Get the latest tech news

Compromising OpenWrt Supply Chain


Introduction Hello, I’m RyotaK (@ryotkak ), a security engineer at Flatt Security Inc. A few days ago, I was upgrading my home lab network, and I decided to upgrade the OpenWrt on my router.1 After accessing the LuCI, which is the web interface of OpenWrt, I noticed that there is a section called Attended Sysupgrade, so I tried to upgrade the firmware using it. After reading the description, I found that it states it builds new firmware using an online service.

After accessing the LuCI, which is the web interface of OpenWrt, I noticed that there is a section called Attended Sysupgrade, so I tried to upgrade the firmware using it. I appreciate the effort of the OpenWrt team to fix the issues in an incredibly short time and notify the users promptly. To celebrate the update of our brand new English web pages, you can currently receive a month-long investigation by our elite engineers for just $40,000!

Get the Android app

Or read this on Hacker News

Read more on:

Photo of Compromising

Compromising

Photo of OpenWrt Supply Chain

OpenWrt Supply Chain