Author Topic: Blog: The Email that Hacks You (your router if default password not changed)  (Read 111 times)

Offline menotu

  • PCLinuxOS Tester
  • Super Villain
  • *******
  • Posts: 15288
  • ┌∩┐(◕_◕)┌∩┐
heise Security -30 November 2012,

A whole range of Arcor, Asus and TP-Link routers are vulnerable to being reconfigured remotely without authorisation. On his blog, security researcher Bogdan Calin demonstrates that just displaying an email within the router's own network can have far-reaching consequences: when opened, his specially crafted test email reconfigures the wireless router so that it redirects the user's internet data traffic. An attacker could exploit this to, for example, redirect unwitting users to a phishing site and harvest their details when they are trying to log into facebook.com.

The attack uses the Cross-Site Request Forgery (CSRF) technique. Calin embedded images whose source URL (src=) points to the router's default IP address (often 192.168.1.1) in his HTML test email. The URL contains parameters that instruct the router's web interface to modify the DNS server configuration. As the URL also contains the admin password for the web interface, the attack will only be successful if the user has left the default password unchanged. A full CSRF URL could look something like this:

http   ://  admin:password@   192.168.1.1/start_apply.htm?dnsserver=66.66.66.66

http://www.h-online.com/security/news/item/Email-hacks-router-1759874.html

Bogdan Calin Blog

The email that hacks you video
« Last Edit: December 05, 2012, 05:42:30 AM by menotu »
PCLinuxOS 32bit KDE 4.10.1; kernel-3.4.11-pclos1.bfs & 64bit 3.2.18bfs; NVidia GeForce 8400GS 1GB 310.19 driver

Sony Vaio SVE1513A4ESI Laptop, Intel Core i5, 2.6GHz, 6GB RAM, 750GB, 15.6" Intel HD Graphics 4000

Offline sling-shot

  • PCLinuxOS Tester
  • Hero Member
  • *******
  • Posts: 1730
  • Satyameva Jayate | Truth Alone Triumphs.
My router also needs that I enter a CAPTCHA for logging in. Will it protect me?
Packaging well will cure headaches of many :) But learning to package will cause headaches in many :(

AMD AthlonX2 3600+/ASUS M2NPV-VM/ATi HD4670/Onboard sound/3.5GB DDR2-533 RAM/SEAGATE 160+320GB HDD/DELL S2240L FullHD/Creative SBS370 2.1/PCLinuxOS2013/KDE4
Samsung NP305U1-A06IN | Nokia E6