OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re[2]: Multiple XSRF in DD-WRT (Remote Root Command Execution)

From: Vladimir '3APA3A' Dubrovin (3APA3ASECURITY.NNOV.RU)
Date: Thu Dec 11 2008 - 03:55:26 CST


Dear s.gottschalldd-wrt.com,

 According to current practices, it's considered as a security
 vulnerability. The fact you must be logged in to device in browser is a
 mitigation factor.

 To protect routers against attacks like this either generate some kind
 of non-predictable session id as a hidden field in any HTML form and
 check this id or check Referer:.

--Wednesday, December 10, 2008, 3:22:56 PM, you wrote to bugtraqsecurityfocus.com:

sgdwc> this is no security flaw since you must be already logged in
within the webinterface of dd-wrt. otherwise this here will not work. we
already fixed this issue in our sourcetree

--
~/ZARAZA http://securityvulns.com/
Патриотизм - это та же религия. (Твен)