what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

WR254-CA-dns.txt

WR254-CA-dns.txt
Posted Nov 1, 2006
Authored by Nikolai Grigoriev

The Hawking Technology wireless router model WR254-CA contains a hardcoded DNS server address which is used first even when an ISP dns server is specified, thus sending information to a potentially hostile server about what sites you are connecting to.

tags | advisory
SHA-256 | 9f4fd39e150f2af901e9ec487582f9ffd4f14bd0b3e0128e0a41ab5a83f8b215

WR254-CA-dns.txt

Change Mirror Download
Hi,

I have discovered a security issue with Hawking Technology wireless
router, model WR254-CA. Since they are still available on the market
so I think it will be good to warn the community.

This router contains a DNS address 139.175.55.244 hardcoded in the
firmware. At least when used in DHCP mode, the set of DNS IP addresses
coming from the ISP does NOT override this hardcoded IP address. The
router takes only first real DNS IP address and puts it to the second
place on its list. Because of this, the hardcoded address is used
first when you try to resolve a hostname through the router (it sends
its own IP address over DHCP to the machines in the local network so
it is typical case).

I have discovered that a similar issue has been reported against Zyxel
P2000W VoIP phone by Shawn Merdinger some time ago - it was exactly
the same hardcoded IP address.

I have attempted to contact Hawking Tech technical support but after
exchanging a couple of emails (they could not understand why do I
consider this a problem) they have stopped answering. Finally, I have
got the answer that "I think it is hard coded inside the router, in
case no DNS server obtain by the DHCP, you still can browse the
internet.".

I would suggest to stay away from this product, check other similar
products from this company and use static DNS configuration if you
actually have this router.

In addition to the danger of having an untrusted DNS server used
without your explicit permission, there is something strange happening
with this DNS server (dns.seed.net.tw). Sometimes I see that some
well-known host names get resolved into wrong IP addresses (about 2-3
weeks ago they had troubles with *.google.com). It may be just a bug
or an attempt to do something more interesting. Anyway, it is a
separate problem.

--
Nikolai Grigoriev
(514) 909-7846
(514) 260-6402
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close