Access member only content, take part in discussions with comments on blogs, news and reviews and receive all the latest security industry news directly to your inbox. Join now for free.
Processing registration... Please wait.
This process can take up to a minute to complete.
A confirmation email has been sent to your email address - SUPPLIED EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can start posting.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain @scmagazine.com.au to your white-listed senders.
A BlackHat presenter has extracted passwords from temporary databases in consumer routers including Netgear using SQL Injection attacks.
Tactical Network Solutions researcher Zachary Cutlip gained remote root access to Netgear wireless routers using SQL injection (SQLi) to exploit unexposed buffer overflows.
The same SQLi was used to extract plain text passwords from the routers' file systems.
The research, reported on DarkReading and to be presented at BlackHat Las Vegas this month, would show how low-level exploits could be strung together to gain root access to consumer routers.
Cutlip told DarkReading he hoped the attacks demonstrated that researchers shouldn't overlook SQL injection vulnerabilities that may seem benign.
"In this case, we're going to be exploiting a SQL injection in a database that has very temporary data but it has no valuable data whatsoever.
"So it might seem there would be no motivation to attack the database. But by doing so, it's going to give us access to some other vulnerabilities."
Copyright © SC Magazine, Australia
To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.