* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Saturday, May 10, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Flutter Entertainment eyes U.S. prediction markets amid growing interest – Sports Business Journal

    Flutter Entertainment Sets Its Sights on U.S. Prediction Markets as Interest Soars

    SXSW Rom-Com ‘I Really Love My Husband’ Acquired for U.S. Release – Variety

    Heartfelt Romance: ‘I Really Love My Husband’ Set to Captivate U.S. Audiences!

    Georgia Entertainment CEO says large-scale production is slowing down – Decaturish

    Georgia Entertainment CEO Warns of Slowdown in Large-Scale Productions

    Zugalu Entertainment Welcomes Crimson Herring Studios to Its Family!

    Fall 2025 TV Schedule: Your Guide to the Complete Lineup – Wyoming News Now

    Get Ready for Fall 2025: Your Ultimate Guide to the Exciting TV Lineup!

    Blackstone River Theatre presents music from Scotland with Cantrip – The Valley Breeze

    Experience the Enchanting Sounds of Scotland: Cantrip Takes the Stage at Blackstone River Theatre!

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Harnessing emerging technologies to power a small business – The Oaklandside

    Unlocking Success: How Emerging Technologies Can Transform Your Small Business

    Artificial intelligence (AI) – The Guardian

    Unlocking the Future: How Artificial Intelligence is Transforming Our World

    Technology Innovation to Take Center Stage at The 2025 National Restaurant Association Show – Restaurant Technology News

    Get Ready for a Tech Revolution: The 2025 National Restaurant Association Show Unveils Cutting-Edge Innovations!

    Newmont signs deal to use Chrysos Corporation technology – Capital Brief

    Newmont Partners with Chrysos Corporation to Revolutionize Mining Technology

    Air Force Invests in Whisper’s Ultraquiet Propulsion Technology – FLYING Magazine

    Air Force Invests in Whisper’s Ultraquiet Propulsion Technology – FLYING Magazine

    Trump administration set to overhaul Biden’s AI chip export regulations – TechHQ

    Trump administration set to overhaul Biden’s AI chip export regulations – TechHQ

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Flutter Entertainment eyes U.S. prediction markets amid growing interest – Sports Business Journal

    Flutter Entertainment Sets Its Sights on U.S. Prediction Markets as Interest Soars

    SXSW Rom-Com ‘I Really Love My Husband’ Acquired for U.S. Release – Variety

    Heartfelt Romance: ‘I Really Love My Husband’ Set to Captivate U.S. Audiences!

    Georgia Entertainment CEO says large-scale production is slowing down – Decaturish

    Georgia Entertainment CEO Warns of Slowdown in Large-Scale Productions

    Zugalu Entertainment Welcomes Crimson Herring Studios to Its Family!

    Fall 2025 TV Schedule: Your Guide to the Complete Lineup – Wyoming News Now

    Get Ready for Fall 2025: Your Ultimate Guide to the Exciting TV Lineup!

    Blackstone River Theatre presents music from Scotland with Cantrip – The Valley Breeze

    Experience the Enchanting Sounds of Scotland: Cantrip Takes the Stage at Blackstone River Theatre!

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Harnessing emerging technologies to power a small business – The Oaklandside

    Unlocking Success: How Emerging Technologies Can Transform Your Small Business

    Artificial intelligence (AI) – The Guardian

    Unlocking the Future: How Artificial Intelligence is Transforming Our World

    Technology Innovation to Take Center Stage at The 2025 National Restaurant Association Show – Restaurant Technology News

    Get Ready for a Tech Revolution: The 2025 National Restaurant Association Show Unveils Cutting-Edge Innovations!

    Newmont signs deal to use Chrysos Corporation technology – Capital Brief

    Newmont Partners with Chrysos Corporation to Revolutionize Mining Technology

    Air Force Invests in Whisper’s Ultraquiet Propulsion Technology – FLYING Magazine

    Air Force Invests in Whisper’s Ultraquiet Propulsion Technology – FLYING Magazine

    Trump administration set to overhaul Biden’s AI chip export regulations – TechHQ

    Trump administration set to overhaul Biden’s AI chip export regulations – TechHQ

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Hackers exploit critical D-Link DIR-859 router flaw to steal passwords

June 30, 2024
in Technology
Hackers exploit critical D-Link DIR-859 router flaw to steal passwords
Share on FacebookShare on Twitter

Hackers exploit critical D-Link DIR-859 router flaw to steal passwords

Hackers are exploiting a critical vulnerability that affects all D-Link DIR-859 WiFi routers to collect account information from the device, including passwords.

The security issue was disclosed in January and is currently tracked as CVE-2024-0769 (9.8 severity score) – a path traversal flaw that leads to information disclosure.

Although D-Link DIR-859 WiFi router model reached end-of-life (EoL) and no longer receives any updates, the vendor still released a security advisory explaining that the flaw exists in the “fatlady.php” file of the device, affects all firmware versions, and allows attackers to leak session data, achieve privilege escalation, and gain full control via the admin panel.

