<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: D-Link router captcha broken</title>
	<atom:link href="http://hackaday.com/2009/05/19/d-link-router-captcha-broken/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com/2009/05/19/d-link-router-captcha-broken/</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Fri, 10 Feb 2012 15:59:24 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: US History Notes</title>
		<link>http://hackaday.com/2009/05/19/d-link-router-captcha-broken/comment-page-1/#comment-78761</link>
		<dc:creator><![CDATA[US History Notes]]></dc:creator>
		<pubDate>Mon, 22 Jun 2009 12:37:05 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=11234#comment-78761</guid>
		<description><![CDATA[I just wanted to say thank you for such a great post. I&#039;ll be visiting your blog again and adding you to my reader ! Thank you again :)
Thanks,
Denise]]></description>
		<content:encoded><![CDATA[<p>I just wanted to say thank you for such a great post. I&#8217;ll be visiting your blog again and adding you to my reader ! Thank you again :)<br />
Thanks,<br />
Denise</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Venga</title>
		<link>http://hackaday.com/2009/05/19/d-link-router-captcha-broken/comment-page-1/#comment-78531</link>
		<dc:creator><![CDATA[Venga]]></dc:creator>
		<pubDate>Fri, 19 Jun 2009 17:53:45 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=11234#comment-78531</guid>
		<description><![CDATA[I use Seimens router and you can view alot of info without being logged in. =( On a good note its easy to custom change your mac address which lets you constantly change your ip.]]></description>
		<content:encoded><![CDATA[<p>I use Seimens router and you can view alot of info without being logged in. =( On a good note its easy to custom change your mac address which lets you constantly change your ip.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jeicrash</title>
		<link>http://hackaday.com/2009/05/19/d-link-router-captcha-broken/comment-page-1/#comment-76032</link>
		<dc:creator><![CDATA[jeicrash]]></dc:creator>
		<pubDate>Sat, 23 May 2009 17:30:26 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=11234#comment-76032</guid>
		<description><![CDATA[Captcha is just one more thing know-nothing Best-Buy /(insert store of your choicehere) employees can pretend to talk about to sell more product. The work around is so basic and simple anyone who buys one of these devices will have no more security then sticking with a device without captcha. More cities/computer groups should offer public talks on the facts of wireless security because 90% of people are just clueless or don&#039;t care.]]></description>
		<content:encoded><![CDATA[<p>Captcha is just one more thing know-nothing Best-Buy /(insert store of your choicehere) employees can pretend to talk about to sell more product. The work around is so basic and simple anyone who buys one of these devices will have no more security then sticking with a device without captcha. More cities/computer groups should offer public talks on the facts of wireless security because 90% of people are just clueless or don&#8217;t care.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: daffamedia</title>
		<link>http://hackaday.com/2009/05/19/d-link-router-captcha-broken/comment-page-1/#comment-75841</link>
		<dc:creator><![CDATA[daffamedia]]></dc:creator>
		<pubDate>Thu, 21 May 2009 02:02:10 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=11234#comment-75841</guid>
		<description><![CDATA[Agreed, it&#039;s doesn&#039;n work all time]]></description>
		<content:encoded><![CDATA[<p>Agreed, it&#8217;s doesn&#8217;n work all time</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wwhat</title>
		<link>http://hackaday.com/2009/05/19/d-link-router-captcha-broken/comment-page-1/#comment-75807</link>
		<dc:creator><![CDATA[Wwhat]]></dc:creator>
		<pubDate>Wed, 20 May 2009 16:49:34 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=11234#comment-75807</guid>
		<description><![CDATA[~~~PAY ATTENTION~~~ not a WAN access issue.
This is for hacks that use tricks to get in via your browser or as a trojan via your computer, so it&#039;s not a WAN access issue
And as stated this new thing is not protected by the router admin password AT ALL, so any script that runs on some site you visit might get access to your router through your browser/system originating from 127.0.0.1, or some trojan hidden in something you install can access your router, again right from your own computer, as dag33k explains above.

And the captcha is meant to ensure it&#039;s a human entering the password, which in itself can be a bit of a pain if you want to yourself automate routeraccess to be honest, that&#039;s made impossible to do easy if it worked as planned, but I guess people that want to automate would get a router that allows custom linux firmware to be installed and use that route, if you pardon the pun.]]></description>
		<content:encoded><![CDATA[<p>~~~PAY ATTENTION~~~ not a WAN access issue.<br />
This is for hacks that use tricks to get in via your browser or as a trojan via your computer, so it&#8217;s not a WAN access issue<br />
And as stated this new thing is not protected by the router admin password AT ALL, so any script that runs on some site you visit might get access to your router through your browser/system originating from 127.0.0.1, or some trojan hidden in something you install can access your router, again right from your own computer, as dag33k explains above.</p>
<p>And the captcha is meant to ensure it&#8217;s a human entering the password, which in itself can be a bit of a pain if you want to yourself automate routeraccess to be honest, that&#8217;s made impossible to do easy if it worked as planned, but I guess people that want to automate would get a router that allows custom linux firmware to be installed and use that route, if you pardon the pun.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: zsiddique</title>
		<link>http://hackaday.com/2009/05/19/d-link-router-captcha-broken/comment-page-1/#comment-75804</link>
		<dc:creator><![CDATA[zsiddique]]></dc:creator>
		<pubDate>Wed, 20 May 2009 16:35:01 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=11234#comment-75804</guid>
		<description><![CDATA[Humm.. Here is my question about all this Captcha requiring you to login and this malware bot.  

First thing is most routers by default dont allow you to access the config from the WAN port, only if you are on the LAN.  So unless you go in and change this, or, this is something that has changed in some these new routers I think that would prevent outsiders from gaining access.

Now if you have an open AP, and, a client with an infected machine comes on the AP then I guess the Captcha could add an extra level, but you already have issues with an open AP and allowing people on your &quot;trusted&quot; network.
Also I thought most new routers require you to set them up properly to work and no longer &quot;work out of the box&quot; to prevent default password.]]></description>
		<content:encoded><![CDATA[<p>Humm.. Here is my question about all this Captcha requiring you to login and this malware bot.  </p>
<p>First thing is most routers by default dont allow you to access the config from the WAN port, only if you are on the LAN.  So unless you go in and change this, or, this is something that has changed in some these new routers I think that would prevent outsiders from gaining access.</p>
<p>Now if you have an open AP, and, a client with an infected machine comes on the AP then I guess the Captcha could add an extra level, but you already have issues with an open AP and allowing people on your &#8220;trusted&#8221; network.<br />
Also I thought most new routers require you to set them up properly to work and no longer &#8220;work out of the box&#8221; to prevent default password.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dag33k</title>
		<link>http://hackaday.com/2009/05/19/d-link-router-captcha-broken/comment-page-1/#comment-75781</link>
		<dc:creator><![CDATA[dag33k]]></dc:creator>
		<pubDate>Wed, 20 May 2009 14:25:02 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=11234#comment-75781</guid>
		<description><![CDATA[@googfan

The whole point of malware bots breaking into routers has nothing to do with stealing peoples wifi.
The primary purpose of a malware bot breaking into somebodys router is to modify the routers DNS tables so certain site requests can be manipulated. For example every bank web address you type in is redirected silently in the background without you even known and without tipping of any of your browser security or phishing filters to a rouge site which then caputres your details. And you wont know a thing about it becouse the site looks identical, you just wont be able to log it, it will take your details and then say &quot;Sorry - Server error, try again later&quot; or something like that.

the other reason malware Bots would try to break into routers is becouse Firewalls can be a pain. However if you break into the admin area of a router you can practically disable the firewall, allowing a human operator to them zombie all the PC&#039;s behind the router firewall at leisure.

HAcker/cracker leaves this bot running to do the leg work for him over night, wakes up in the morning and has a whole screen long list of address&#039;s where the routers now forward all bank requests to silent phishing sites and, a list of routers than have possiblely hundreds of avaliable PC&#039;s ready for dronning.
Considering MOST pc&#039;s are behind external modem routers these days, Malware has addapted. 

Malware that directally and automatically compromises your gateway to the internet is this fashion is as frightening to us computer security guys as it is interesting.

Can gurantee once a router is hacked, your&#039;ll never be able to trust any site again.

(Ask yourself this question, how many people do you know with broadband.... and how many of them would even know if somebody had loggin into their router? 90% of the people I know have never touched the thing after the initial setup.)

They own your DNS.
Trust me router bots are not &quot;Pointless&quot; they are frightening and the next big thing.]]></description>
		<content:encoded><![CDATA[<p>@googfan</p>
<p>The whole point of malware bots breaking into routers has nothing to do with stealing peoples wifi.<br />
The primary purpose of a malware bot breaking into somebodys router is to modify the routers DNS tables so certain site requests can be manipulated. For example every bank web address you type in is redirected silently in the background without you even known and without tipping of any of your browser security or phishing filters to a rouge site which then caputres your details. And you wont know a thing about it becouse the site looks identical, you just wont be able to log it, it will take your details and then say &#8220;Sorry &#8211; Server error, try again later&#8221; or something like that.</p>
<p>the other reason malware Bots would try to break into routers is becouse Firewalls can be a pain. However if you break into the admin area of a router you can practically disable the firewall, allowing a human operator to them zombie all the PC&#8217;s behind the router firewall at leisure.</p>
<p>HAcker/cracker leaves this bot running to do the leg work for him over night, wakes up in the morning and has a whole screen long list of address&#8217;s where the routers now forward all bank requests to silent phishing sites and, a list of routers than have possiblely hundreds of avaliable PC&#8217;s ready for dronning.<br />
Considering MOST pc&#8217;s are behind external modem routers these days, Malware has addapted. </p>
<p>Malware that directally and automatically compromises your gateway to the internet is this fashion is as frightening to us computer security guys as it is interesting.</p>
<p>Can gurantee once a router is hacked, your&#8217;ll never be able to trust any site again.</p>
<p>(Ask yourself this question, how many people do you know with broadband&#8230;. and how many of them would even know if somebody had loggin into their router? 90% of the people I know have never touched the thing after the initial setup.)</p>
<p>They own your DNS.<br />
Trust me router bots are not &#8220;Pointless&#8221; they are frightening and the next big thing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ejonesss</title>
		<link>http://hackaday.com/2009/05/19/d-link-router-captcha-broken/comment-page-1/#comment-75775</link>
		<dc:creator><![CDATA[ejonesss]]></dc:creator>
		<pubDate>Wed, 20 May 2009 13:02:32 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=11234#comment-75775</guid>
		<description><![CDATA[even if all pages are secured then there is the captchas they can be cracked too.

i have heard of forum sign up captchas being broken allowing spammers to automate sign ups to spam the board.

the only ways i know to totally secure it is.

1. remove the remote admining feature (force user to be at pc to admin the router.

2. for those with older routers that the makers refuse to make firmware that removes the remote admining you can hope your isp has and strictly enforces the &quot;no servers on residential account&quot; and actually blocks the standard server ports 21,80,443 from accessing from the outside.]]></description>
		<content:encoded><![CDATA[<p>even if all pages are secured then there is the captchas they can be cracked too.</p>
<p>i have heard of forum sign up captchas being broken allowing spammers to automate sign ups to spam the board.</p>
<p>the only ways i know to totally secure it is.</p>
<p>1. remove the remote admining feature (force user to be at pc to admin the router.</p>
<p>2. for those with older routers that the makers refuse to make firmware that removes the remote admining you can hope your isp has and strictly enforces the &#8220;no servers on residential account&#8221; and actually blocks the standard server ports 21,80,443 from accessing from the outside.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fartface</title>
		<link>http://hackaday.com/2009/05/19/d-link-router-captcha-broken/comment-page-1/#comment-75774</link>
		<dc:creator><![CDATA[fartface]]></dc:creator>
		<pubDate>Wed, 20 May 2009 12:22:40 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=11234#comment-75774</guid>
		<description><![CDATA[Dont care...

As long as the Bin file of OpenWrt installs  It fixes all problems with these routers.

Honestly, If you have any advanced education you should be using OpenWRT or DDWRT and not the crap firmware in these routers.

But then if you have even a high school education you know to set the password to something that is not easily cracked.

Yes, Most Americans dont even have a high school education as far as I am concerned. you are a RETARD if you dont understand Computer basics.]]></description>
		<content:encoded><![CDATA[<p>Dont care&#8230;</p>
<p>As long as the Bin file of OpenWrt installs  It fixes all problems with these routers.</p>
<p>Honestly, If you have any advanced education you should be using OpenWRT or DDWRT and not the crap firmware in these routers.</p>
<p>But then if you have even a high school education you know to set the password to something that is not easily cracked.</p>
<p>Yes, Most Americans dont even have a high school education as far as I am concerned. you are a RETARD if you dont understand Computer basics.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nawak</title>
		<link>http://hackaday.com/2009/05/19/d-link-router-captcha-broken/comment-page-1/#comment-75767</link>
		<dc:creator><![CDATA[Nawak]]></dc:creator>
		<pubDate>Wed, 20 May 2009 11:25:13 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=11234#comment-75767</guid>
		<description><![CDATA[Ok the captcha is random but the default admin password can&#039;t be?
Make it random and print it beneath the router!
Or put a physical button on it that enables admin when pressed! It can be an already present button but with a longer push for instance!
There are so many possible &quot;full&quot; solutions to the rooting problem and yet they choose to just fix (badly) the rooting-by-bot...]]></description>
		<content:encoded><![CDATA[<p>Ok the captcha is random but the default admin password can&#8217;t be?<br />
Make it random and print it beneath the router!<br />
Or put a physical button on it that enables admin when pressed! It can be an already present button but with a longer push for instance!<br />
There are so many possible &#8220;full&#8221; solutions to the rooting problem and yet they choose to just fix (badly) the rooting-by-bot&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hackius</title>
		<link>http://hackaday.com/2009/05/19/d-link-router-captcha-broken/comment-page-1/#comment-75758</link>
		<dc:creator><![CDATA[Hackius]]></dc:creator>
		<pubDate>Wed, 20 May 2009 09:00:56 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=11234#comment-75758</guid>
		<description><![CDATA[Recently Dlink routers have been a lot better. Their entry level stuff is excelent for the price.

On the other hand Linksys has become crap.

What good brand is there left?]]></description>
		<content:encoded><![CDATA[<p>Recently Dlink routers have been a lot better. Their entry level stuff is excelent for the price.</p>
<p>On the other hand Linksys has become crap.</p>
<p>What good brand is there left?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gluefish</title>
		<link>http://hackaday.com/2009/05/19/d-link-router-captcha-broken/comment-page-1/#comment-75754</link>
		<dc:creator><![CDATA[gluefish]]></dc:creator>
		<pubDate>Wed, 20 May 2009 07:48:57 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=11234#comment-75754</guid>
		<description><![CDATA[Not news.  In a competitive business environment, QA is frequently the group that is shortchanged (or outsourced, or just cut) in order to economically compete.  But that&#039;s the one group that could save the company.
If you are finding holes in the security of a company&#039;s product you can be sure that someone in management was saving a few bucks by cutting back on QA.
If it comes back to bitch-slap them, they deserve it.]]></description>
		<content:encoded><![CDATA[<p>Not news.  In a competitive business environment, QA is frequently the group that is shortchanged (or outsourced, or just cut) in order to economically compete.  But that&#8217;s the one group that could save the company.<br />
If you are finding holes in the security of a company&#8217;s product you can be sure that someone in management was saving a few bucks by cutting back on QA.<br />
If it comes back to bitch-slap them, they deserve it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ross maclean</title>
		<link>http://hackaday.com/2009/05/19/d-link-router-captcha-broken/comment-page-1/#comment-75750</link>
		<dc:creator><![CDATA[ross maclean]]></dc:creator>
		<pubDate>Wed, 20 May 2009 07:21:13 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=11234#comment-75750</guid>
		<description><![CDATA[wow, months of R&amp;D by them, and within 2 weeks a room full of geeks has smashed it into little tiny bits of joke. amazing.]]></description>
		<content:encoded><![CDATA[<p>wow, months of R&amp;D by them, and within 2 weeks a room full of geeks has smashed it into little tiny bits of joke. amazing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BigD145</title>
		<link>http://hackaday.com/2009/05/19/d-link-router-captcha-broken/comment-page-1/#comment-75747</link>
		<dc:creator><![CDATA[BigD145]]></dc:creator>
		<pubDate>Wed, 20 May 2009 06:12:03 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=11234#comment-75747</guid>
		<description><![CDATA[yet another dlink fuck up]]></description>
		<content:encoded><![CDATA[<p>yet another dlink fuck up</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sean</title>
		<link>http://hackaday.com/2009/05/19/d-link-router-captcha-broken/comment-page-1/#comment-75742</link>
		<dc:creator><![CDATA[sean]]></dc:creator>
		<pubDate>Wed, 20 May 2009 04:55:18 +0000</pubDate>
		<guid isPermaLink="false">http://hackaday.com/?p=11234#comment-75742</guid>
		<description><![CDATA[These kinds of things are why I dumped D-Link quite some time ago. Bye bye!]]></description>
		<content:encoded><![CDATA[<p>These kinds of things are why I dumped D-Link quite some time ago. Bye bye!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

