A number of NetGear WNDR devices contain an embedded SOAP service that is seemingly for use with the NetGear Genie application. As this SOAP service is implemented by the built-in HTTP / CGI daemon, unauthenticated queries will also be answered over the internet if remote management has been enabled on the device. As a result, affected devices can be interrogated and hijacked with as little as a well placed HTTP query. Proof of concept included.
Monthly Archives: February 2015
Phishing Attacks Increasingly Target Financial Data – Help Net Security
Year of the Hack? A Billion Records Compromised in 2014 – CNBC
Google Email 4.4.2.0200 Denial Of Service
A bug in the stock Google email application version 4.4.2.0200 has been found. An attacker can remotely perform an denial of service attack by sending a specially crafted email. No interaction from the user is needed to produce the crash just receive the malicious email.
Top 10 Tips for Educating Employees About Cybersecurity – IT Business Edge
Netatmo Weather Station Cleartext Password Leak
During initial setup, the weather station will submit its complete configuration unencrypted to the manufacturer cloud service. This configuration includes confidential information like the user’s Wifi password.
Kaspersky Anti-Virus for Windows Receives vCloud Ready Status – The VAR Guy
Router Hunter 1.0
Router Hunter is a php script that scans for and exploits DNS change vulnerabilities in Shuttle Tech ADSL Modem-Router 915 WM and D-Link DSL-2740R routers and also exploits the credential disclosure vulnerability in LG DVR LE6016D devices.
Kaspersky Total Security 2015 Review – TopTenReviews
eTouch Samepage 4.4.0.0.239 SQL Injection / File Read
eTouch Samepage version 4.4.0.0.239 suffers from remote SQL injection and arbitrary file read vulnerabilities.