• Hacking News
    • Defacement Hack
    • Data Breach
    • Credit Card Hacking
    • Smartphone Hacking
    • SCADA System Hacking
    • Password Cracking
    • Browser Security
  • Malware
    • Ransomware Malware
    • Banking Trojan
    • Malware/Virus
    • Botnet attack
    • Smartphone Malware
    • Stuxnet Worm
    • Cyber Espionage
  • Cyber Attack
    • DDoS Attack
    • Cyber Security
    • Malware/Virus
    • State Sponsored Hackers
    • Email/Gmail Hacking
    • Cyber Warfare
    • Cyber Espionage
  • Vulnerabilities
    • Vulnerability Disclosure
    • Zero-Day Vulnerability
    • Android Vulnerability
    • iPhone Vulnerability
    • SQL Injection
    • MITM Attack
    • XSS Vulnerability
    • Brute Force attack
  • NSA Spying
    • Edward Snowden
    • National Security Agency(NSA)
    • Online Privacy
    • Encryption Tools
    • Surveillance
    • Tor Anonymity Network
    • Bitcoin/Blockchain
Menu
The Hacker News

+1,453,072

198,310

477,235
cyber security degree online

Backdoor found in Chinese Tenda Wireless Routers, allows Root access to Hackers

2013-10-18T22:06:00-11:00Friday, October 18, 2013 Mohit Kumar

Like Us on Facebook:
Last week Craig Heffner, specialized on the embedded device hacking exposed a serious backdoor in number of D-Link routers allows unauthorized backdoor access.
Recently he published his another researcher, Titled 'From China, With Love', exposed that D-Link is not only the vendor who puts backdoors in their products. According to him, China based networking device and equipment manufacturer - Tenda Technology (www.tenda.cn) also added potential backdoors into their Wireless Routers.

He unpacked the software framework update and locate the httpd binary an found that the manufacturer is using GoAhead server, which has been substantially modified.
These routers are protected with standard Wi-Fi Protected Setup (WPS) and WPA encryption key, but still by sending a UDP packet with a special string , an attacker could take over the router.

Routers contain a flaw in the httpd component, as the MfgThread() function spawns a backdoor service that listens for incoming messages containing commands to execute. A remote attacker with access to the local network can execute arbitrary commands with root privileges, after access.

He observed that, attacker just need run the following telnet server command on UDP port 7329, in order of root gain access:
echo -ne "w302r_mfg\x00x/bin/busybox telnetd" | nc -q 5 -u 7329 192.168.0.1
Where, "w302r_mfg" is the magic string to get access via backdoor.
Some of the vulnerable routers are W302R and W330R as well as re-branded models, such as the Medialink MWN-WAPR150N. Other Tenda routers are also possibly affected. They all use the same “w302r_mfg” magic packet string.

Nmap NSE script to test for the backdoored routers – tenda-backdoor.nse is also available for penetration testing.
Like Us on Facebook:
Subscribe for Latest News

Backdoor

,

D-Link router

,

hacking news

,

hardware hacking

,

remote code execution

,

reverse engineering

,

root access

,

Router hacking

,

telnet

,

Tenda Wireless Routers

Follow 'Mohit Kumar' on Google+, Twitter or Facebook or Contact via Email.
The Hacker News
Latest Stories

Comments

AlienVault USM

Popular Stories

  • The Hacker News

    Hacking WordPress Website with Just a Single Comment

  • The Hacker News

    Crazy! Hacker Implants NFC Chip In His Hand To Hack Android Phones

  • The Hacker News

    Hacker Finds a Simple Way to Bypass Google Password Alert

  • The Hacker News

    [Video] PayPal Remote Code Execution Vulnerability Demonstrated by Hacker

  • The Hacker News

    8 Best Android Apps To Improve Privacy and Security in 2015

  • The Hacker News

    The Great... Great... Firewall of China Hijacks Facebook Connect Plugin

  • The Hacker News

    TRAI leaked Over Million Email Addresses; Anonymous India takes Revenge

  • The Hacker News

    Microsoft Edge: The Windows 10 Web Browser

  • The Hacker News

    Fastest Operating System for Quantum Computing Developed By Researchers

  • The Hacker News

    Password Alert Chrome Extension to Protect your Google Account from Phishers

The Hacker News
About | THN Magazine |The Hackers Conference |Sitemap |Advertise on THN | Our Authors |Submit News |Privacy Policy | Contact