Heartbleed Strikes Again: Android Devices, Wi-Fi Routers Vulnerable

By

Just when you thought you've heard the last of the Heartbleed bug, it rears its ugly head again almost seven weeks later. As we learn more about the flaw that tricks servers into dumping recent user information to those devious enough to learn how, more vulnerabilities are arising. The most recent one, named Cupid by the Portuguese security researcher Luis Grangeia who discovered it, exploits local Wi-Fi signals to make an attack against what is essentially the same vulnerability. Despite the cute name, Cupid poses a significant security risk that must be identified and addressed immediately.

Instead of targeting remote computer servers over the Web in the way that Heartbleed originally struck, Cupid instead performs the same procedure by targeting Wi-Fi routers. Since Wi-Fi routers were never (knowingly) targeted by the Heartbleed bug, they never received the same protections. That means that any hacker with access to a Wi-Fi router can access every computer and mobile device connected to that network. Whether dealing with a private home Wi-Fi router or a large-scale enterprise router network, the bug has access and can have the router spit back data including passwords, usernames, account details and more.

What's worse is that there is no list that denotes which devices are safe from this kind of an attack. Grangeia has urged vendors and administrators to upgrade their routers to prevent these attacks, and he has posted the proof of concept in order to aid this process. He has also identified that the most vulnerable targets rely on EAP-based routers that require both an individual password and login, as hackers can easily gain that information and then explore the network at their leisure. Android devices running the 4.1.1 Jelly Bean OS are also vulnerable to the bug.

Thankfully, Grangeia says that the damage will be far more contained than the original Heartbleed leak. Hackers will have to physically travel to Wi-Fi networks to break into them, which is more difficult and time-consuming than simply accessing a server through the Internet. This will allow for plenty of time to upgrade routers before the problem becomes too widespread.


Edited by Rory J. Thompson

TechZone360 Contributing Writer

SHARE THIS ARTICLE
Related Articles

5 Tips to Protect Your Website From Hackers

By: Contributing Writer    9/21/2022

Having an online presence today is critical for every organization, but as organizations increase their online visibility, they need to be constantly …

Read More

Intel Addressing Semiconductor Challenge with $20B Silicon Heartland Facility

By: Greg Tavarez    9/20/2022

Intel broke ground at the Silicon Heartland in Ohio and revealed the first phase of an education program to innovate and develop new capabilities with…

Read More

Food Tech and The Vegan Revolution

By: Juhi Fadia    9/13/2022

Israel is not only one of the most active venture capital investment countries in the world and home to many of the most successful tech start-ups in …

Read More

TECH: BIG DATA IN THE FASHION INDUSTRY

By: Contributing Writer    9/12/2022

The recipe for success in fashion retail? The right product, at the right price, at the right time. Simple. It is therefore quite remarkable that pred…

Read More

How To Find The Best Business VPN For Your Company

By: Contributing Writer    8/29/2022

A VPN, or Virtual Private Network, is a tool that helps to improve your online privacy and security by creating a private network from a public intern…

Read More