D-Link: Inadvertently revealed signing certificates for her code

D-Link, a Taiwanese networking company, has inadvertently posted the company's firmware code to its firmware source code.D-Link Logo

A Norwegian developer known as bartvbl recently purchased a surveillance camera (the DCS-5020L) from the company, and while inspecting its firmware source code, he discovered four which the company signs the software it develops.dlink 1

[Pullquote] virtually invisible to any kind of anti-virus[/ pullquote]After many experiments with the keys, he managed to create a Windows application, which he signed with one of the four keys.

So the application seemed to come from D Link. The other three keys do not seem to be valid.

Η του Νορβηγού προγραμματιστή επιβεβαιώθηκαν από εταιρεία ασφαλείας Fox-IT στην ολλανδική ιστο technology Tweakers:

"The signature certificate is actually from a software package, firmware version 1.00b03, which was released on February 27 this year."

Meanwhile, the Taiwanese company has revoked this certificate and is starting to distribute new firmware versions that obviously do not contain a key to signing the code.

Let's say that if these keys had ended up in the hands of a malicious user, they would enable him to create and distribute malicious software that could pass as a formal application D-Link.

So it would be virtually invisible from any kind of anti-virus.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.082 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).