@Motherboard
  @Motherboard
Motherboard | How to Turn a Router Into Part of a Botnet (Livestream) @Motherboard | Uploaded November 2017 | Updated October 2024, 20 hours ago.
Today Rick Ramgattie will assess the security of the D-Link DIR-865L router to show how he can chain vulnerabilities in both its web and storage interfaces to get root shell access. This would give an attacker full access to the device thus allowing them to spy on the user's web traffic, redirect the user to phishing sites, or add the router to a botnet.

When you plug in a USB drive the router shares it over an anonymous Samba share, which an attacker can abuse. Since the Samba server follows symbolic links we can then explore the entire file system rather than just the USB drive. The router stores the web interface password in a clear text file, so with Samba we download it. The router's web application has a file inclusion vulnerability, so we can write files where we want.  Finally we show with a race condition vuln, we can use the file inclusion vulnerability to overwrite a script with our desired included script and have it execute.

By chaining these vulnerabilities together, we can launch a Telnet server, achieving full root access to the device.
How to Turn a Router Into Part of a Botnet (Livestream)The Virus That Kills Drug-Resistant SuperbugsHow Bitcoin Became El Salvadors CurrencyIs Bitcoin Bad for the Environment? | Cryptoland RoundtableThe World’s Largest Telescope Is Leaving Earth | Motherboard’s Space ShowThe Risky New Frontier of Defi and Altcoins | Cryptoland RoundtableThe Fixers Using Recycled Laptop Batteries to Power Their HomesDigital License Plates HACKED. Researcher Uses AI to TROLL Wells Fargo. CYBER LIVEMeet the NASA Engineer Trying to Stop Space Hackers | The Space ShowHow Technology Is Reshaping Every Aspect of Daily LifeLooking for The Beginning of The Universe | Motherboard’s Space ShowLooking Into the Center of the Galaxy

How to Turn a Router Into Part of a Botnet (Livestream) @Motherboard

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER