7 ms·
Backdoor in D-Link routers enables telnet access
- skilled 2y agoCVE-2024-6045 - https://nvd.nist.gov/vuln/detail/CVE-2024-6045 https://nvd.nist.gov/vuln/detail/CVE-2024-6045 > Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor. Unauthenticated attackers on the local area network can force the device to enable Telnet service by accessing a specific URL and can log in by using the administrator credentials obtained from analyzing the firmware.
- WhatsName 2y agoHow would anyone tell if this is not malicious in the first place? It quacks like a backdoor, looks like a backdoor...
- sph 2y agoOn security issues from massive Internet appliance vendors, you can safely assume it is malicious, though it might not have been placed there with knowledge of the vendor itself (i.e. it's very likely a state actor)
- consp 2y agoI much rather assume it's cost cutting in combination with poor testing practices. Which is also more likely.
- arp242 2y agoIf a state actor has access to your LAN you're all kinds of fucked already. They really don't need this crummy exploit for crummy home routers. It's pretty far-fetched to suspect a state actor, and outright ridiculously conspiratorial to say we can "safely assume" this.
- MaxikCZ 2y agoNoone said its "your state" actor.
- ndsipa_pomu 2y ago> If a state actor has access to your LAN you're all kinds of fucked already. Seems very likely that some IOT devices are connected to LANs and can be used for shenanigans which is why you shouldn't trust anything on your LAN and always require encryption/authentication. Having telnet available on a router is beyond stupid and outright malicious.
- mijoharas 2y agoHanlon's razor would disagree with you.
- colordrops 2y agoHanlons razor is used by the malicious to fool the stupid
- account42 2y agoThat's an opinion, not an argument.
- mijoharas 2y agoAgreed, as is the point I was responding to.
- remram 2y agoSomeone putting in a backdoor would have known it's a backdoor, and I feel like they would have done it better. For example, making sure the hardcoded password can't be recovered from the firmware.
- deleted 2y ago[deleted]
- pxeger1 2y ago*from the LAN side only
- WhatsName 2y agoA quick look at shodan and it's painfully obvious that these words mean very litte if the device is widely in use.
- n_plus_1_acc 2y agoIt's hilarious that they put this sentence on a page about a CVE: > This ensures that the software is of the highest quality and meets our stringent standards.
- belter 2y ago> D-Link will not be liable for any direct, indirect, special, or consequential loss suffered by any party due to their use of the beta firmware, beta software, or hit-fix release. We have a hardcoded password...but take the fix at your own risk.
- happycube 2y agoD-Link... has... software standards?
- Severian 2y agoSo, what is the count of D-Link exploits in their routers now? I swear there is at least 1-2 per year for as long as I can remember. Do they just hire some rando code monkeys with 0 security audits?
- coldtea 2y ago>Do they just hire some rando code monkeys with 0 security audits? They offer telnet access as a backdoor, so yes...
- Havoc 2y agoHow are router manufacturers so incompetent? They’ve been in the biz long enough to know that a security through obscurity back doors don’t hold. And yet this keeps happening.
- Hackbraten 2y agoHome routers aren’t exactly a high-margin industry. Manufacturers may not be willing to pay for developers who know what they’re doing.
- nickpeterson 2y agoThat or they get developers who know exactly what they’re doing…
- toyg 2y ago* codemonkey takes low salary from router manufacturer * codemonkey integrates it with low salary from $state_actor * codemonkey be happy, manufacturer be happy, state actor be happy - win-win!
- nickpeterson 2y agoI’m pretty sure you missed a step where “he gets up gets coffee”
- ahazred8ta 2y agoState actor have many banana.
- Havoc 2y agoDon’t leave mystery backdoors exposed internet side isn’t exactly advanced knowledge though
- arp242 2y agoIt's LAN side only. Not that this excuses things, but it's not internet side.
- deleted 2y ago[deleted]
- fred_39582 2y ago[dead]
- throwaway71271 2y agoI find it really hard to distinguish malice and incompetence in this case.
- Uptrenda 2y agoIs it me or are the standards for 'home routers' just basically horrible? I don't work as a security researcher or anything but in my time I've found multiple router vulnerabilities across manufactures. Everything from exposed admin interfaces (with default creds), issues with firewalls, UPnP accessible outside..., incredibly naïve credential management, its like home routers are swiss cheese by default. What do HN people tend to run that doesn't give them issues? I'd especially be interested in routers that have good IPv6 support (maybe impossible but still.)
