Reply to post: Re: djack

Misfortune Cookie crumbles router security: '12 MILLION+' in hijack risk

diodesign (Written by Reg staff) Silver badge

Re: djack

"If it is a real technical announcement, what does this mean"

The problem is, if you go full disclosure and dump all the details online, someone will weaponize it an hour and by the end of the week someone will have a 12-million-strong botnet. Check Point noted: "This public awareness may serve as a better incentive for the makers to release updated firmware faster."

You need to craft a HTTP request with a cookie that exploits a flaw – probably a buffer overflow – in the server. You can always reverse engineer the firmware yourself, like Check Point did, and I suspect people already are.

C.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon