D-Link Routers Vulnerable to 'Backdoor' Exploit
Up to ten different router models, including some by popular manufacturer D-Link, are now vulnerable to hackers. It appears the code that runs the devices contains a master password that anyone could find and use.
The problem was discovered by security researcher Craig Heffner, who admitted he had nothing more exciting to do on a Saturday than nose through code accompanying a recent firmware update for his D-Link DIR-100 router.
Like most routers, the settings menu for the D-100 router is accessible through a web browser -- the idea being that the user can access the router through one of many devices on his or her wireless network.
Secret Code Bypasses Router Password System
Normally the user has to type in a user name and password to access the router settings. However, Heffner discovered that it's possible to get access without entering the login details by changing the user agent string to a specific string of characters actually listed in the code.
The user agent string is information a web browser sends to a website to tell it what browser the user's computer is running. Although it's normally sent automatically, it's possible to add it manually at the end of a website address, such as the one used to access a router.
On further examination, Heffner discovered the code would work on several other D-Link routers, plus two made by Planex.
Hidden Code Allows Entry Via "Backdoor"
Including the string of characters in the firmware code (and thus making them accessible to anyone with the right technical knowledge) is no accident. Heffner noted that among the string of characters was the term "roodkcab", which reversed says "backdoor". (Source: itworld.com)
"Backdoor" is a computing term used by software designers who create a system with some form of security barrier but include a secret code that allows them to quickly get back into the system, if need be. That can cause problems if, as has happened here, the backdoor is too easy to discover.
Heffner says the code is open to abuse. Somebody who was able to remotely access a router could alter its settings to redirect all Internet traffic, allowing them to read everything a user sent over the Internet unless it had been encrypted (as happens with secure websites).
D-Link says it is carrying out a full review and has already issued a temporary security patch at its website, pending a complete update to the firmware. It's also warned users to ignore any unsolicited emails about the problem, particularly those with clickable links that claim to offer an update. (Source: dlink.com)
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.