Skip to main content

Researchers take over Linksys router with simple JavaScript

posted onJuly 30, 2012
by l33tdawg

A pair of researchers at last week's Black Hat conference demonstrated how a simple JavaScript app could be used to compromise a wireless router with little to no user interaction.

Network devices – such as routers, switches, printers and firewalls – can be hijacked to give a remote attacker full control of the network, Phil Purviance and Joshua Brashars, senior security consultants at AppSec Consulting, said during their presentation on Thursday. The attack method relied on JavaScript and cross-site request forgery, they said.

While demonstrations of hacking routers and other networked hardware is not new to Black Hat, this presentation was unusual because so much of the attack was automated. Its success hinged on social engineering, a modern browser supporting HTML5 and lax password security. Typically JavaScript attacks are limited to the browser, but the researchers used a blended attack, which broke this constraint and could affect actual network devices and the network itself.

Source

Tags

Linksys Security

You May Also Like

Recent News

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th