Reverse Engineering a D-Link Backdoor
devttys0.com
devttys0.com
I've no security expertise, but this seems cataclysmically bad!
http://www.bloomberg.com/quote/3380:TT/profile
Where did you get "Joel"?
Specific title: Senior Director-Chief Technology Office
Via: http://www.joesdata.com/executive/Joel_Liu_421313008.html
if(strstr(header, "User-Agent:") != NULL)
{
http_request_t->0xD0 = header + strlen("User-Agent:") + strspn(header, " \t");
}
Note how you could have a header some includes 'User-Agent:' somewhere back in the value, and the arrive with an entirely incorrect pointer to what you think is the value - strstr just finds the needle anywhere in the haystack, not necessarily at the beginning. This particular piece (AFAICT) cannot be exploited for e.g. overruns or similar, maybe just for a subsequent crash or unexpected behaviour due to lack of input sanitization, but still, crazy strstr juggling on untrusted user input? oh oh.If the rest of this code looks like that, this should never, ever be exposed to the wild wild web.
The good reason being able to login to the router to reset the password if the customer forgot it (I remember some home/small office routers don't reset the admin password when you use the reset button).
The evil reason being able to login remotely to any router and snoop around.
I really should get a new router... like...very soon.
Also, I'm a conspiracy-nut and I think a significant amount of these "bugs" happen on purpose.