Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - Takin' names and kickin' ASCII.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews




spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. Visual C++ Redistributable Runtimes AIO Repack
5. Visual C++ Runtime Installer (All-In-One)
6. McAfee Removal Tool (MCPR)
7. MusicBee
8. Rufus
9. K-Lite Mega Codec Pack
10. Sergei Strelec's WinPE
More >>

top reads

Star How to Disable 1-Click Ordering on Amazon (and Avoid Surprise Charges)

Star How to Fix Shallow Paint Layer Depth in Bambu Studio

Star Aviator Betting Game Secrets: Unlock 97% RTP & Triple Your Wins

Star Windows Recall: What It Is, Why Hackers Will Love It, and How to Stay Safe

Star Star Trek Fleet Command Promo Codes: Redeem Codes for Free Shards, Blueprints And Resources

Star How To Use VLC Media Player to Trim Video Clips

Star What Is the $WinREAgent Folder and Can I Delete It?

Star Swear Your Way to Better Search Results

Star How to Get a Dark Start Menu and Taskbar in Windows 10 & 11

Star Enable, Disable, Manage, Delete or Create a System Restore Point


MajorGeeks.Com » News » November 2012 » Email hacks router

Email hacks router


Contributed by: Email on 11/30/2012 04:07 PM [ comments Comments ]


A whole range of Arcor, Asus and TP-Link routers are vulnerable to being reconfigured remotely without authorization. On his blog, security researcher Bogdan Calin demonstrates that just displaying an email within the router's own network can have far-reaching consequences: when opened, his specially crafted test email reconfigures the wireless router so that it redirects the user's internet data traffic. An attacker could exploit this to, for example, redirect unwitting users to a phishing site and harvest their details when they are trying to log into facebook.com.

The attack uses the Cross-Site Request Forgery (CSRF) technique. Calin embedded images whose source URL (src=) points to the router's default IP address (often 192.168.1.1) in his HTML test email. The URL contains parameters that instruct the router's web interface to modify the DNS server configuration. As the URL also contains the admin password for the web interface, the attack will only be successful if the user has left the default password unchanged. A full CSRF URL could look something like this: http://admin :password@192.168.1.1/start_apply.htm?dnsserver=66.66.66.66

A600
The security researcher says that attacks are successful on devices such as Arcor's EasyBox A 600. When displaying the email, the email client will attempt to retrieve the embedded picture from this URL. The router, however, will interpret the parameters as an instruction from the user to configure a different DNS server. Once the changes have been made, any DNS queries will be handled by the configured DNS server, which is controlled by the attacker. From then on, the sender of the email can freely direct the user to arbitrary web servers.

The security researcher opened his test emails with the iOS and Mac OS X default email clients, which load images in HTML emails without prior confirmation. iOS users can disable this functionality with the "Load Remote Images" switch under "Mail, Contacts, Calendar" in the Settings menu. Calin says that Gmail will also load images if a user has previously replied to emails from that user. Other email clients may also load images without requesting prior confirmation.

Calin says that he successfully attacked Asus RT-N16 and RT-N56U routers, TP-Link routers such as the TL-WR841N, and the Arcor EasyBox A 600. Further models are likely to be vulnerable as new CSRF holes in routers continue to surface. Users can protect their routers from being compromised by changing their router password to something other than the default – advice which is applicable to this as well as various other attack scenarios.

Tools such as the OWASP CSRFTester can track down holes in the web applications and web interfaces of network-enabled devices. A case in Brazil demonstrates that CSRF attacks can be launched not only via HTML emails, but also via specially crafted web pages: according to Kaspersky Lab, 4.5 million routers in Brazil were successfully compromised this way.






« Surveillance software: Gamma Group's offshore companies uncovered · Email hacks router · News anchors accidentally cover fake plane crash staged for TV show »




Comments
comments powered by Disqus

MajorGeeks.Com » News » November 2012 » Email hacks router

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition