<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: D-Link Routers: One Hack to Own Them All</title>
	<atom:link href="http://www.sourcesec.com/2010/01/09/d-link-routers-one-hack-to-own-them-all/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sourcesec.com/2010/01/09/d-link-routers-one-hack-to-own-them-all/</link>
	<description>Security research and vulnerability assesment</description>
	<lastBuildDate>Fri, 03 Sep 2010 01:47:13 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: credit score</title>
		<link>http://www.sourcesec.com/2010/01/09/d-link-routers-one-hack-to-own-them-all/comment-page-2/#comment-265</link>
		<dc:creator>credit score</dc:creator>
		<pubDate>Fri, 03 Sep 2010 01:37:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.sourcesec.com/?p=195#comment-265</guid>
		<description>I applied for my credit score and reports.It&#039;s really free,fast and secure. Highly recommended!  http://safe-creditscore.com</description>
		<content:encoded><![CDATA[<p>I applied for my credit score and reports.It&#8217;s really free,fast and secure. Highly recommended!  <a href="http://safe-creditscore.com" rel="nofollow">http://safe-creditscore.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: DyadyaSportivnihShtanah</title>
		<link>http://www.sourcesec.com/2010/01/09/d-link-routers-one-hack-to-own-them-all/comment-page-2/#comment-262</link>
		<dc:creator>DyadyaSportivnihShtanah</dc:creator>
		<pubDate>Fri, 13 Aug 2010 09:40:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.sourcesec.com/?p=195#comment-262</guid>
		<description>&lt;a href=&quot;http://linagane.t35.com&quot; rel=&quot;nofollow&quot;&gt;This is good&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p><a href="http://linagane.t35.com" rel="nofollow">This is good</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: corny</title>
		<link>http://www.sourcesec.com/2010/01/09/d-link-routers-one-hack-to-own-them-all/comment-page-2/#comment-261</link>
		<dc:creator>corny</dc:creator>
		<pubDate>Thu, 12 Aug 2010 22:39:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.sourcesec.com/?p=195#comment-261</guid>
		<description>&lt;a href=&quot;http://diabettreatment.net&quot; rel=&quot;nofollow&quot;&gt;&lt;b&gt;Insulin&lt;/b&gt;&lt;/a&gt;, a protein hormone produced before the pancreas and it 
regulates &lt;b&gt;&lt;a href=&quot;http://diabetsinfo.com/&quot; rel=&quot;nofollow&quot;&gt;blood sugar&lt;/a&gt;&lt;/b&gt; (glucose) in blood. Insulin is tolerant of as a replacement for treatment of diabetes.
The hormone is synthesized in the beta cells, which stick into in hormone-secreting cells of the pancreas
 and is called islets of Langerhans. The hormone is synthesized in the beta cells, which insert in 
hormone-secreting cells of the pancreas and is called islets of Langerhans. The word “insulin” is from 
the Latin insula – island, it indicates on the eyot creation of the hormone.</description>
		<content:encoded><![CDATA[<p><a href="http://diabettreatment.net" rel="nofollow"><b>Insulin</b></a>, a protein hormone produced before the pancreas and it<br />
regulates <b><a href="http://diabetsinfo.com/" rel="nofollow">blood sugar</a></b> (glucose) in blood. Insulin is tolerant of as a replacement for treatment of diabetes.<br />
The hormone is synthesized in the beta cells, which stick into in hormone-secreting cells of the pancreas<br />
 and is called islets of Langerhans. The hormone is synthesized in the beta cells, which insert in<br />
hormone-secreting cells of the pancreas and is called islets of Langerhans. The word “insulin” is from<br />
the Latin insula – island, it indicates on the eyot creation of the hormone.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robin Volbrecht</title>
		<link>http://www.sourcesec.com/2010/01/09/d-link-routers-one-hack-to-own-them-all/comment-page-2/#comment-258</link>
		<dc:creator>Robin Volbrecht</dc:creator>
		<pubDate>Sat, 31 Jul 2010 11:48:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.sourcesec.com/?p=195#comment-258</guid>
		<description>Not several men and women believe the similar way as you. That contains me.. sorry :)</description>
		<content:encoded><![CDATA[<p>Not several men and women believe the similar way as you. That contains me.. sorry <img src='http://www.sourcesec.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hackademix.net » ABE Patrols the Routes to Your Routers</title>
		<link>http://www.sourcesec.com/2010/01/09/d-link-routers-one-hack-to-own-them-all/comment-page-2/#comment-257</link>
		<dc:creator>hackademix.net » ABE Patrols the Routes to Your Routers</dc:creator>
		<pubDate>Wed, 28 Jul 2010 11:14:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.sourcesec.com/?p=195#comment-257</guid>
		<description>[...] is not exposed on the internet side it can&#8217;t be reached by an internet attacker (see this HNAP D-Link Hack for a glaring [...]</description>
		<content:encoded><![CDATA[<p>[...] is not exposed on the internet side it can&#8217;t be reached by an internet attacker (see this HNAP D-Link Hack for a glaring [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Листовка</title>
		<link>http://www.sourcesec.com/2010/01/09/d-link-routers-one-hack-to-own-them-all/comment-page-2/#comment-250</link>
		<dc:creator>Листовка</dc:creator>
		<pubDate>Mon, 21 Jun 2010 09:21:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.sourcesec.com/?p=195#comment-250</guid>
		<description>and not be a comparative article, which of the router is better?</description>
		<content:encoded><![CDATA[<p>and not be a comparative article, which of the router is better?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: craig</title>
		<link>http://www.sourcesec.com/2010/01/09/d-link-routers-one-hack-to-own-them-all/comment-page-2/#comment-235</link>
		<dc:creator>craig</dc:creator>
		<pubDate>Sun, 28 Feb 2010 01:45:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.sourcesec.com/?p=195#comment-235</guid>
		<description>BobW,

