CSRF attacks against a linksys wireless router

Ryan Poyar · Annual Information Security Symposium · 2010

CSRF attacks have been called the sleeping giant of web-based vulnerabilities. These attacks take advantage of the trust that a website has in a user's browser. It can also take advantage of something inherent about the victim such as the private network that the victim is in or any other trust that the victim machine has. The CSRF attacks used in this research against wireless routers takes advantage of all of these inherent properties of the victim's machine. In doing so, an attacker can gain complete control of the wireless router. In order to help prevent against this type of attack browsers implement a Same Origin Policy (SOP) which only allows client side code to interact with the origin (website) which it came from. Browsers also use a technique called DNS pinning in order to further prevent scripts from evading the SOP. On the other side of the fence, attackers attempt to use a technique called DNS rebinding in order to break the DNS pinning within the browser. This research explored the feasibility of performing these types of attacks in a number of different technologies as well as analyzed the consequences and significance of the attacks.

Read the paper · More papers on PaperTik