blog.vastart.dev/2022/02/10/d-link-router-cve-2021-27342-timing-side-channel-attack-vulnerability-writeup

Preview meta tags from the blog.vastart.dev website.

Linked Hostnames

7

Thumbnail

Search Engine Appearance

Google

https://blog.vastart.dev/2022/02/10/d-link-router-cve-2021-27342-timing-side-channel-attack-vulnerability-writeup

D-Link Router CVE-2021-27342 Timing Side-Channel Attack Vulnerability Writeup

I recently bought a new DIR-842 home router, and immediately (as any hacker would) started toying with it - I can’t call it mine until I pop a shell on it. Rather quickly I found I can enable telnet through the admin web gui, and then connect to telnet with an admin user. But that was too easy, so let’s see if we can find a bug/vulnerability.



Bing

D-Link Router CVE-2021-27342 Timing Side-Channel Attack Vulnerability Writeup

https://blog.vastart.dev/2022/02/10/d-link-router-cve-2021-27342-timing-side-channel-attack-vulnerability-writeup

I recently bought a new DIR-842 home router, and immediately (as any hacker would) started toying with it - I can’t call it mine until I pop a shell on it. Rather quickly I found I can enable telnet through the admin web gui, and then connect to telnet with an admin user. But that was too easy, so let’s see if we can find a bug/vulnerability.



DuckDuckGo

https://blog.vastart.dev/2022/02/10/d-link-router-cve-2021-27342-timing-side-channel-attack-vulnerability-writeup

D-Link Router CVE-2021-27342 Timing Side-Channel Attack Vulnerability Writeup

I recently bought a new DIR-842 home router, and immediately (as any hacker would) started toying with it - I can’t call it mine until I pop a shell on it. Rather quickly I found I can enable telnet through the admin web gui, and then connect to telnet with an admin user. But that was too easy, so let’s see if we can find a bug/vulnerability.

  • General Meta Tags

    8
    • title
      D-Link Router CVE-2021-27342 Timing Side-Channel Attack Vulnerability Writeup | mavlevin
    • charset
      utf-8
    • viewport
      width=device-width, initial-scale=1, minimum-scale=0.5, maximum-scale=5
    • generator
      Jekyll v4.3.4
    • author
      Mav Levin
  • Open Graph Meta Tags

    8
    • og:image
      https://mavlevin.com/assets/img/whtaguy_research_bg.png
    • og:type
      website
    • og:title
      D-Link Router CVE-2021-27342 Timing Side-Channel Attack Vulnerability Writeup
    • US country flagog:locale
      en_US
    • og:description
      I recently bought a new DIR-842 home router, and immediately (as any hacker would) started toying with it - I can’t call it mine until I pop a shell on it. Rather quickly I found I can enable telnet through the admin web gui, and then connect to telnet with an admin user. But that was too easy, so let’s see if we can find a bug/vulnerability.
  • Twitter Meta Tags

    6
    • twitter:card
      summary
    • twitter:title
      D-Link Router CVE-2021-27342 Timing Side-Channel Attack Vulnerability Writeup
    • twitter:description
      I recently bought a new DIR-842 home router, and immediately (as any hacker would) started toying with it - I can’t call it mine until I pop a shell on it.Ra...
    • twitter:card
      summary
    • twitter:image
      https://mavlevin.com/assets/img/whtaguy_research_bg.png
  • Link Tags

    5
    • alternate
      https://mavlevin.com/feed.xml
    • alternate
      https://mavlevin.com/feed.xml
    • canonical
      https://mavlevin.com/2022/02/10/D-Link-Router-CVE-2021-27342-Timing-Side-Channel-Attack-Vulnerability-Writeup.html
    • shortcut icon
      /assets/favicon.ico
    • stylesheet
      /assets/css/main.css

Links

27