Showing posts with label D-Link Router. Show all posts
Showing posts with label D-Link Router. Show all posts

Thursday, 16 April 2015

Researcher: Security D-Link Routers Is Not Working


A security update that network manufacturer D-Link for different routers released just does not work and introduces a new vulnerability, so claims the researcher who discovered all kinds of vulnerabilities in the routers. Security Researcher Craig of the blog / dev / ttyS0 discovered early this year several vulnerabilities in the D-Link DIR-645 router, where D-Link finally released an update for.

Early this month, Craig found the same problems in the DIR-890L router. Yesterday, D-Link with a update for this model, which the researcher decided to check whether the problem also really been resolved. Craig discovered that the patches for the DIR-645 and DIR-890L are identical. To his surprise, they were all just problems still exist, even if D-Link says that the updates address vulnerabilities correct.

It also showed that the updates are also introducing a new security problem. Unused Authentic Weathered users can therefore still perform a variety of actions on the router. "But I think no matter it something that a authentication user information systems on the internal network can retrieve, view and change system settings can or router to the default settings can be reset," responds the investigator sarcastically.

Tuesday, 3 February 2015

D-Link Routers Vulnerable To DNS Hijacking


Different routers network manufacturer D-Link contains a vulnerability which can modify a remote attacker without credentials the DNS settings of the devices. This allows the attacker to the movement of the hacked router running through its servers, reports PC World .

The vulnerability is in the ZyNOS router firmware, developed by manufacturer ZyXEL. In addition to D-Link's firmware is also used by other manufacturers, including TP-Link and ZTE. Through the leak is possible to get without a valid username and password to access the administration interface. The problem is both an administrative interface that is directly accessible via the Internet as an interface that is only accessible locally. In the latter case an attacker to perform a CSRF attack.

Once access to the interface, the attacker could change the DNS settings. The Domain Name System (DNS) is similar to the directory and translates among other domain names into IP addresses. The DNS hijacking an attacker can manipulate the movement of users. It is believed that the leak in the D-Link DSL-2740R and the D-Link DLS 320B. Both models are sold in the Netherlands, where the DLS 320B still being offered.

Researcher Todor Donev, who noticed the problem reported this to manufacturer D-Link, so there is no update available yet.Moreover, the DSL-2740R is a phased model. Donev opposes Threat Post that other models are vulnerable, but he does not have the resources to test all affected devices. Meanwhile, he has also put an exploit online to demonstrate the attack.