steampixel, to random German
@steampixel@social.tchncs.de avatar

Upgraded my old D-LINK Share Center DNS 320 NAS to a nesting box.

I hate this kind of waste. May it be a good home. This is the final upgrade in response to a security nightmare.

https://steampixel.de/upgrade-your-old-d-link-share-center-dns-320-nas-to-a-nesting-box/

Olly42, to SEC
@Olly42@nerdculture.de avatar

Critical Flaws Leave 92,000 D-Link NAS Devices Vulnerable to Malware Attacks.

​Over 92,000 end-of-life D-Link Network Attached Storage Devices exposed online and unpatched against a critical remote code execution (RCE) zero-day flaw.

D-Link NAS devices including models DNS-340L, DNS-320L, DNS-327L and DNS-325.

CVE-2024-3272 (CVSS score: 9.8)
CVE-2024-3273 (CVSS score: 7.3)

https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383

The command injection flaw arises from adding a base64-encoded command to the "system" parameter via an HTTP GET request, which is then executed. (Example of the malicious request)
[Netsecfish’s network scans show over 92,000 vulnerable D-Link NAS devices exposed online and susceptible to attacks through these flaws. (Netsecfish|GitHub) https://github.com/netsecfish/dlink?tab=readme-ov-file](https://nerdculture.de/system/media_attachments/files/112/246/741/459/654/058/original/0c8cb578783e16d7.png)

governa, to random
@governa@fosstodon.org avatar

Critical Flaws Leave 92,000 Devices Vulnerable to Malware Attacks

https://thehackernews.com/2024/04/critical-flaws-leave-92000-d-link-nas.html

alexkidman, to australia
@alexkidman@aus.social avatar

New review time, as I put the D-Link Aquila Pro AI M30 AX3000 Wi-Fi 6 Smart Mesh System through its paces. It looks like a stingray, but how does it perform?

https://alexreviewstech.com/d-link-aquila-pro-ai-m30-ax3000-wi-fi-6-smart-mesh-system-review-good-value/

governa, to apple
@governa@fosstodon.org avatar
todb, to random

Well that’s just too many vulns. 51 on one day from ?

https://www.zerodayinitiative.com/advisories/published/

woof, to random
@woof@aria.dog avatar

Trying out Gnu plus Linux on the desktop again. First search result about my first problem is an angry forum dweller chastising a first time poster for not using the search function. I am using "EndeavourOs" which advertises that one is its main benefits is a "friendly community".

kkarhan,
@kkarhan@mstdn.social avatar

@woof Awwww....

I remember this stick...

I still have the big stand for it and use it to this day...

0xor0ne, to infosec

Great blog post on how to start with security analysis of embedded device firmwares (debugging and emulation)
With examples using D-Link routers and CVE-2022-1262

https://greynoise.io/blog/debugging-d-link-emulating-firmware-and-hacking-hardware

image/jpeg
image/jpeg
image/jpeg

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • everett
  • rosin
  • Youngstown
  • ngwrru68w68
  • khanakhh
  • slotface
  • InstantRegret
  • mdbf
  • osvaldo12
  • kavyap
  • cisconetworking
  • DreamBathrooms
  • ethstaker
  • Leos
  • magazineikmin
  • thenastyranch
  • modclub
  • GTA5RPClips
  • tacticalgear
  • provamag3
  • normalnudes
  • cubers
  • Durango
  • tester
  • megavids
  • anitta
  • lostlight
  • All magazines