Pwning the Dlink 850L routers and abusing the MyDlink Cloud protocol
pierrekim.github.io
pierrekim.github.io
That's a feature, not a bug. ( https://openwrt.org/ )
At least it makes it possible to patch the other (real) bugs yourself.
I also think it's unreasonable to expect people to patch bugs in consumer gear they've purchased.
That's actually a feature. I consider this a fundamental right I demand on most equipment I buy.
I have no issues with UEFI secureboot as long as it can be disabled and/or put under the users control.
If not, that's strictly a vendor issue and best solved by not buying stuff from that vendor.
Otherwise I would totally agree with that.
Sadly, none of this is going to change in the foreseeable future.
We already have laws on the books for vandalization and sabotage. We also have that horrific law that criminalizes EULAs and "Authorized Access". Why aren't they being used against these companies that make easy to remote-pwn gear? Its readily evident that it's not the end-user's actions that cause these forms of vandalization and digital assault.
Id much prefer enforcing laws, rather than make new ones we hardware creators have to parse and understand.
(Like, how does this affect open source hardware? Some of my side projects are put online. I know a few implementations in the wild already.)
This is pretty scary stuff. I suspect dlink just resells generic firmwares and add branding while the real OEM is so no-name Chinese shop that provides everything but the industrial design of the plastic case. With generic OEMs like these you can't burn your key into the hardware, so you more or less have to do non-key passwords, which as the article shows, are trivially cracked on modern equipment.
I think its safe to say budget brands are usually a security risk. They just don't have the funding to actually take security seriously, even if the engineers have the political will to do so.
This is also the same D-link that was sued by the FTC for its poorly secured cameras, which I believe were also a rebranding of a no-name OEM product.
https://www.ftc.gov/news-events/press-releases/2017/01/ftc-c...
I find that Netgear, Cisco small business, and Linksys aren't perfect, they are miles ahead of d-link, belkin, and other budget brands for home use and really don't cost all that much more. I'm pleasantly surprised to see how often my Netgear gets security updates and Linksys/Cisco small business line is wonderful for the price.
That said, most consumers will be on the receiving end of a ISP provided router. I suspect a good chunk of these things aren't actually internet facing, they're behind the ISP router and working as a access point, but typically consumers won't or can't put them in access point mode. I think there's a lot of dumb luck in home networking that ironically keeps people secure because if they knew how to put the ISP router/modem into gateway mode they'd be in a lot more trouble once their dlinks and belkins are internet facing.
The only thing that's changed is that while in older versions the <?= shorthand was also controlled by the short_open_tags ini option, it's now permanently enabled.
No.
http://php.net/manual/en/ini.core.php#ini.short-open-tag
$ cat test.php
<? var_dump(PHP_VERSION); ?>
$ php test.php
string(5) "7.0.9"
$
Yes?Please, accept my apologies. :)
These sorts of organisations certainly have chutzpah.