Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 62 guests and 2 members online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow News from the Outside Worldarrow Multiple D-Link Routers Vulnerable to Authentication Bypass
EH-Net
May 25, 2012, 03:38:51 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Multiple D-Link Routers Vulnerable to Authentication Bypass  (Read 6030 times)
0 Members and 1 Guest are viewing this topic.
Craig
EH-Net Columnist
Jr. Member
*****
Offline Offline

Posts: 69


View Profile WWW
« on: January 09, 2010, 05:55:05 PM »

FYI for anyone running a D-Link router, I've found some rather glaring issues that affect multiple models from 2006 to present:

Quote
Multiple D­-Link routers suffer from insecure implementations of the Home Network Administration Protocol which allow un­authenticated and/or un­privileged users to view and configure administrative settings on the router.

Further, the mere existence of HNAP allows attackers to completely bypass the CAPTCHA login features that D­-Link has made available in recent firmware releases.

These vulnerabilities can be exploited by an individual inside the local network, as well as an external attacker.

It is suspected that most, if not all, D­-Link routers manufactured since 2006 have HNAP support and are vulnerable. However, only the following routers and firmware versions have been confirmed to date:

         1) DI-­524 hardware version C1, firmware version 3.23
         2) DIR-­628 hardware version B2, firmware versions 1.20NA and 1.22NA
         3) DIR­-655 hardware version A1, firmware version 1.30EA

Full description and POC code available here: http://www.sourcesec.com/2010/01/09/d-link-routers-one-hack-to-own-them-all/
Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.174 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.