Quantcast

Forums | MacLife

You are not logged in.

#1 2009-07-22 7:41 am

Bat
Flawless Cowboy
Royal Wombat
From: Björk, Björk
Registered: 2001-05-14
Posts: 28541

Open-source firmware vuln exposes wireless routers

Back door to complete control

A hacker has discovered a critical vulnerability in open-source firmware available for wireless routers made my Linksys and other manufacturers that allows attackers to remotely penetrate the device and take full control of it.

The remote root vulnerability affects the most recent version of DD-WRT, a piece of firmware many router users install to give their device capabilities not available by default. The bug allows unauthenticated users to remotely gain root access simply by luring someone on the local network to a malicious website.

"This means someone can even post some crafted [img] link on a forum and a dd-wrt router owner visiting the forum will get owned," a user named Leka Vecher "gat3way" wrote in this posting to Milw0rm. "A weird vulnerability you're unlikely to see in 2009 smile Quite embarrassing I would say."

Messages sent through the DD-WRT website to the software designers weren't returned by time of publication, but comments posted to this user forum thread said the vulnerability affected the most recent builds, prompting a user by the name of autobot to declare the vulnerability a "mini code red."
..

Update
DD-WRT developer Sebastian Gottschall just emailed to say an interim fix is available here. "Consider that this exploit was released without any Report to us," he added.

http://www.theregister.co.uk/2009/07/21 … uter_vuln/


If all economists were laid end to end, they would not reach a conclusion - George Bernard Shaw

"Fire up a colortini, sit back, relax, and watch the pictures, now, as they fly through the air."

Offline

 

Board footer

Powered by PunBB 1.2.6
© Copyright 2002–2005 Rickard Andersson