USB3.0 02

Default settings leave exposed external hard drives connected to an Asus router

USB3.0_02

Data on thousands of hard drives connected to its router Asus are easily accessible from the Internet due to unsafe default settings, according to tests conducted by PC World Norway specialists.

The Routers with USB ports that allow users to connect external hard drives directly to the router are becoming more and more common. Shared space accessible over the internet using protocols such as FTP is quite useful but has significant security risks.

If the products are not set up correctly, personal data is exposed to anyone with basic technical knowledge. Several incidents have already been reported with people using its router Asus.

The it starts with how the routers are configured. Access to an external hard drive, which is connected via USB to a router using FTP, can be enabled manually or using the wizard. In both cases, however, they leave the router exposed.

The wizard lets the user choose between 3 settings, the default unlimited access with options for permissions, limited access and admin permissions, with little information on what each one means. Also, limited access permissions include an option that creates a user named 'family' and suggests the family password instead of asking each user to create their own password.

This issue affects users worldwide including users in the US. The strange thing is that these routers passed all the tests which Asus uses without any problem.

To solve the problem the company develops a firmware update which will be distributed worldwide thus making the security settings clearer.

 

We thank her warmly SecTeam  @Walkin.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).