.
Avantgarde, the Marketing and Design company that published the results of the "Time to Live on the Network" study did a first rate job. The published results of the joint study that were published at the Avantgarde website show that they did a very reasonable tests and they didn't suffer from any predetermined Windows bias. A Linux distribution (OK, but not one that I'm familiar with or would have suggested) was also used as part of this study. With that said the folks over at Avantgarde should also see much more traffic at their web site and probably more business.
Lost in the noise about the study results is the fact that Kevin Mitnick is credited as having participated in this study as one of the principal investigators. Many folks in the computer security business take issue with hackers who have been convicted of a crime later making there way back into the security business. I'm glad to see that Kevin put his skills to good work here and produced good solid work without making it all about a former hacker.
It should be noted that the PCs that did the best in this study had some sort of Firewall installed.
So where is the beef here? Hopefully the most important result of this study will be all the folks who see the headline and read the article in USA Today who are going to learn something about how bad the security of an unprotected PC really is. This work is another data point that highlights the problems of untargeted attacks over the Internet. It's up to users of PCs and developers of PC operating systems and security products to put the data together to realize the size and scope of the problem and work harder to it's resolution.
First off for USA Today it sells lots of papers and results in many, many hits at their web site. When a news outlet like USA Today gets behind a study like this many, many people will be able to get to the results.
Avantgarde, the Marketing and Design company that published the results of the "Time to Live on the Network" study did a first rate job. The published results of the joint study that were published at the Avantgarde website show that they did a very reasonable tests and they didn't suffer from any predetermined Windows bias. A Linux distribution (OK, but not one that I'm familiar with or would have suggested) was also used as part of this study. With that said the folks over at Avantgarde should also see much more traffic at their web site and probably more business.
Lost in the noise about the study results is the fact that Kevin Mitnick is credited as having participated in this study as one of the principal investigators. Many folks in the computer security business take issue with hackers who have been convicted of a crime later making there way back into the security business. I'm glad to see that Kevin put his skills to good work here and produced good solid work without making it all about a former hacker.
It should be noted that the PCs that did the best in this study had some sort of Firewall installed.
So where is the beef here? Hopefully the most important result of this study will be all the folks who see the headline and read the article in USA Today who are going to learn something about how bad the security of an unprotected PC really is. This work is another data point that highlights the problems of untargeted attacks over the Internet. It's up to users of PCs and developers of PC operating systems and security products to put the data together to realize the size and scope of the problem and work harder to it's resolution.
November 26, 2004
Scoble on Firefox and Security
Robert Scoble of Microsoft writes a great blog that I read regularly. I was catching up this evening and noticed an entry titled "Sticking it to the man Firefox style". One of the things that Rob has learned from Firefox was: "3) Security -- or the perception of having security -- is now a driver. It's why Microsoft is spending so much time on security now.". I can't help wonder if in the marketplace the perception of security is actually more important than actually be able to provide security in a product.
Worthless freeware?: Linksys Log Viewer
I'm looking at a number of the log tools available for a couple of different Firewall products. I'm trying to determine how useful these tools are in determining what the Firewall is providing in the way of protection. I'm currently using the Linksys BEFSX41 Firewall / router.
The first log tool I decided to look at was included on the Linksys products install CD. Linksys bundles a program called Logviewer and also makes the program available for download from the support section of their website. The program installs in seconds on a Windows PC and on execution shows up in the task bar.
When you run this program it displays a window on the screen with tabs to separate the view of incoming and outgoing traffic. The program doesn't seem to allow incoming and outgoing traffic to be viewed on the screen at the same time.
The biggest problem I had was getting this program to actually display all the information that it captured in its window. I could not re-size the Logviewer window and there was no option of going full screen. The program doesn't have a command bar. I could change the size of each of the columns. I wound up making the date and time columns really small and unreadable in order to be able to read the destination port column (that includes what was done to the packets).
I thought that maybe the version of this program that I retrieved from the CD was old. Just in case I downloaded and installed the utility from the Linksys support pages. Alas, there was no version number listed for Logviewer at the web site or in the filename.
About all I can say is that using Logviewer you will be able to figure out if the Linksys device is sending data to the log host. Since Logviewer can't get the most basic data fields up on to the screen at the same time it's not really very useful for trying to visually analyze what's going on at the Firewall.
The first log tool I decided to look at was included on the Linksys products install CD. Linksys bundles a program called Logviewer and also makes the program available for download from the support section of their website. The program installs in seconds on a Windows PC and on execution shows up in the task bar.
When you run this program it displays a window on the screen with tabs to separate the view of incoming and outgoing traffic. The program doesn't seem to allow incoming and outgoing traffic to be viewed on the screen at the same time.
The biggest problem I had was getting this program to actually display all the information that it captured in its window. I could not re-size the Logviewer window and there was no option of going full screen. The program doesn't have a command bar. I could change the size of each of the columns. I wound up making the date and time columns really small and unreadable in order to be able to read the destination port column (that includes what was done to the packets).
I thought that maybe the version of this program that I retrieved from the CD was old. Just in case I downloaded and installed the utility from the Linksys support pages. Alas, there was no version number listed for Logviewer at the web site or in the filename.
About all I can say is that using Logviewer you will be able to figure out if the Linksys device is sending data to the log host. Since Logviewer can't get the most basic data fields up on to the screen at the same time it's not really very useful for trying to visually analyze what's going on at the Firewall.
