My research in analyzing the security of Dlink 850L routers starts from a recent security contest organized by a security company. The Dlink 850L has 2 versions of these routers with very slight hardware modifications.
Following a very badly coordinated previous disclosure with Dlink last February(see -02-02-update-dlink-dwr-932b-lte-routers-vulnerabilities.html),Full-disclosure is applied this time.
The webpage _of_router/register_send.php doesn't check the authentication of the user, thus an attacker can abuse this webpage to gain control of the device.This webpage is used to register the device to the myDlink cloud infrastructure.
o Then, using Firefox dev tools, the attacker can passively analyze the default HTTP requests/responses from the Dlink APIs on www.mydlink.com:The dlink cloud interface will leak by default the password of the device (!) inside the answer of a PUT request (and inside GET requests too). Just by watching the HTTP requests from the NPAPI plugin, the APIs will provide passwords of the device in cleartext.
o Finally, the NPAPI plugins will automatically establish a tunnel between the router and the Firefox browser:the attacker will be able to visit :dynamicaly_generated_remote_port/ to reach the remote router.The traffic will go directly to Amazon servers then to the remote Dlink router:
o The attacker will use the previous password provided by the legit HTTPS answers from the Dlink APIs and will be able to login inside the router.At that point complete control over the router is achieved.
The PHP script hosted at _of_router/register_send.php will serve as a proxy between the attacker and the remote Dlink APIs.This page will also retrieve the password (it is stored in cleartext - see part 8. Weak files permission and credentials stored in cleartext) and send it to remote Dlink APIs.
The request to /tssm/tssml.php will ask the remote Cloud platform to forward the traffic to the device number 3XXXXXXX.This will provide the attacker information about the new-established TCP tunnel from the browser NPAPI extension to the DLINK 850L router, via the Cloud platform:
So, it appears, the router is reachable over this TCP tunnel using either HTTP and HTTPS.By default, you can see HTTP request AND HTTPS request from the browser (over the tunnel) to the router.About the HTTPS requests, the SSL certificate provided by the router is self-signed. Sus, an invalid certificate can be forged and used in order to successful MITM the device and intercept information. More, by default, a TCP relay for HTTP is made by the NPAPI plugin to the router as shown above.
Futhermore, the /mydlink/signalc program running inside the router uses the MAC address of the device to get an unique identifier,which will always be the same, even if the dlink device is reset or linked with a new dlink cloud account.This allows Dlink to 'follow' the ownership of the device.
Finally, the mydlink interface allows the user to enter credentials for gmail/hotmail accounts, the credentials are then transfered to the routers using the tunnel established with the cloud protocol.It doesn't seem to be a good idea, as the traffic between the router and the Cloud platform is not encrypted or encrypted using a self-signed certificate without verification and the passwords are sent over this tunnel using the Internet.
Bonus point: this attack will be relayed to internal clients using the dhcp server running inside the router.So if you connect a vulnerable Dlink router to the internal network, it will be pwned too:
It appears some daemons running in the routers (revA and revB) can be crashed remotely from the LAN.As it doesn't provide further remote privileges to an attacker, this is only for information and was not detailed.
I have a DLink 601 router with several Ethernet ports on it. It runs my MacBook and Wi-Fi radio wirelessly and my iMAc is plugged into it. It has a long Ethernet cable going to my AV system in another room, with 3 components there having Ethernet connections. Can I put a simple splitter on the incoming Ethernet modem from Comcast to hook up my iMAc directly, and then safely move my router from my office to my AV room and run 3 Ethernet cables to my 3 components there? This would be instead of getting a hub or switch at the AV system. (I'm also thinking my iMAc would work even better online hooked up directly instead of going thru the router.) I'll only be using one Internet connection at a time on the three components.
In order to serve a single Internet connection to multiple devices in your house, a router must be the first device connected to (or included in) your bridge device (AKA cable modem).
More complicated solutions involve replacing your D-Link with a new router, and re-purposing the D-Link to be that switch. Or, you could replace your entire cable modem with one that also does routing & switching and then move the router to be your switch.
