D link routers firmware security update

The DNS of the D-Link router can be changed by third parties

DNS settings on some router models by D-Link can be modified without permission via the administration menu, from the web.

D-Link

For this change and attack, essentially, no authentication is required, and it can be used to redirect them on malicious online sites, with dangerous scripts or even on phishing pages.

The resulting report was published by Todor Donev, a member of the Bulgarian research team Hacker, στόχος της οποίας είναι να καθιερώσει μια κοινότητα επαγγελματιών, που φέρνουν την καινοτομία στον τομέα της ασφάλειας των υπολογιστών.

His research focused mainly on the D-Link DSL-2740R, but according to the report released on Tuesday, other routers from the same manufacturer are affected by this vulnerability. But the researcher did not list the affected devices.

It's unclear if Donev contacted D-Link about the matter, as there's no word on an official release from the company's side about the problem. According to the official website of the company, the DSL-2740R has been discontinued, meaning it is no longer for sale.

However, although the production of the model has stopped, it can still receive support, since the models being released and used are still covered by the manufacturer's warranty.

Technology DNS, is responsible for the translation of to IP addresses of server hosting the websites. If the device is set to connect to one server DNS that manage scammers, the content the user sees will not be normal.

Secnews.gr

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).