Network equipment in a business on the secondary market includes sensitive data , which hackers can use to breach the corporate environment and obtain customer information
See also: APT28 hackers target Cisco routers with new malware

Researchers examined several used corporate routers and found that most of them were not properly disposed of during the decommissioning process and were then sold online.
Cybersecurity firm ESET purchased 18 used basic routers and found that full configuration data was still accessible on more than half of them, which were working properly. This makes them easy targets for hackers.
Core routers are essentially the central device in a large network, as they connect all the other devices on the network. These products support many different data communication interfaces and are specifically designed to be able to transfer IP packets at very high speeds.
Initially, the ESET research team purchased used routers to create a test environment. Upon evaluating these routers, they found that they had not been properly cleaned and still contained network configuration data, as well as information that helped identify the previous owners. The equipment purchased included four Cisco devices (ASA 5500), three Fortinet devices (Fortigate series), and 11 Juniper Networks devices (SRX Series Services Gateway).
According to a report this week by Cameron Camp and Tony Anscombe, one device was not working when it arrived for testing and was excluded from the tests. Of the remaining 16 devices, only 5 were properly cleaned, while only 2 had been hardened, making some of the data difficult to access.
See also: Ongoing Hiatus hacking campaign infects business routers

For most people, it was possible to access the full configuration information. This includes detailed information about the system owner, how the network was set up, and the connections between the various systems.
To securely erase and restore the configuration on corporate network devices , an administrator must run certain commands. Without this, routers can be booted into recovery mode, which allows control over how they are configured
The researchers reported that some of the routers retained customer information, which allowed hackers to connect to the network, even with credentials that granted them access to other networks as trusted users. In addition, eight of the nine routers exhibited full configuration data that included router authentication keys in various hashed forms.
The list of corporate secrets was expanded to include full maps of sensitive applications hosted on-premises or in the cloud. Some examples of technology applications include Microsoft Exchange, Salesforce, SharePoint, Spiceworks, VMware Horizon , and SQL.
Following their findings, the researchers emphasize the importance of properly cleaning network devices before disposing of them. Companies should implement procedures for the safe disposal and destruction of their digital equipment.
The researchers warn that it's not always a good idea to use service for this activity. After informing the owner of one router of their findings, they determined that the company had used such a service. "The use of the service did not unfold as planned," the researchers say.
See also: Cisco warns of critical vulnerability in EoL routers
The advice is to follow the device manufacturer's instructions for cleaning the equipment of potentially sensitive data and restoring it to the original state it had when it left the factory.
