Heartbleed Strikes Again: Android Devices, Wi-Fi Routers Vulnerable

By Matt Paulson June 03, 2014

Just when you thought you've heard the last of the Heartbleed bug, it rears its ugly head again almost seven weeks later. As we learn more about the flaw that tricks servers into dumping recent user information to those devious enough to learn how, more vulnerabilities are arising. The most recent one, named Cupid by the Portuguese security researcher Luis Grangeia who discovered it, exploits local Wi-Fi signals to make an attack against what is essentially the same vulnerability. Despite the cute name, Cupid poses a significant security risk that must be identified and addressed immediately.

Instead of targeting remote computer servers over the Web in the way that Heartbleed originally struck, Cupid instead performs the same procedure by targeting Wi-Fi routers. Since Wi-Fi routers were never (knowingly) targeted by the Heartbleed bug, they never received the same protections. That means that any hacker with access to a Wi-Fi router can access every computer and mobile device connected to that network. Whether dealing with a private home Wi-Fi router or a large-scale enterprise router network, the bug has access and can have the router spit back data including passwords, usernames, account details and more.

What's worse is that there is no list that denotes which devices are safe from this kind of an attack. Grangeia has urged vendors and administrators to upgrade their routers to prevent these attacks, and he has posted the proof of concept in order to aid this process. He has also identified that the most vulnerable targets rely on EAP-based routers that require both an individual password and login, as hackers can easily gain that information and then explore the network at their leisure. Android devices running the 4.1.1 Jelly Bean OS are also vulnerable to the bug.

Thankfully, Grangeia says that the damage will be far more contained than the original Heartbleed leak. Hackers will have to physically travel to Wi-Fi networks to break into them, which is more difficult and time-consuming than simply accessing a server through the Internet. This will allow for plenty of time to upgrade routers before the problem becomes too widespread.


Edited by Rory J. Thompson

TechZone360 Contributing Writer

SHARE THIS ARTICLE
Related Articles

Amid Cryptocurrency Mania, Coinsquare's goNumerical Raises CAD $10.5M

By: Paula Bernier    12/5/2017

The company that operates the Canadian digital currency exchange known as Coinsquare says it has raised CAD $10.5 million in new funding.

Read More

Your New Heart Monitor is an Apple Watch. Really.

By: Doug Mohney    12/4/2017

Looking at a new smartwatch or fitness wearable for the holidays? If you are concerned about your heart health due to family history or reason, Apple …

Read More

Amazon Unleashes Alexa for Business - Consequences Abound

By: Doug Mohney    11/30/2017

Today, Amazon Web Services (AWS) announced Alexa for Business, bringing Amazon's intelligent assist into the office. This shouldn't be a surprise to T…

Read More

Pai Makes His Case for Title II Repeal

By: Paula Bernier    11/21/2017

FCC Chairman Ajit Pai today made clear his plans to repeal Title II net neutrality rules. The commission is expected to pass his proposal at its Dec. …

Read More

Winners of the 2017 Tech Diversity Award Announced

By: TMCnet News    11/20/2017

TMC, a global, integrated media company helping clients build communities in print, in person and online, today announced the recipients of the 2017 T…

Read More