Critical Flaw Discovered In DD-WRT 225
MagicM writes "A critical flaw has been discovered in DD-WRT, a Linux based alternative open source firmware for WLAN routers such as the fan-favorite Linksys WRT54GL. The flaw can give an attacker instant root access to the router merely by embedding an image with a specially crafted URL in a Web page (CSRF attack)." The linked page notes that a fix is being rolled out (build 12533) and gives firewall rules to thwart the attack if the fix is not available yet for a particular device.
I'd download the patch but... (Score:1, Funny)
my router keeps redirecting me to porn sites and scrolling "pWnD by c0d3k177y" in HTML marquee tags at the top of my browser.
Re:Standard Practices (Score:2, Funny)
What about dentists? Can dentists make an img tag to load the malformed URL too, or just hackers?
Sorry to see you go (Score:4, Funny)
Greetings, I am a Linksys customers service representative. While I'm sorry to hear that you'll be leaving us, I'd like to remind you that if you have to wait for your paycheck in order to purchase a piece of home networking equipment, perhaps navigating flash based websites is the least of your worries. Have you considered going back to school?
Re:It's "homogeneity" (Score:4, Funny)
langs morf. get use 2 it.
Re:This is a common stack in wifi APs (Score:2, Funny)
The router appears to glow in the picture.
Does that mean the router has biochemical reactions involving free radicals as well?
Someone call Greenpeace! There's a lack of environmental progress from router makers!
Re:This is a common stack in wifi APs (Score:2, Funny)
Re:Mod Parent Up (Score:3, Funny)