Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

DEFCON 18: How to Hack Millions of Routers 1/3

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
25,559
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Oct 5, 2010

Speaker: Craig Heffner


This talk will demonstrate how many consumer routers can be exploited via DNS rebinding to gain interactive access to the router's internal-facing administrative interface. Unlike other DNS rebinding techniques, this attack does not require prior knowledge of the target router or the router's configuration settings such as make, model, internal IP address, host name, etc, and does not rely on any anti-DNS pinning techniques, thus circumventing existing DNS rebinding protections.

A tool release will accompany the presentation that completely automates the described attack and allows an external attacker to browse the Web-based interface of a victim's router in real time, just as if the attacker were sitting on the victim's LAN. This can be used to exploit vulnerabilities in the router, or to simply log in with the router's default credentials. A live demonstration will show how to pop a remote root shell on Verizon FIOS routers (ActionTec MI424-WR).

Confirmed affected routers include models manufactured by Linksys, Belkin, ActionTec, Thompson, Asus and Dell, as well as those running third-party firmware such as OpenWRT, DD-WRT and PFSense.

For presentations, whitepapers or audio version of the Defcon 18 presentations visit: http://defcon.org/html/links/dc-archives/dc-18-archive.html

Category:

Science & Technology

Tags:

License:

Standard YouTube License

Link to this comment:

Share to:

Top Comments

  • I'm Commander Shepard and this is my favorite DEFCON 18 video

  • Ah, my schools router uses Javascript to authenticate the login. All I had to do was use Firebug to remove that line, and it lets me in without a problem. :3

see all

All Comments (24)

Sign In or Sign Up now to post a comment!
  • fine dont believe meh, i dont care o.o

  • @itsbasil1126

    HAHAHAHAHA! yeah sure^^

  • @itsbasil1126 dumbshit

  • Does anyone have a site to learn all this?

  • Your vid is a favorite on Nay Pyi Taw

  • @itsbasil1126 kids, sigh.

  • @itsbasil1126 Cool story, bro.

  • Your video is a favorite on Skopje

  • @itsbasil1126 You know why that isn't true? Someone that would have done that wouldn't say it on youtube. Idiot, learn to lie.

  • just bullshit

  • I hacked my school's network and got into the gradebook, attendance records, student and teacher and administrator files as well as their files on how much money they spend and get and the school's credit card. I screwed around with it and fucked up the network and their files, we didnt have computers for a whole month cuz it took them tht long to figure it out, and from the credit card i got around 23,000$, funny thing is, im only 15 and i did all tht. I covered my trail well and they nvr fo

  • I don't understand a thing!!!

  • wtf with recommended videos?

  • Man defcon people leave in 1992...

  • yeah but as u see now that pretty much no good now

  • @1waitandbleed1 haha

  • what if the user browses to ip addresses not domain names :)

  • Amazingly impressive.

  • cool!!

  • Thats really cool!

    (hey i am the 3000 viewer)

  • Clever.

  • Amazing !

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more