| Recent Featured Videos and Articles | Eastern “Orthodoxy” Refuted | How To Avoid Sin | The Antichrist Identified! | What Fake Christians Get Wrong About Ephesians | Why So Many Can't Believe | “Magicians” Prove A Spiritual World Exists | Amazing Evidence For God | News Links |
| Vatican II “Catholic” Church Exposed | Steps To Convert | Outside The Church There Is No Salvation | E-Exchanges | The Holy Rosary | Padre Pio | Traditional Catholic Issues And Groups | Help Save Souls: Donate | ![]() |
Cyber Group Finds Surveillance Backdoors In Routers Sold In U.S.
Chinese law requires telecom and internet companies to provide technical assistance to police and state-security agencies.
In an Aug. 27 report, cybersecurity firm VulnCheck said it found two hidden programs in an $88 router bought through Amazon from a U.S. seller. One, which the researchers named Speakingstone, sends information about the router to a remote server and can receive instructions to redirect internet traffic, obtain login credentials, or take control of the device.
The second, named Darklantern, can allow someone on the internet to take control of an affected router without a password, VulnCheck said.
The researchers then found both programs operating on routers already connected to the internet.
The findings expand VulnCheck's Aug. 5 investigation, which involved a different Zbtlink backdoor, named ENDLESSDOORS, found across more than 20 router models sold worldwide.
The newly discovered backdoors are older. VulnCheck found them in router software dating to 2019, years before ENDLESSDOORS was disclosed.
Speakingstone was not simply dormant code sitting inside old router software. It was still running...
Speakingstone gave whoever controlled its remote server broad access to an affected router.
VulnCheck said an operator could collect information about the device, obtain the credentials it used to connect to the internet, redirect internet traffic, and take control of the router. Its security advisory also says the software can open another path for remote access.
Baines described Speakingstone in his Aug. 27 post as software that "phones home to ZBT infrastructure and supports remote surveillance." ZBT refers to Shenzhen Zhibotong Electronics, the Chinese networking equipment manufacturer known as Zbtlink.
The software was built into the router rather than installed later by an outside hacker, according to VulnCheck.
Darklantern provided another path into affected devices. VulnCheck said someone who could reach one of the routers over the internet could take control without supplying a valid password, according to its advisory.
Jeremiah Ford, a senior cloud support engineer with 25 years of experience in information technology, said the most serious issue was that the routers exposed administrator-level access directly to the public internet.
"This is the biggest problem," Ford said.
He said full control of a router could also give an attacker access to other devices on the same network.
Ford called the scale of the exposure significant, pointing to VulnCheck's finding that every detected Darklantern device offered administrator-level access without authentication.
"This is huge," he said. "And based on the numbers of devices affected by this, the scale could have been huge, if it went undetected."
The U.S. exposure extended beyond the single router the researchers bought on Amazon.
Sign up for our free e-mail list to see future vaticancatholic.com videos and articles.
Recent Content
^