Heartbleed Strikes Again: Android Devices, Wi-Fi Routers Vulnerable

By

Just when you thought you've heard the last of the Heartbleed bug, it rears its ugly head again almost seven weeks later. As we learn more about the flaw that tricks servers into dumping recent user information to those devious enough to learn how, more vulnerabilities are arising. The most recent one, named Cupid by the Portuguese security researcher Luis Grangeia who discovered it, exploits local Wi-Fi signals to make an attack against what is essentially the same vulnerability. Despite the cute name, Cupid poses a significant security risk that must be identified and addressed immediately.

Instead of targeting remote computer servers over the Web in the way that Heartbleed originally struck, Cupid instead performs the same procedure by targeting Wi-Fi routers. Since Wi-Fi routers were never (knowingly) targeted by the Heartbleed bug, they never received the same protections. That means that any hacker with access to a Wi-Fi router can access every computer and mobile device connected to that network. Whether dealing with a private home Wi-Fi router or a large-scale enterprise router network, the bug has access and can have the router spit back data including passwords, usernames, account details and more.

What's worse is that there is no list that denotes which devices are safe from this kind of an attack. Grangeia has urged vendors and administrators to upgrade their routers to prevent these attacks, and he has posted the proof of concept in order to aid this process. He has also identified that the most vulnerable targets rely on EAP-based routers that require both an individual password and login, as hackers can easily gain that information and then explore the network at their leisure. Android devices running the 4.1.1 Jelly Bean OS are also vulnerable to the bug.

Thankfully, Grangeia says that the damage will be far more contained than the original Heartbleed leak. Hackers will have to physically travel to Wi-Fi networks to break into them, which is more difficult and time-consuming than simply accessing a server through the Internet. This will allow for plenty of time to upgrade routers before the problem becomes too widespread.


Edited by Rory J. Thompson

TechZone360 Contributing Writer

SHARE THIS ARTICLE
Related Articles

How Real is Telecom Network Transformation: From Legacy to Leading Edge by When?

By: Cynthia S. Artin    11/7/2018

Last week, ABI Research issued its latest report and forecasts in the network orchestration domain, asserting that while a disruption in orchestration…

Read More

What's New in Artificial Intelligence

By: Paula Bernier    11/5/2018

A brief look at what's new in the world of artificial intelligence as it relates to IT operations; customer engagement; marketing analytics; and cloud…

Read More

IBM Makes $34B Bet with Red Hat

By: Paula Bernier    10/29/2018

IBM plans to purchase Red Hat in a $34 billion deal. Big Blue says its combination with the open source pioneer will establish it as the world's No. 1…

Read More

Coding and Invention Made Fun

By: Special Guest    10/12/2018

SAM is a series of kits that integrates hardware and software with the Internet. Combining wireless building blocks composed of sensors and actors con…

Read More

Facebook Marketplace Now Leverages AI

By: Paula Bernier    10/3/2018

Artificial intelligence is changing the way businesses interact with customers. Facebook's announcement this week is just another example of how this …

Read More