Critical Flaw Discovered In DD-WRT
MagicM writes "A critical flaw has been discovered in DD-WRT, a Linux based alternative open source firmware for WLAN routers such as the fan-favorite Linksys WRT54GL. The flaw can give an attacker instant root access to the router merely by embedding an image with a specially crafted URL in a Web page (CSRF attack)." The linked page notes that a fix is being rolled out (build 12533) and gives firewall rules to thwart the attack if the fix is not available yet for a particular device.
my router keeps redirecting me to porn sites and scrolling "pWnD by c0d3k177y" in HTML marquee tags at the top of my browser.
What about dentists? Can dentists make an img tag to load the malformed URL too, or just hackers?
Greetings, I am a Linksys customers service representative. While I'm sorry to hear that you'll be leaving us, I'd like to remind you that if you have to wait for your paycheck in order to purchase a piece of home networking equipment, perhaps navigating flash based websites is the least of your worries. Have you considered going back to school?
langs morf. get use 2 it.
The router appears to glow in the picture.
Does that mean the router has biochemical reactions involving free radicals as well?
Someone call Greenpeace! There's a lack of environmental progress from router makers!
Zomg they have discovered a vulnerability in EARTH! My infastructure runs on earth! Oh noes!! F1 key! F1!!!
Whats the harm in yelling 'Computer, end program!'? You could be living in Star Trek! Go on.. give it a try.
I traded my gamecube for a wii and bought a 360, and hooked them both up to my computer! :D
Ezekiel 23:20