Tuesday, October 6, 2020

Latest Tech News

A team of researchers from Synopsys' Cybersecurity Research Center (CyRC) in Oulu, Finland have discovered a partial authentication bypass vulnerability in multiple wireless router chipsets from Mediatek, Qualcomm (Atheros), Zyxel and Realtek.

The vulnerability, tracked as CVE-2019-18989, CVE-2019-18990 and CVE-2019-18991, affects Mediatek's MT7620N chipset, Qualcomm's AR9132, AR9283 and AR9285 chipsets and Realtek's RTL8812AR, RTL8196D, RTL8881AN and RTL8192ER chipsets. However, Synopsys was unable to identify a comprehensive list of vulnerable devices and chipsets as numerous wireless routers are affected by this vulnerability.

As part of its disclosure process, Synopsys engaged with all the manufacturers of the devices it tested. After reaching out to each manufacturer, the company only received a response from Zyxel though Mediatek notified D-Link regarding the matter during the disclosure process. Both Zyxel and D-Link confirmed that they have patches ready to fix the issue and these will be made available to their affected customers.

Authentication bypass vulnerability

According to a new blog post from Synopsys, the vulnerability allows an attacker to inject packets into a WPA2-protected network without knowledge of the preshared key. 

Upon injection, these packets are routed through the network in the same way valid packets are and responses to the injected packets return encrypted. However, since an attacker exploiting this vulnerability can control what is sent through the network, they would eventually be able to ascertain if the injected packets successfully reached an active system.

As a proof-of-concept, Synopsy researchers were able to open a UDP port in a router's NAT by injecting UDP packets into a vulnerable WPA2-protected network. The packets were able to route through the public internet before they were eventually received by an attacker-controlled host listening on a defined UDP port. Upon receiving this response, the attacker-controlled host can then use this opened UDP port to communicate back to the vulnerable network.

While access point manufacturers whose devices include the identified chipset can request patches from Mediatek and Realtek, end users with vulnerable access points are strongly encouraged to upgrade their devices as soon as possible or replace vulnerable access points with another access point.



from TechRadar - All the latest technology news https://ift.tt/2GIxZfy

Best indoor home security cameras to buy in 2020 - CNET

Find out which indoor security cameras are the best at keeping an eye on your home.

from CNET https://ift.tt/2FFDFq7

NBA Finals: How to watch Lakers vs. Heat Game 4 tonight on ABC - CNET

The Miami Heat won on Sunday to make it a series against the Los Angeles Lakers. Game 4 tips off Tuesday night.

from CNET https://ift.tt/3d3s4Oh

How you may be able to break the sound barrier again - CNET

On Wednesday morning, Boom Supersonic will unveil the demonstrator aircraft for its planned commercial supersonic plane. You can watch the event here.

from CNET https://ift.tt/33BBddL

Volvo XC40 Recharge electric SUV only manages 208 miles of range, EPA says - Roadshow

Why is this so much worse than the Polestar 2 that shares a platform with the Recharge?

from CNET https://ift.tt/36DVvVH

Mercedes-Benz wants to electrify and expand AMG, G and Maybach - Roadshow

It also wants to grow EQ and refocus on its history as a luxury brand.

from CNET https://ift.tt/2GA5ReF

How to watch Mars get in close to Earth on Tuesday night - CNET

Mark your calendars for a Mars close approach on Oct. 6 and opposition on Oct. 13.

from CNET https://ift.tt/2SuWdwi

SpaceX wins contract to build missile tracking satellites for US military - CNET

Starlink isn't just for broadband anymore.

from CNET https://ift.tt/34x802F

12 cookbooks with low-sugar recipes for diabetic, paleo and keto dieters - CNET

Regardless of why you're cutting sugar and carbs, there are lots of cookbooks out there to help make it taste great.

from CNET https://ift.tt/3loIqnB

Second stimulus check could bring you a bigger payment, whenever it comes - CNET

Before the talks to work out a deal came to a sudden stop, negotiators were closing in on a new rule that could bring your family more money than the first check.

from CNET https://ift.tt/2FcUGYU

The $300 unemployment payment is over in many states with little hope of an extension - CNET

President Trump killed negotiations to provide more stimulus money for unemployed workers on Tuesday, making the future of extra weekly payments uncertain. Here's what you need to know.

from CNET https://ift.tt/33CZnVb

Monday, October 5, 2020

Dune movie remake: Trailer, cast, plot and more for Denis Villeneuve's sci-fi epic - CNET

Here's everything we know about the upcoming Dune movie, based on the book series by Frank Herbert, tentatively scheduled to be released in 2021.

from CNET https://ift.tt/2GDmIgn

Best identity theft protection and monitoring services in 2020 - CNET

Is someone applying for a mortgage in your name? Ruining your credit? The best identity theft protection and monitoring service can help you find out -- and fight back.

from CNET https://ift.tt/3j8GL48

The Batman has been delayed to 2022 - CNET

While Dune's delay has been made official and The Matrix 4 has been moved -- wait for it -- forward.

from CNET https://ift.tt/30zmluA

New stimulus check: 9 things you need to know now that Trump has COVID, House passed a bill - CNET

It's been a long, drawn-out journey to secure another round of direct payments. We'll keep the details simple.

from CNET https://ift.tt/3jCUscn

Here Are the Best Nintendo Switch 2 Deals to Snag Before the Price Increases

Nintendo recently announced a $50 price increase on the Nintendo Switch 2, so any discount available now is well-worth considering. We'v...