RyotaK

@ryotak.net

Security researcher? | Icon: https://twitter.com/MelvilleTw | Keybase: http://keybase.io/ryotak | Threads: http://threads.net/ryotkak | Misskey: http://misskey.io/@ryotak

[PSA] If you're using OpenWrt router and have used the Attended sysupgrade, firmware-selector.openwrt[.]org or CLI upgrade previously, I recommend you to re-flash your firmware. Due to a security issue, it was possible to pollute the firmware images delivered to these tools. (1/2)

OpenWrtのビルド用サーバーに脆弱性を報告しました。 Attended sysupgrade、firmware-selector.openwrt[.]orgあるいはCLIからのアップグレードを過去に実施した場合、改ざんされたファームウェアが配信された可能性が完全には否定できないため、ファームウェアの再更新を推奨します。 技術的解説についてはこちらの記事をご確認ください。 flatt.tech/research/pos... 公式からの発表はこちらをご覧ください。 lists.openwrt.org/pipermail/op...

Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection

Introduction Hello, I’m RyotaK (@ryotkak ), a security engineer at Flatt Security Inc. A few days ago, I was upgrading my home lab network, and I decided to upgrade the OpenWrt on my router.1 After ac...

flatt.tech