请输入您要查询的百科知识:

 

词条 Misfortune Cookie (computers)
释义

  1. References

{{Orphan|date=August 2018}}

Misfortune Cookie is computer software vulnerability of certain set of network routers' firmware which found be leveraged by an attacker to gain access remotely. Tyne CVSS rating for this vulnerability is rated between 9.8 to 10 on the scale of 10.

The attacker in this scenario sends a crafted HTTP cookie attribute to the vulnerable system's (network router) web-management portal where the attacker's content overwrites the device memory. The contents of the cookie act as command to the router which then abides by the commands. This results in arbitrary code execution. This vulnerability was discovered in early 2000s but did not emerge publicly until 2014 when security researchers from Israeli security firm checkpoint made a public disclosure. The vulnerability still persists in over 1 million devices accessible over internet and total of about 12 million devices. This includes around 200 different router brands.[1]

In 2018, the vulnerability again gained traction as the vulnerable firmware was used in medical equipments that could potentially cause life threatening attacks via IoT.[2] Its severity was highlighted by ICS-CERT in its advisory, thereby.[3]

References

1. ^{{Cite news|url=http://mis.fortunecook.ie/misfortune-cookie-suspected-vulnerable.pdf|title=MisFortune cookie|last=|first=|date=|work=Bulletin|access-date=}}
2. ^{{Cite news|url=https://www.bleepingcomputer.com/news/security/4-year-old-misfortune-cookie-rears-its-head-in-medical-gateway-device/|title=4-Year Old Misfortune Cookie Rears Its Head In Medical Gateway Device|work=BleepingComputer|access-date=2018-08-30|language=en-us}}
3. ^{{Cite web|url=https://ics-cert.us-cert.gov/advisories/ICSMA-18-240-01|title=Qualcomm Life Capsule {{!}} ICS-CERT|website=ics-cert.us-cert.gov|language=en|access-date=2018-08-30}}

2 : Firmware|Computer security exploits

随便看

 

开放百科全书收录14589846条英语、德语、日语等多语种百科知识,基本涵盖了大多数领域的百科知识,是一部内容自由、开放的电子版国际百科全书。

 

Copyright © 2023 OENC.NET All Rights Reserved
京ICP备2021023879号 更新时间:2024/9/23 5:19:51