No. You can't additional devices to the WAN side of your network because your Internet connection can only support a single device. That's why you need the router -- to make multiple devices (on the LAN side) appear as a single device to the modem.
You can add a switch to the LAN side of your router. Leave your router where it is. Connect the long cable to one of its LAN ports. And then get a cheap Ethernet switch (10/100, 5 ports unmanaged is fine) to connect the long cable to your other device.
With cinematic Full HD 1080p resolution, mydlink Cameras capture clearer, smoother video. mydlink Cameras are jammed packed with advanced features, from AI-based person detection to enhanced sound and motion detection, IR night vision and outdoor weather resistance to pan and tilt control, cloud recording and more!*
Select mydlink Smart Cameras come with built-in AI-based IVA (Intelligent Video Analytics) technology.
Person Detection, Multi-Zone Detection, Boundary-Crossing Detection and Priority Zone settings ensure advanced, intelligent customisation of how alerts are triggered for all-round smarter home monitoring.
D-Link is banking on its cylindrical form-factor to attract potential buyers, since four of its five new draft 11ac routers come in that shape. The family portrait below shows the 868L as the tallest of the group. As an AC1750 class router, the 868L supports link rates up to 450 Mbps in the 2.4 GHz band and 1300 Mbps in 5 GHz.
Routing throughput was measured running 1.01 firmware, using our router test process. Table 4 summarizes the results, which earn it a position at the top of the Router Charts for downlink (WAN to LAN) throughput and a #1 rank among AC1750 routers for Routing performance.
I ran 40 MHz Coexistence and Fat channel intolerant tests passed to make sure the 868L behaved when encountering interfering 2.4 GHz networks. Both tests passed with the 868L responding immediately and falling back to 20 MHz mode link rates. I did note that when the Fat Channel Intolerant bit was set back to disable, that the router stayed in 20 MHz mode for the few minutes that I monitored it.
All tests were run using our new wireless test process and 1.01 version firmware loaded. The router was first reset to factory defaults and Channel 6 was set for 2.4 GHz and Channel 153 for 5 GHz. 20 MHz bandwidth mode was set for 2.4 GHz and 80 MHz mode (to enable draft 802.11ac link rates) was set for 5 GHz. The test client was connected using WPA2/AES encryption.
The 5 GHz uplink plot shows more separation between the WD and D-Link, with the latter besting both other routers only at the 0 dB test point, which is also used for the "Location A" equivalent.
I get a blank page trying to log in to a new D-Link router DIR882US using either or I can log in using IE. I have FF 57.0.1 64-bit. I just installed the router and latest driver update. I haven't had problems accessing other web sites. I found a statement on the d-link forums that this has been an issue since FF 52 for mydlink users. I don't use mydlink, but I suspect my problem is related. Here's that link: -is-the-d-link-mydlink-portal-not-working-with-firefox-52-and-above.html. I've asked D-Link support about this also.
I appreciate both responses but I'll decline to uninstall/reinstall Firefox in this case. (I've done that before when I had problems accessing almost everything.) I'm pretty certain that the issue for the D-Link login is the javascript. The page source shows javascript is used. After searching further, I also found essentially the same information about the problem on java.com, "Java plug-in does not work in Firefox after installing Java" at _java.xml.A D-Link support rep said he would forward my concern to their engineering team. Perhaps they'll work out a fix. If not, I'll use IE for the rare times I need to access my router's admin site.
This Blog page is a different situation - having to do with all NPAPI Plugins, except for Flash, being deprecated. The only similarity is the HTTPS started one version earlier with Firefox 51. -is-the-d-link-mydlink-portal-not-working-with-firefox-52-and-above.html'Firefox 52 has removed all support for Netscape Plugin API (NPAPI). Plugins such as the D-Link mydlink plugin, Silverlight, Java, and Acrobat are no longer supported. mydlink portal uses mydlink plugin to access mydlink devices, and since mydlink plugin no longer works on Firefox 52, Firefox users are stuck at the plugin download page. Please note that customers using Firefox 51 are not affected. Internet Explorer and Safari still support these plugins.
f448fe82f3