Categories
Sites

Малые ракетные корабли для ВМФ получат допзащиту от морских дронов


Гендиректор судостроительной корпорации «Ак Барс» отметил, что нужно защитить машинное отделение – «сердце корабля».

The post Малые ракетные корабли для ВМФ получат допзащиту от морских дронов first appeared on The Russian World.


Categories
Sites

ФНП: россияне с 1 июля могут оперативно передавать документы из-за границы


Переслать документы можно через консула.

The post ФНП: россияне с 1 июля могут оперативно передавать документы из-за границы first appeared on The Russian World.


Categories
Sites

Испания в рамках усилий НАТО против РФ перебросила в Словакию военных


Россия неоднократно утверждала, что не представляет угрозы для стран альянса.

The post Испания в рамках усилий НАТО против РФ перебросила в Словакию военных first appeared on The Russian World.


Categories
Sites

Панкратов-Черный раскрыл сумму своей пенсии


По словам артиста, на такую сумму, даже с добавкой от мэра Москвы, прожить трудно.

The post Панкратов-Черный раскрыл сумму своей пенсии first appeared on The Russian World.


Categories
Sites

Участники фестиваля «Лето в Москве» смогут получить эксклюзивные сувениры


До 15 июля на площадках фестиваля будут работать 26 павильонов с подарками.

The post Участники фестиваля «Лето в Москве» смогут получить эксклюзивные сувениры first appeared on The Russian World.


Categories
Sites

Morgan Stanley Team’s Trump Trade Hinges on a Worsening Economy – Bloomberg


The post Morgan Stanley Team’s Trump Trade Hinges on a Worsening Economy – Bloomberg first appeared on The Trump Investigations – trumpinvestigations.net – The News And Times.


Categories
Sites

Trump ally Steve Bannon to report to federal prison to serve four-month sentence on contempt charges – The Associated Press


The post Trump ally Steve Bannon to report to federal prison to serve four-month sentence on contempt charges – The Associated Press first appeared on The Trump Investigations – trumpinvestigations.net – The News And Times.


Categories
Sites

‘Wow!’: Conservative Legal Icon Stuns Ali Velshi With Plea To Jack Smith – Yahoo News UK


close.svg

  Yahoo News UK

The post ‘Wow!’: Conservative Legal Icon Stuns Ali Velshi With Plea To Jack Smith – Yahoo News UK first appeared on The Trump Investigations – trumpinvestigations.net – The News And Times.


Categories
Sites

Mueller Hotel: Downtown Hamilton project gets $6 million in historic tax credits – Hamilton Journal News


The post Mueller Hotel: Downtown Hamilton project gets $6 million in historic tax credits – Hamilton Journal News first appeared on The Trump Investigations – trumpinvestigations.net – The News And Times.


Categories
Sites

Threat actors actively exploit D-Link DIR-859 router flaw CVE-2024-0769


Experts spotted threat actors exploiting the critical vulnerability CVE-2024-0769 affects all D-Link DIR-859 WiFi routers.

Researchers from cybersecurity firm GreyNoise have spotted exploitation attempts for the critical vulnerability CVE-2024-0769 (CVSS score 9.8) impacting all D-Link DIR-859 WiFi routers.

The vulnerability is a path traversal issue that can lead to information disclosure. Threat actors are exploiting the flaw to collect account information, including user passwords, from the vulnerable D-Link DIR-859 WiFi routers.

The vendor states that the DIR-859 family of routers has reached their End of Life (“EOL”)/End of Service Life (“EOS”) life-cycle, and for this reason, the flaw will likely not be addressed.

GreyNoise observed hackers targeting the ‘DEVICE.ACCOUNT.xml’ file to extract all account names, passwords, user groups, and user descriptions on the device. The attackers use a modified version of the public exploit.

“GreyNoise observed a slight variation in-the-wild which leverages the vulnerability to render a different PHP file to dump account names, passwords, groups, and descriptions for all users of the device. At the time of writing we are not aware of the motivations to disclose/collect this information and are actively monitoring it” reads the analysis published by GreyNoise.

“In the variation as observed by GreyNoise DEVICE.ACCOUNT.xml is utilized. We went ahead and retrieved this file in full. While the exploit conditions are the same as the public PoC, the variation as observed by GreyNoise is dumping all name, password, group, and description for all users of the device.”

The hackers are exploiting the flaw by sending a malicious POST request to ‘/hedwig.cgi,’ to access sensitive configuration files (‘getcfg’) via the ‘fatlady.php’ file, potentially leasing to the exposure of the user credentials.

Once the attackers have obtained the credentials, they can potentially take full control of the device.

D-Link DIR-859 WiFi routers

“It is unclear at this time what the intended use of this disclosed information is, it should be noted that these devices will never receive a patch. Any information disclosed from the device will remain valuable to attackers for the lifetime of the device as long as it remains internet facing.” concludes GreyNoise. “These attributes make for the potential of a long-tail of exploitation that may come to a head at a later date, such as through a currently unknown authenticated RCE vulnerability in the affected device.”

The researchers pointed out that the public PoC exploit targets the ‘DHCPS6.BRIDGE-1.xml’ file instead of ‘DEVICE.ACCOUNT.xml’, for this reason, attackers can use it to attack other files.

The GreyNoise post include a list of possible variations of other getcfg files that can be invoked using CVE-2024-0769.

D-Link customers are recommended to replace the EoL devices as soon as possible.

Pierluigi Paganini

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

(SecurityAffairs – hacking, D-Link DIR-859)