Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

dd-wrt pwnd

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
25,553
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Jul 20, 2009

yep...a stupid bug exploited. Shame on the dd-wrt developers :(

Category:

Science & Technology

Tags:

License:

Standard YouTube License

Link to this comment:

Share to:

Uploader Comments (gat3way)

  • the code für cgi-bin handling has been completelly wriped, but CSRF prevention is made before this code. search for "cross site attack"

  • I've just tested against 24sp1 - CSRF works. But indeed in the SVN there is a referer check before. Probably it's been added later. However even this way, the attack is possible from a ssl site cause in that case no referers are being sent.

  • i checked that too right now. the referer is included in ssl calls too

  • Not if the request comes from a SSL site - that would be considered an information leakage and no sane browser does it (konqueror is an exception AFAIK).

    OpenWRT does a great job at preventing CSRF by validating the request based on an unique session id (about 15-20 bytes long) in the URL. Since it's hard to guess/bruteforce, CSRF attacks are not feasible against it.

  • Yes, but then it's still open for a CSRF attack. If someone that has access to the web UI open a specially crafted page (this even could be a forum with crafted img urls), then his router is at risk. It does not require an authenticated session to work.

see all

All Comments (34)

Sign In or Sign Up now to post a comment!
  • I've been attempting this on an old router I dug up from 2006 that I can't retrieve the passwords from, but It doesn't seem to be working on the older ones. You can still ";reboot" them though.

  • did the dd-wrt pwnd died in this video???

  • i dont understand the video (im newbie) but THE SONG IS AWESOME! =D

  • wtf this is really not cool.

    just tried does not works with the actual svn-version. but with an older no problem.

    just turn off remote web gui and the problem is away..

  • Bravo :D

  • shame on the dd-wrt developers :(

  • Bravo! Respect! Microsoft sized bug ;-)

  • impressive

  • good job :) nice bug

  • interesante! ..... habra q probarlo

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more