- spydum 2y agoopnsense. you dont need to run these garbage consumer routers. downside is if your ISP still provides a modem/CPE. but some times you can put those into bridge mode and make them less of a risk
- WhackyIdeas 2y agoIs something like that really that necessary though, sure it has a lot of features but for a simple router it takes 15mins to follow a guide on openbsd.org to set up a simple router which works really well and is really secure.
- vladvasiliu 2y agoGiven GP's question, they're likely not someone who would spontaneously whip up an openbsd router. Maybe they don't care to fiddle with a command line, read up on dhcp servers, ipv6 router advertisements, pf configuration and what have you. In such a case, throwing opnsense on some machine, clicking around on three pages and calling it a day isn't that bad. The experience is close enough to an off-the-shelf router (except for the installation part), all the while getting a much better security situation.
- WhackyIdeas 2y agoI actually found it easier understanding the openbsd router than pfsense when I tried it. The abstraction confused me personally.
- ricktdotorg 2y agookay so, assuming this is malice vs. incompetence: surely D-Link would be able to pinpoint the code injection and ID the engineer who put in the backdoor (presumably paid by someone) right? what happens to that engineer? or are they already long-gone with their $$$
- toyg 2y agoSuch engineer probably made sure to note it was for testing purposes, like what was stated the last 47392 times this exact same problem was found in mass-produced network hardware. Now, the question is whether the subsequent failure to remove it was willing or not... That will be hard to ascertain, probably enough to keep them from firing the involved code monkey.
- bastard_op 2y agoNote to self: Warn everyone I know or run into using D-Link products to stop using them. I'm curious for more info like how long it was there.
- Erlangen 2y agoSimilar case with tp-link routers, https://websec.ca/publication/advisories/root-shell-tplink-wdr740 https://websec.ca/publication/advisories/root-shell-tplink-w...
- wiseguy317 2y agoIn 2012.
- markhahn 2y agoPLEASE start saying "D-Link firmware", since you can avoid this sort of silliness by just installing OpenWRT. How about another conversation: "Vendors are never trustworthy, so what to do?"
- tyingq 2y agoConfirmation that if you're going to use an inexpensive router, buy one that can run open software and run that instead. I understand this doesn't solve the broadest use case, but you can at least protect yourself.
- PaulKeeble 2y agoRun open source software on your router, don't buy one that doesn't support it. Every single company abandons support for the router in a few years at which point your destined to become part of a botnet or worse. Instead get an open source firmware and keep it up to date and not only will you have more features but it will also get security patches. Open source firmware routers have better features and support.
- e12e 2y ago> Confirmation that if you're going to use an inexpensive router Expensive is no panacea, remember eg?: https://www.rapid7.com/blog/post/2023/10/17/etr-cve-2023-20198-active-exploitation-of-cisco-ios-xe-zero-day-vulnerability/ https://www.rapid7.com/blog/post/2023/10/17/etr-cve-2023-201...
- tyingq 2y agoSure...I mention "inexpensive", because "expensive" and "open" aren't immune to zero days, but both have options to mitigate that via either paid or self-support. Where the inexpensive ones often have no real options in that situation.
- nimishk 2y agolaughs in openwrt
- deleted 2y ago[deleted]
- nerdjon 2y agoI have to wonder, in the US at least (I don't know if this trend is outside the US) most ISP's are selling devices that are both the modem and the router. Which I despise since it also means the ISP can change settings on my Router way too easily. Then customer support will often tell you how they can't support you using your own router (I use my own, I refuse to use theirs and it is currently in bridge mode). How are the Linksys, d-links, and others actually doing? I would have thought that that market to completely plummet. Which would lead to shortcuts and a lack of proper care.
- bcrl 2y agoIs anyone surprised after D-Link's previous settlement with the FTC? https://www.ftc.gov/news-events/news/press-releases/2019/07/d-link-agrees-make-security-enhancements-settle-ftc-litigation https://www.ftc.gov/news-events/news/press-releases/2019/07/...
- almazzz 2y ago[dead]