Foreign media said: D-Link Wireless Router Security Vulnerability. Security is always a sensitive topic, especially in the information age. Everyone is spending a lot of money on privacy and information security.
Foreign media said: D-Link Wireless Router Security Vulnerability
In May 19, according to a hacker's blog outside China, a new security function added by some D-Link wireless routers made users more vulnerable to network intrusion. To block malicious attackers, the router vendor D-Link recently added a CAPTCHA design for its products. However, a hacker posted a post on the SourceSec Security Research blog saying that the upgrade can be used to steal a WPA password.
The reason is that the new firmware uses a GET request to log on. The request contains a password that has been hashed by MD5. The results show that, with this function, anyone in the wireless router's coverage can easily access the setting page consisting of all sensitive settings and including the WPA password.
In addition, the new firmware even allows common users to log on to the control page. Therefore, attackers can launch attacks without administrative permissions. When the CAPTCHA design is added to some of the vro products of the D-Link wireless router, some security experts question its practicality, it is not as effective as modifying the default vro password in 30 seconds.