D-Link: Inadvertently revealed signing certificates for her code

D-Link, a Taiwanese networking equipment company, accidentally published the code that the company signs its software in its source code .D-Link Logo

A Norwegian developer known as bartvbl recently bought a surveillance camera (DCS-5020L) from the company, and while inspecting his firmware source code, he discovered four keys that the company signed the software he is developing.dlink 1

[Pullquote] Malware virtually invisible of any kind [/ pullquote]After many experiments with the keys, he managed to create a Windows application, which he signed with one of the four keys.

So the application seemed to come from D Link. The other three keys do not seem to be valid.

Norwegian developer's discovery was confirmed by security firm Fox-IT on the Dutch technology website Tweakers:

"Το πιστοποιητικό υπογραφής είναι πράγματι από ένα πακέτο λογισμικού, με firmware 1.00b03, το οποίο κυκλοφόρησε την 27η Φεβρουαρίου του τρέχοντος έτους."

Meanwhile, the Taiwanese company has revoked this certificate and is starting to distribute new firmware versions that obviously do not contain a key to signing the code.

Let's mention that if these keys had ended up in someone's hands user, would enable him to create and distribute malware that could pass as an official application of D-Link.

So it would be virtually invisible from any kind of anti-virus.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).