{"id":117886,"date":"2015-01-30T14:28:56","date_gmt":"2015-01-30T12:28:56","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=117886"},"modified":"2015-01-30T15:41:01","modified_gmt":"2015-01-30T13:41:01","slug":"dsl-router-hijacking-vulnerability-discovered","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/hardware\/117886-dsl-router-hijacking-vulnerability-discovered.html","title":{"rendered":"DSL router hijacking vulnerability discovered"},"content":{"rendered":"<p>A vulnerability in Zyxeltech\u2019s ZynOS firmware, which is used in numerous DSL routers globally, is exposing many of the devices\u00a0to a DNS hijacking attack.<\/p>\n<p>Todor Donev, a member of the Bulgarian security research group Ethical Hacker, <a title=\"Donev router vulnarability\" href=\"http:\/\/packetstormsecurity.com\/files\/130113\/dlinkdsl2740r-dnschange.txt\" target=\"_blank\"><strong>revealed the vulnerability<\/strong><\/a> which allows hackers to change the DNS settings on routers running the ZynOS firmware.<\/p>\n<p>\u201cThe vulnerability exists in the web interface, which is accessible without authentication,\u201d said Donev.<\/p>\n<p>\u201cOnce modified, systems use foreign DNS servers, which are usually set up by cybercriminals,\u201d Donev explained.<\/p>\n<p>Compromised routers will allow hackers to redirect a user\u2019s traffic to malicious sites, and steal personal information.<\/p>\n<p>A user accessing a banking site, for example, may be redirected to a phishing site which will gather sensitive information.<\/p>\n<p>Other attacks may include pushing malware to users, and even replacing ads on legitimate sites.<\/p>\n<p><strong><a title=\"The Stack\" href=\"http:\/\/thestack.com\/zyxeltech-zynos-firmware-vulnerability-ethical-hacker-todor-donev-290115\" target=\"_blank\">According to The Stack<\/a>,<\/strong> the attack will \u201cwork most easily on affected routers which are configured for remote administration, but can also be implemented via Cross-Site Request Forgery (CSRF)\u201d.<\/p>\n<p>Some of the routers affected include D-Link\u2019s DSL-2740R ADSL router, as well as DSL routers from TP-Link and ZTE.<\/p>\n<h3 class=\"my-4\">More security news<\/h3>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/security\/117573-dont-share-your-smartphone-with-friends-of-family.html\">Don\u2019t share your smartphone with friends or family<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/security\/117518-117518.html\">Suspected drone invades White House<\/a><\/strong><\/p>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/security\/117492-malaysia-airlines-hacked-plane-not-found.html\">Malaysia Airlines hacked \u2013 Plane not found<\/a><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A ZynOS vulnerability exposes D-Link, TP-Link, and ZTE routers to a DNS hijacking attack<\/p>\n","protected":false},"author":23,"featured_media":72572,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[15],"tags":[71,11795,2614,28634,35,28636,3284,895,28632],"class_list":["post-117886","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hardware","tag-adsl-2","tag-d-link","tag-dsl","tag-ethical-hacker","tag-headline","tag-todor-donev","tag-tp-link","tag-zte","tag-zynos-firmware"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/117886"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=117886"}],"version-history":[{"count":2,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/117886\/revisions"}],"predecessor-version":[{"id":117890,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/117886\/revisions\/117890"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/72572"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=117886"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=117886"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=117886"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}