Language Selection

English French German Italian Portuguese Spanish

Easter egg: DSL router patch merely hides backdoor instead of closing it

Filed under
Hardware
Security
Legal

First, DSL router owners got an unwelcome Christmas present. Now, the same gift is back as an Easter egg. The same security researcher who originally discovered a backdoor in 24 models of wireless DSL routers has found that a patch intended to fix that problem doesn’t actually get rid of the backdoor—it just conceals it. And the nature of the “fix” suggests that the backdoor, which is part of the firmware for wireless DSL routers based on technology from the Taiwanese manufacturer Sercomm, was an intentional feature to begin with.

Back in December, Eloi Vanderbecken of Synacktiv Digital Security was visiting his family for the Christmas holiday, and for various reasons he had the need to gain administrative access to their Linksys WAG200G DSL gateway over Wi-Fi. He discovered that the device was listening on an undocumented Internet Protocol port number, and after analyzing the code in the firmware, he found that the port could be used to send administrative commands to the router without a password.

After Vanderbecken published his results, others confirmed that the same backdoor existed on other systems based on the same Sercomm modem, including home routers from Netgear, Cisco (both under the Cisco and Linksys brands), and Diamond. In January, Netgear and other vendors published a new version of the firmware that was supposed to close the back door.

Read more

More in Tux Machines

NVIDIA 367.44 Stable Linux Driver Released

While the NVIDIA 370 Linux driver series is currently in beta, the 367 driver series has been updated as the latest long-lived branch release. The Pascal-based TITAN X, GeForce GTX 1060 3GB, and GTX 1060 6GB are now officially supported... That's just with regards to proper product detection as I've been using the GTX 1060 fine on earlier driver releases, etc. Read more Also: Nvidia 367.44 Driver Adds TITAN X (Pascal) and GeForce GTX 1060 Support to Linux

OpenIndiana Operating System Gets MATE 1.14 Desktop Environment, New ISOs

Alexander Pyhalov from the OpenIndiana development team was happy to announce the availability of the latest MATE 1.14 open-source desktop environment for the Solaris-derived operating system. Read more

Canonical Announces Snapcraft 2.15 for Ubuntu 16.04 LTS with Many New Features

We reported earlier on the release of the major Mir 0.24.0 display server for the Ubuntu Linux operating system, and now we would like to inform you about the latest Snapcraft 2.15 tool for packaging apps in the Snap universal binary format. Read more

KDevelop 5.0.0 release

Almost two years after the release of KDevelop 4.7, we are happy to announce the immediate availability of KDevelop 5.0. KDevelop is an integrated development environment focusing on support of the C++, Python, PHP and JavaScript/QML programming languages. Many important changes and refactorings were done for version 5.0, ensuring that KDevelop remains maintainable and easy to extend and improve over the next years. Highlights include much improved new C/C++ language support, as well as polishing for Python, PHP and QML/JS. Read more