November 24, 2004
Linksys and the blinking LED
If anyone else out there in the world is using a Linksys BEFW11S4 router (4 ports 10/100 with a 802.11B wireless access point) to connect to the Internet and you notice that it's not working properly take a look at the "power" LED on the front of the device. Apparently this can happen to just about any Linksys router. If that LED is blinking it means that the router was not able to load the firmware that the device needs to operate. The remedy is to reset the router by turning it on and holding the reset button down for 30 seconds. Then you connect to the Linksys from a PC with a fixed IP address in the 192.168.1.2 to 192.168.1.10 range. From that PC you should be able to ping the router at 192.168.1.1 and get a response. If not the unit is probably toast. If the ping succeeds then use the Linksys firmware installation (TFTP) utility with the default password of "admin" to load new a firmware image. Linksys support covers the issue here.
Be careful of a couple of things here. When we first noticed the problem one computer was able to connect to the Internet. The Linksys router had given that PC the ISP DHCP provided IP address. As far as I could tell that PC was on the Internet totally unprotected by the Linksys device.
I also noted that the Linksys support site points out that you can connect your PC directly to the Internet in order to retrieve the firmware image and firmware update utility. Be careful in that directly connected configuration to either disconnect or power off when you are not using the Internet to minimize the risk of attack.
Be careful of a couple of things here. When we first noticed the problem one computer was able to connect to the Internet. The Linksys router had given that PC the ISP DHCP provided IP address. As far as I could tell that PC was on the Internet totally unprotected by the Linksys device.
I also noted that the Linksys support site points out that you can connect your PC directly to the Internet in order to retrieve the firmware image and firmware update utility. Be careful in that directly connected configuration to either disconnect or power off when you are not using the Internet to minimize the risk of attack.
November 20, 2004
Application Firewalls Vendors Challenge, Part 2
After my previous blog post I received an email from one of the firms that I had described based on reading several articles as developing this new application Firewall test criteria. The message pointed out that there were two factual errors in my previous post.
The claimed first error was that this group has posted their criteria. I checked the InfoWorld article that I had based much of my entry on and there was no pointer to the criteria file there. I also looked at articles on the topic that appeared in both eWeek and SC Magazine and could not find any reference to where I might find the criteria in those articles either.
The second claimed error was that these vendors don't call themselves a consortium. I took a quick look at the InfoWorld article and it said:
In was provided with a link to the proposed criteria document. The criteria that the group has published was reported to be "a baseline standard for application security firewalls", again according to reporting in InfoWorld. The actual title of the document is "Web Application Security Minimum Protection Criteria". The document has no author, no date, and no copyright mark and I couldn't find a link to it from anywhere else on ICSA Labs site. Given the lack of any of this info I chose not to link this entry to that document.
My suggestion is that if you want to stop application layer attacks you need to develop a good security policy that can be implemented on your network that meets your objectives given a reasonable risk of operation. There is no silver bullet.
The claimed first error was that this group has posted their criteria. I checked the InfoWorld article that I had based much of my entry on and there was no pointer to the criteria file there. I also looked at articles on the topic that appeared in both eWeek and SC Magazine and could not find any reference to where I might find the criteria in those articles either.
The second claimed error was that these vendors don't call themselves a consortium. I took a quick look at the InfoWorld article and it said:
"At the Computer Security Institutes Annual Security Conference, F5 Networks, Imperva, NetContinuum, and Teros announced the Application Security Consortium, saying the group wanted to establish minimum standards for application security software through independent testing."If you're not calling yourself a consortium I'm sorry but it would seem InfoWorld got it wrong.
In was provided with a link to the proposed criteria document. The criteria that the group has published was reported to be "a baseline standard for application security firewalls", again according to reporting in InfoWorld. The actual title of the document is "Web Application Security Minimum Protection Criteria". The document has no author, no date, and no copyright mark and I couldn't find a link to it from anywhere else on ICSA Labs site. Given the lack of any of this info I chose not to link this entry to that document.
My suggestion is that if you want to stop application layer attacks you need to develop a good security policy that can be implemented on your network that meets your objectives given a reasonable risk of operation. There is no silver bullet.
Microsoft says Firewalls failing to keep out hackers
This is possibly a future classic... It seems that a Microsoft security technology architect named Fred Baumhardt was ripping "Firewalls" at a technology briefing on the need for next generation Firewalls.
"We are all bloody lucky that something hasn't obliterated IT on earth," said Baumhardt. "Firewalls are like retarded routers. They just look at the ports, sources and destinations they like. If a train comes from Gare du Nord [Paris] to Waterloo [London] via Eurostar you allow it to enter the country because you trust it. That's what firewalls currently do. They don't check to see if al-Quaeda is riding inside."
I think Fred is trivializing what is perhaps the most common security problem faced by anyone with an Internet connection. Even Microsoft's own Internet Connection Firewall (ICF) does more than this (but in the case of ICF not much). Which begs the question to Fred; what is Microsoft going to do to address this?
"We are all bloody lucky that something hasn't obliterated IT on earth," said Baumhardt. "Firewalls are like retarded routers. They just look at the ports, sources and destinations they like. If a train comes from Gare du Nord [Paris] to Waterloo [London] via Eurostar you allow it to enter the country because you trust it. That's what firewalls currently do. They don't check to see if al-Quaeda is riding inside."
I think Fred is trivializing what is perhaps the most common security problem faced by anyone with an Internet connection. Even Microsoft's own Internet Connection Firewall (ICF) does more than this (but in the case of ICF not much). Which begs the question to Fred; what is Microsoft going to do to address this?
Subscribe to:
Posts (Atom)