Thanks for the update, and yes, if you got a 401 unauthorized then your firmware version isn&#039;t vulnerable. The latest firmware for the DIR-655 should also have this bug fixed, but it&#039;s funny that not keeping your firmware up to date kept you secure. :)

Thanks for the info on the DIR-624; like you said, it is old, but you see those old routers around all the time and I don&#039;t think I&#039;ve ever seen anyone change the user account logins for them.</description>
		<content:encoded><![CDATA[<p>BobW,</p>
<p>Thanks for the update, and yes, if you got a 401 unauthorized then your firmware version isn&#8217;t vulnerable. The latest firmware for the DIR-655 should also have this bug fixed, but it&#8217;s funny that not keeping your firmware up to date kept you secure. <img src='http://www.sourcesec.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Thanks for the info on the DIR-624; like you said, it is old, but you see those old routers around all the time and I don&#8217;t think I&#8217;ve ever seen anyone change the user account logins for them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BobW</title>
		<link>http://www.sourcesec.com/2010/01/09/d-link-routers-one-hack-to-own-them-all/comment-page-2/#comment-230</link>
		<dc:creator>BobW</dc:creator>
		<pubDate>Thu, 25 Feb 2010 02:41:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.sourcesec.com/?p=195#comment-230</guid>
		<description>I just read about this issue and came here.  I have tested my US DIR-655 on firmware 1.11 (while I&#039;m a professional programmer, I must admit I&#039;ve rarely bothered to update my routers unless to fix a specific issue that got in my way).  Interestingly enough, v1.11 doesn&#039;t seem to have the vulnerability.

Using your hnap0wn script I get back a 401 Authorization Required for the GetDeviceSettings.xml post (and the others).  So unless I&#039;m overlooking something, it might be that D-Link originally had everything secure and opened it up accidently during a firmware update.  I&#039;m probably not going to try updating my firmware at this time :)

I also have an old D-Link DI-624 Rev C firmware 2.76 (the last firmware update, as this product is no longer supported), and it does have the user exploit (e.g. if user password is still default of blank, then I can update the admin password).</description>
		<content:encoded><![CDATA[<p>I just read about this issue and came here.  I have tested my US DIR-655 on firmware 1.11 (while I&#8217;m a professional programmer, I must admit I&#8217;ve rarely bothered to update my routers unless to fix a specific issue that got in my way).  Interestingly enough, v1.11 doesn&#8217;t seem to have the vulnerability.</p>
<p>Using your hnap0wn script I get back a 401 Authorization Required for the GetDeviceSettings.xml post (and the others).  So unless I&#8217;m overlooking something, it might be that D-Link originally had everything secure and opened it up accidently during a firmware update.  I&#8217;m probably not going to try updating my firmware at this time <img src='http://www.sourcesec.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I also have an old D-Link DI-624 Rev C firmware 2.76 (the last firmware update, as this product is no longer supported), and it does have the user exploit (e.g. if user password is still default of blank, then I can update the admin password).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mrdlnf</title>
		<link>http://www.sourcesec.com/2010/01/09/d-link-routers-one-hack-to-own-them-all/comment-page-2/#comment-215</link>
		<dc:creator>mrdlnf</dc:creator>
		<pubDate>Fri, 05 Feb 2010 00:29:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.sourcesec.com/?p=195#comment-215</guid>
		<description>Here is the latest of WW version, i have tested it and seems it fixed the issue : http://support.dlink.co.id/firmware/DIR655A4_FW131WWB01.rar</description>
		<content:encoded><![CDATA[<p>Here is the latest of WW version, i have tested it and seems it fixed the issue : <a href="http://support.dlink.co.id/firmware/DIR655A4_FW131WWB01.rar" rel="nofollow">http://support.dlink.co.id/firmware/DIR655A4_FW131WWB01.rar</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eck</title>
		<link>http://www.sourcesec.com/2010/01/09/d-link-routers-one-hack-to-own-them-all/comment-page-2/#comment-162</link>
		<dc:creator>Eck</dc:creator>
		<pubDate>Sun, 24 Jan 2010 18:12:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.sourcesec.com/?p=195#comment-162</guid>
		<description>I must have missed it earlier. Great info I was watching HNN, and Dlink supposedly has a patch for the problem. However, it isn&#039;t posted on their site. Might have to give Dlink a call after I play with this a little more. 
Thanks
Eck</description>
		<content:encoded><![CDATA[<p>I must have missed it earlier. Great info I was watching HNN, and Dlink supposedly has a patch for the problem. However, it isn&#8217;t posted on their site. Might have to give Dlink a call after I play with this a little more.<br />
Thanks<br />
Eck</p>
]]></content:encoded>
	</item>
</channel>
</rss>
