Jump to content
OpenSecurity.global
  • Recently Browsing   0 members

    No registered users viewing this page.

Sign in to follow this  
Tim Casey

"Commercial grade" Layer 7 Routers - What now?

Recommended Posts

You may have heard research from IBM's X-Force ISIS on Magecart's attacks on "commercial-grade layer 7 (L7) routers .... typically used by airports, casinos, hotels and resorts, to name a few." (https://securityintelligence.com/posts/leading-magecart-group-targeting-captive-wi-fi-users-via-l7-routers/)

I have a CCNA and never heard of "commercial grade" routers, so thought I would look for some.

The closest product I came up with in my search was Cisco's Meraki. https://meraki.cisco.com/solutions/hospitality. BTW, has a bluetooth low engergy beacon traffic tracking, which has some privacy implications. "How long did guests spend at the lobby bar this past week, and how many spent over an hour at the hotel restaurant last Thursday?" Wow. And Login into Wifi with Facebook. What could go wrong. Anyway it has an API, maybe this is what MG5 is attacking: https://meraki.cisco.com/solutions/location_analytics. This link has a few sub links with access to more detailed information.

Anyway, usually when we hear about Layer7 is tracking app use on a network or load balancing. Many Cisco products have this feature. But I don't think that is what X-Force is talking about. 

It would nice if IBM would release more information, if you want the report you have to enter your business info (there is a link at the bottom of the first link above).

Share this post


Link to post

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
Sign in to follow this  

  • Members online now

    No members to show

  • Similar Content

×
×
  • Create New...

Important Information

We use cookies as we're cookie monsters. Privacy Policy