5 ms·
Definitely a bug, but don't you have to log in to the administrative interface to access those forms in the first place? On D-Link routers I've played with, tha
by erydo 15y ago
Definitely a bug, but don't you have to log in to the administrative interface to access those forms in the first place? On D-Link routers I've played with, that interface was password protected and was the mechanism for uploading new firmware anyway.
- JoachimSchipper 15y agoIIRC, the exploit goes like this: get the victim to log in on their router (typically HTTP Basic auth) and convince them to go to a site that contains e.g. <img src="http://192.168.0.1/admin.cgi?remote_admin=1&passwd=foo&confirm_passwd=foo"> or <img src="http://192.168.0.1/ping.cgi?addr=\"127.0.0.1`rm -rf /`\""> Not the most convenient attack, but hardly impossible.
- ck2 15y agoThis is why at a minimum you should change your ports to non-standard - it may only be temporary security by obscurity but it will at least prevent basic script-kiddie attacks. nonce required is another good layer
- skrebbel 15y agoI'm sure there are similar devices that make the same mistakes even for the login screen. For me, this article isn't so much about this particular device, but more a very clear and illustrative guide to how easy it is to get root access to many little linux-driven devices.
- 1880 15y agoFTA: "since Web access requires authentication, this bug might be exploitable by administrators only, so it is only useful for people who would like to gain a shell on their own systems"
- throwaway32 15y agoPlenty of web interfaces on routers have VERY poor security, a bug that gives you access to the web interface may have just given you a shell aswell.
- jarrett 15y agoRealistic attack scenario: Create a web site with user-friendly instructions on configuring your router for popular games. (Port forwarding, etc..) Hustle for good Google rankings. For each game, have an instruction sheet. Each instruction sheet is two pages long. The first page tells you how to log into your router. The second page contains the malicious <img> tag as described by JoachimSchipper, as well as genuine instructions to complete your router config. (If you want to hit multiple router firmwares, just include multiple <img> tags, each with its own parameters.) From there, you can gain remote admin access to the router. Presumably, you'd want to automate whatever you're doing to people. So, after people visit the second instruction page, run a script that reconfigures the router however you please. At this point, the sky's the limit, but might I suggest uploading your own firmware such as DD-WRT. From there, you could do all kinds of things, from the silly (replacing all downloaded images with kittens) to the nefarious (stealing passwords on all non-SSL sites). Standard disclaimer: I'm not writing this to help the bad guys. They already know what to do. This is food for thought for the good guys.
- shabble 15y agoI daresay if you included "...and you'll need to add this certificate to your browser..." you could get a good number of people installing your Totally Trustworthy Root Cert(tm) and do a bit of HTTPS MitM as well. Makes it more likely someone will notice and you'll get flagged though I suppose.
- ma2rten 15y agoWhat would be even easier and more evil is to inject some backdoor into every (non ssl) executable download. Then you can just install a keylogger or patch the browser or whatever else you please.
- jarrett 15y agoYou're right. I hadn't thought of that, but it strikes me as one of the nastier attacks I've heard of in a while. Just think of how many downloadable packages require root privileges to install.