DSL router remotely controlled by URL
Security researcher Michal Sajdak revealed at CONFidence 2009 in Krakow in mid-May that it's relatively easy to make the Linksys WAG54G2 WLAN DSL router execute arbitrary shell commands. He has now published [securitum.pl] further details.
Sajdak discovered that it's easy to add a shell command to a POST request and have the router execute it. To test this, all you need is a proxy that can modify the POST request before it's sent. Sajdak says he told the manufacturer, Cisco, about the error in March and his message was acknowledged, but he has received no report of a fix as yet. Read the full story [h-online.com]
Recommended Reads
Kaspersky Lab Channel and Alliance Partners
Newsletter Sign-up
Newsletter Sign-up
Security news and analysis with expert opinion and perspective from the Threatpost editors.
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.