D-Link is not expected to release a fixing patch for CVE-2024-0769, so owners of the device should switch to a supported device as soon as possible.

Detected exploitation activity

Threat monitoring platform GreyNoise has observed the active exploitation of CVE-2024-0769 in attacks that rely on a slight variation of the public exploit.

The researchers explain that hackers are targeting the ‘DEVICE.ACCOUNT.xml’ file to dump all account names, passwords, user groups, and user descriptions present on the device.

Contents of the retrieved configuration fileContents of the retrieved configuration file
Source: GreyNoise

The attack leverages a malicious POST request to ‘/hedwig.cgi,’ exploiting CVE-2024-0769 to access sensitive configuration files (‘getcfg’) via the ‘fatlady.php’ file, which potentially contains user credentials.

Malicious POST requestMalicious POST request
Source: GreyNoise

GreyNoise has not determined the motivation of the attackers, but the targeting of user passwords shows an intention to perform device takeover, thus giving the attacker full control of the device.

“It is unclear at this time what the intended use of this disclosed information is, it should be noted that these devices will never receive a patch,” the researchers explain.

“Any information disclosed from the device will remain valuable to attackers for the lifetime of the device as long as it remains internet facing” – GreyNoise

GreyNoise notes that the public proof-of-concept exploit, on which current attacks rely, targets the ‘DHCPS6.BRIDGE-1.xml’ file instead of ‘DEVICE.ACCOUNT.xml’, so it could be used to target other configuration files, including:

ACL.xml.php
ROUTE.STATIC.xml.php
INET.WAN-1.xml.php
WIFI.WLAN-1.xml.php

These files could expose configurations for access control lists (ACLs), NAT, firewall settings, device accounts, and diagnostics, so defenders should be aware of them being potential targets for exploitation.

GreyNoise makes available a larger list of files that could be invoked in attacks that exploit CVE-2024-0769. This should server defenders in case other variations occur.

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : BleepingComputer – https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-d-link-dir-859-router-flaw-to-steal-passwords/

Tags: Exploithackerstechnology
Previous Post

Meet Brain Cipher — The new ransomware behind Indonesia’s data center attack

Next Post

Microsoft resumes rollout of Windows 11 KB5039302 update for most users

‘Active Management’ Harms Forests — And It’s About to Get a Whole Lot Worse – The Revelator

‘Active Management’ Harms Forests — And It’s About to Get a Whole Lot Worse – The Revelator

May 10, 2025

Unlocking the Future: How Innovation Funds Propel Breakthroughs in AI, Bioengineering, and Materials Science

May 10, 2025
Talking Animals: Veteran science journalist Stephen S. Hall recounts reporting and research that yielded Slither, singular book on snakes – WMNF 88.5 FM

Unraveling the Secrets of Snakes: A Journey with Veteran Science Journalist Stephen S. Hall

May 10, 2025
Lifestyle Lookout: Mother’s Day brunch in Bellingham, Big Jam Stories in Ferndale and The Spring Wine Walk – My Bellingham Now

Unforgettable Mother’s Day Brunch, Big Jam Stories, and the Spring Wine Walk: Exciting Events in Bellingham and Ferndale!

May 10, 2025
WCK Forced to Halt Cooking in Gaza as Supplies Run Out – World Central Kitchen

World Central Kitchen Suspends Operations in Gaza Amid Supply Crisis

May 10, 2025
China Reacts to Trump Claims About ‘Suffering’ Chinese Economy – Newsweek

China Responds to Trump’s Claims of Economic Struggles: What You Need to Know

May 10, 2025
Flutter Entertainment eyes U.S. prediction markets amid growing interest – Sports Business Journal

Flutter Entertainment Sets Its Sights on U.S. Prediction Markets as Interest Soars

May 10, 2025
Optimizing Human Health On Earth And In Space – Texas A&M Today

Optimizing Human Health On Earth And In Space – Texas A&M Today

May 10, 2025
Rep. Marjorie Taylor Greene says she won’t run for U.S. Senate – NBC News

Marjorie Taylor Greene Declares She’s Not Entering the Senate Race!

May 10, 2025
Harnessing emerging technologies to power a small business – The Oaklandside

Unlocking Success: How Emerging Technologies Can Transform Your Small Business

May 10, 2025

Categories

Archives

May 2025
MTWTFSS
 1234
567891011
12131415161718
19202122232425
262728293031 
« Apr    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (597)
  • Economy (608)
  • Entertainment (21,521)
  • General (15,210)
  • Health (9,650)
  • Lifestyle (613)
  • News (22,149)
  • People (611)
  • Politics (615)
  • Science (15,830)
  • Sports (21,118)
  • Technology (15,598)
  • World (598)

Recent News

‘Active Management’ Harms Forests — And It’s About to Get a Whole Lot Worse – The Revelator

‘Active Management’ Harms Forests — And It’s About to Get a Whole Lot Worse – The Revelator

May 10, 2025

Unlocking the Future: How Innovation Funds Propel Breakthroughs in AI, Bioengineering, and Materials Science

May 10, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version