Language Selection

English French German Italian Portuguese Spanish

Easter egg: DSL router patch merely hides backdoor instead of closing it

Filed under
Hardware
Security
Legal

First, DSL router owners got an unwelcome Christmas present. Now, the same gift is back as an Easter egg. The same security researcher who originally discovered a backdoor in 24 models of wireless DSL routers has found that a patch intended to fix that problem doesn’t actually get rid of the backdoor—it just conceals it. And the nature of the “fix” suggests that the backdoor, which is part of the firmware for wireless DSL routers based on technology from the Taiwanese manufacturer Sercomm, was an intentional feature to begin with.

Back in December, Eloi Vanderbecken of Synacktiv Digital Security was visiting his family for the Christmas holiday, and for various reasons he had the need to gain administrative access to their Linksys WAG200G DSL gateway over Wi-Fi. He discovered that the device was listening on an undocumented Internet Protocol port number, and after analyzing the code in the firmware, he found that the port could be used to send administrative commands to the router without a password.

After Vanderbecken published his results, others confirmed that the same backdoor existed on other systems based on the same Sercomm modem, including home routers from Netgear, Cisco (both under the Cisco and Linksys brands), and Diamond. In January, Netgear and other vendors published a new version of the firmware that was supposed to close the back door.

Read more

More in Tux Machines

Alice is killing the trolls -- but expect patent lawyers to strike back

Open source software developers rejoice: Alice Corp. v CLS Bank is fast becoming a landmark decision for patent cases in the United States. The Court of Appeals for the Federal Circuit, which handles all appeals for patent cases in the United States, has often been criticized for its handling of these cases -- Techdirt describes it as "the rogue patent court, captured by the patent bar." But following the Alice decision, the Court of Appeals seems to have changed. Read more

How to Give your Smartphone the Android L Look

Android L is Google's latest mobile operating system. Apart from a complete UI overhaul, this version brings along a myriad of performance improvements. Compared to its competitor iOS 8, Android L outperforms the Apple mobile operating system in design and performance. Though there is no clear announcement as to when Android L will be reaching our devices, its Material Design has slowly started catching up among app developers. Furthermore, many apps have come up that let you completely change the Android smartphone’s user interface to match that of Android L. Although many of those apps are annoyingly hard to use, some of them make the job really simple. Below, we'll show you how to make the most out of such apps and then transform your phone’s UI to completely match the Android L look. Read more

Webconverger 26 Is a Secure Kiosk OS That Doesn't Store Any Data

Webconverger is a distribution designed and developed with a single goal in mind, namely to provide the best Kiosk experience possible. This means that people will be able to use that OS as a regular system, although its functionality will be limited and it will be impossible to install any other apps. This is a very helpful solution if this is a public PC, like in a library or a cafe, and it preserves the quality of the installation for a very long time. Because users can't interact with it on a deeper level, the operating system will remain stable and it will be pretty much the same like in the first day that it was used. Read more

Today in Techrights