[ISN] A better reason not to use Huawei routers: Code from the '90s

From: InfoSec News <alerts_at_private>
Date: Thu, 11 Oct 2012 02:24:17 -0500 (CDT)
http://www.networkworld.com/news/2012/101012-a-better-reason-not-to-263231.html

By Jeremy Kirk
IDG News Service
October 10, 2012

Security researcher Felix "FX" Lindner has a more compelling reason to 
steer clear of routers from Huawei Technologies than fears about its 
ownership.

While the company blasted for its opaque relationship with China's 
government in a U.S. intelligence report released Monday, a bigger worry 
for some is what's inside its routers.

"The code quality is pretty much from the '90s," said Lindner, who has 
analyzed the software inside Huawei's home and enterprise routers, and 
runs Recurity Labs, a security consultancy, in Berlin.

Lindner will speak on Thursday at the Hack in the Box security 
conference in Kuala Lumpur and discuss some of the vulnerabilities he 
and a fellow researcher disclosed earlier this year along with an 
overview of Huawei's security.

When Lindner began looking at Huawei's routers, the company didn't have 
a prominent product security team, Lindner said. But since he and 
colleague Gregor Kopf detailed vulnerabilities in the firmware of 
Huawei's AR18 series routers, which are meant for homes, and its AR29 
series routers, intended for small enterprises, at the Defcon conference 
in July, "they seem to be trying to ramp up product security in a 
visible way right now," he said.

[...]


--
Get your CEH, CISSP or ISSMP with ExpandingSecurity.com Live OnLine classes that will not wreck your schedule.
Come to a free class and see how good our program really is. Free weekly PainPill: http://www.expandingsecurity.com/PainPill
Received on Thu Oct 11 2012 - 00:24:17 PDT

This archive was generated by hypermail 2.2.0 : Thu Oct 11 2012 - 00:19:40 PDT