Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

Warning: Use of this site may cause you to excessively download cool programs and feel geeky.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews



IObit Black Friday Sale

spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. MusicBee
5. Sergei Strelec's WinPE
6. Microsoft Visual C++ 2015-2022 Redistributable Package
7. Visual C++ Redistributable Runtimes AIO Repack
8. McAfee Removal Tool (MCPR)
9. K-Lite Mega Codec Pack
10. Visual C++ Runtime Installer (All-In-One)
More >>

top reads

Star AI Answers: Authority Without Accountability

Star All the New Features Landing in Windows 11 This December

Star Lossless vs Lossy: When FLAC, APE, and ALAC Beat MP3 and When They Don't

Star Google Search Tricks You'll Actually Use in 2025 and Beyond

Star Fresh PC Checklist: First 12 Things to Do On a New Windows 11 Machine

Star Running AI Models Locally: What They Are, Where to Find Them, and How to Get Started

Star Deciding Between Idle State, Sleep Mode, and Shutdown: What's Best for Your PC?

Star How to Fix VMware Workstation "The Update Server Could Not Be Resolved" Error Installing VMware Tools

Star How to Remove Google Gemini from Your Phone (and Your Life)

Star Windows Bloat Removal Guide: Debloat Safely and Keep What You Need


MajorGeeks.Com » News » November 2012 » Email hacks router

Email hacks router


Contributed by: Email on 11/30/2012 04:07 PM [ comments Comments ]


A whole range of Arcor, Asus and TP-Link routers are vulnerable to being reconfigured remotely without authorization. On his blog, security researcher Bogdan Calin demonstrates that just displaying an email within the router's own network can have far-reaching consequences: when opened, his specially crafted test email reconfigures the wireless router so that it redirects the user's internet data traffic. An attacker could exploit this to, for example, redirect unwitting users to a phishing site and harvest their details when they are trying to log into facebook.com.

The attack uses the Cross-Site Request Forgery (CSRF) technique. Calin embedded images whose source URL (src=) points to the router's default IP address (often 192.168.1.1) in his HTML test email. The URL contains parameters that instruct the router's web interface to modify the DNS server configuration. As the URL also contains the admin password for the web interface, the attack will only be successful if the user has left the default password unchanged. A full CSRF URL could look something like this: http://admin :password@192.168.1.1/start_apply.htm?dnsserver=66.66.66.66

A600
The security researcher says that attacks are successful on devices such as Arcor's EasyBox A 600. When displaying the email, the email client will attempt to retrieve the embedded picture from this URL. The router, however, will interpret the parameters as an instruction from the user to configure a different DNS server. Once the changes have been made, any DNS queries will be handled by the configured DNS server, which is controlled by the attacker. From then on, the sender of the email can freely direct the user to arbitrary web servers.

The security researcher opened his test emails with the iOS and Mac OS X default email clients, which load images in HTML emails without prior confirmation. iOS users can disable this functionality with the "Load Remote Images" switch under "Mail, Contacts, Calendar" in the Settings menu. Calin says that Gmail will also load images if a user has previously replied to emails from that user. Other email clients may also load images without requesting prior confirmation.

Calin says that he successfully attacked Asus RT-N16 and RT-N56U routers, TP-Link routers such as the TL-WR841N, and the Arcor EasyBox A 600. Further models are likely to be vulnerable as new CSRF holes in routers continue to surface. Users can protect their routers from being compromised by changing their router password to something other than the default – advice which is applicable to this as well as various other attack scenarios.

Tools such as the OWASP CSRFTester can track down holes in the web applications and web interfaces of network-enabled devices. A case in Brazil demonstrates that CSRF attacks can be launched not only via HTML emails, but also via specially crafted web pages: according to Kaspersky Lab, 4.5 million routers in Brazil were successfully compromised this way.






« Surveillance software: Gamma Group's offshore companies uncovered · Email hacks router · News anchors accidentally cover fake plane crash staged for TV show »




Comments
comments powered by Disqus

MajorGeeks.Com » News » November 2012 » Email hacks router

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition