Avatar
u32larry
6fae3efabeed99627753383aee38a220ac354c588f12f54640d834eb9f7d11ec
Software security, testing, and reliability. I like the orange coin
Replying to Avatar Ava

**Hackers exploit critical D-Link DIR-859 router flaw to steal passwords**

If you or anyone you know is using this device, now would be a good time to upgrade.

https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-d-link-dir-859-router-flaw-to-steal-passwords/

"Hackers are exploiting a critical vulnerability that affects all D-Link DIR-859 WiFi routers to collect account information from the device, including passwords.

The security issue was disclosed in January and is currently tracked as CVE-2024-0769 (9.8 severity score) - a path traversal flaw that leads to information disclosure.

Although D-Link DIR-859 WiFi router model reached end-of-life (EoL) and no longer receives any updates, the vendor still released a security advisory explaining that the flaw exists in the "fatlady.php" file of the device, affects all firmware versions, and allows attackers to leak session data, achieve privilege escalation, and gain full control via the admin panel.

D-Link is not expected to release a fixing patch for CVE-2024-0769, so owners of the device should switch to a supported device as soon as possible."

#cybersecgirl

What's your thoughts on zero trust for home networks?

๐Ÿ˜„ I get it. I feel the same quite often.

You've got the right attitude though. Cypherpunks write code. Let's build something new.

Thanks for the zap too! Largest one I've received yet ๐Ÿ˜ฎ

โ€œThe thing I have noticed is that when the anecdotes and the data disagree, the anecdotes are usually right. There is something wrong with the way that you are measuring it."

-Bezos

Don't forget the plebs

I went thru a phase where I was totally obsessed and listened to a whole bunch of them. Funny dude