- Joined
- May 18, 1997
- Messages
- 54,458
Why subscribe to a cable or satellite service when there are tens of thousands of those on the net for you to access? Because you are not a criminal, most likely. That said, I hate browsing through my own DVR's menu, and probably even hate browsing through yours even more. Although this DVR vulnerability has been confirmed, not attacks have been verified yet. Also it can be fairly easily blocked as well should the companies using these decide to. I need to go check if my DVR is mining right now though.
Fernandez discovered that by accessing the control panel of specific DVRs with a cookie header of "Cookie: uid=admin," the DVR would respond with the device's admin credentials in cleartext. The entire exploit is small enough to fit inside a tweet.
...companies can still detect attempts to access /login.rsp or /device.rsp URL paths and block those, allowing access to the DVR's management interface only for trusted IPs.
Fernandez discovered that by accessing the control panel of specific DVRs with a cookie header of "Cookie: uid=admin," the DVR would respond with the device's admin credentials in cleartext. The entire exploit is small enough to fit inside a tweet.
...companies can still detect attempts to access /login.rsp or /device.rsp URL paths and block those, allowing access to the DVR's management interface only for trusted IPs.