Language Selection

English French German Italian Portuguese Spanish

Easter egg: DSL router patch merely hides backdoor instead of closing it

Filed under

First, DSL router owners got an unwelcome Christmas present. Now, the same gift is back as an Easter egg. The same security researcher who originally discovered a backdoor in 24 models of wireless DSL routers has found that a patch intended to fix that problem doesn’t actually get rid of the backdoor—it just conceals it. And the nature of the “fix” suggests that the backdoor, which is part of the firmware for wireless DSL routers based on technology from the Taiwanese manufacturer Sercomm, was an intentional feature to begin with.

Back in December, Eloi Vanderbecken of Synacktiv Digital Security was visiting his family for the Christmas holiday, and for various reasons he had the need to gain administrative access to their Linksys WAG200G DSL gateway over Wi-Fi. He discovered that the device was listening on an undocumented Internet Protocol port number, and after analyzing the code in the firmware, he found that the port could be used to send administrative commands to the router without a password.

After Vanderbecken published his results, others confirmed that the same backdoor existed on other systems based on the same Sercomm modem, including home routers from Netgear, Cisco (both under the Cisco and Linksys brands), and Diamond. In January, Netgear and other vendors published a new version of the firmware that was supposed to close the back door.

Read more

More in Tux Machines

Announced at LinuxCon Europe 2015

A Few Worrisome Regressions Appear In Ubuntu 15.04 vs. 15.10 Performance

With Ubuntu 15.10 set to be released later this month, I've started preparing for a variety of Linux performance comparisons involving the Wily Werewolf. This morning I ran some Ubuntu 15.04 vs. 15.10 benchmarks on one of my frequent test beds and it's revealed a few significant changes in some of the benchmarks. Read more

Leftovers: KDE

  • Baloo 5.15
    We have a new release of Baloo. For those of you who don't know about it - It's a file indexing and searching solution for Linux. It's quite fast, and shipped by default in KDE Plasma.
  • October Development News: krita moves to a new repository
    Lots of things are happening! Let’s start with the most important part: Krita is no longer part of the Calligra source code. Krita 2.9 will still be developed inside Calligra, and we expect to do several more releases of Krita 2.9 with bug fixes and performance improvements. In fact, we expect to be releasing Krita 2.9 regularly until Krita 3.0 is done.
  • The Kubuntu Podcast Team Debunks some Myths
    Aaron Honeycutt, Ovidiu-Florin BOGDAN, and Rick Timmis debunk the myths surrounding the future of Kubuntu and interview Eike Hein (KDE Developer).
  • KDE Frameworks 5.15 have landed in Kubuntu Wily
    KDE Frameworks 5.15 have landed in Kubuntu Wily (to become 15.10).