On 26 May 2018, at 9:48 am, I <[email protected]> wrote:
> 
> >For those who came in late. Specifically mentions Linksys, MikroTik, Netgear 
> >Inc, TP-Link.
> >https://www.theguardian.com/technology/2018/may/25/router-hacking-russia-fbi
> >Paul Wilkins
> 
> There's more here
> https://blog.talosintelligence.com/2018/05/VPNFilter.html
> 
> Robert

TP-Link have made a statement and basically said their devices in support with 
latest firmware are not vulnerable. https://www.tp-link.com/au/faq-2213.html

Interestingly they make a special mention to disable the remote management 
feature unless it is absolutely necessary. I’m guessing this may have been one 
of the attack vectors used by VPNFilter to deliver the first stage payload. 
Like most things on your network, and especially your perimeter; if you don’t 
need it, turn it off!

Cheers,

James

Attachment: smime.p7s
Description: S/MIME cryptographic signature

_______________________________________________
AusNOG mailing list
[email protected]
http://lists.ausnog.net/mailman/listinfo/ausnog

Reply via email to