Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
jschwartzi
on April 11, 2015
|
parent
|
context
|
favorite
| on:
Hacking the D-Link DIR-890L
tl;dr: but only if you're inside the lan or your target has enabled remote administration.
finnn
on April 11, 2015
|
prev
|
next
[–]
It looks like it could be done with a DNS rebinding attack (as you need to set a special HTTP header, so normal CSRF stuff doesn't work). This would mean the victim would simply need to visit an attacker controlled webpage
jschwartzi
on April 11, 2015
|
parent
|
next
[–]
Sweet, even better. Is there any mitigation for that?
finnn
on April 11, 2015
|
root
|
parent
|
next
[–]
Sure! Install OpenWRT or some other alternative firmware.
rasz_pl
on April 11, 2015
|
prev
[–]
just make user click your crafted link, "she put it in her mouth and you wont believe what happened next!"
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: