In February this year, researchers at the David Ben-Gurion University (Israel) told how to use the LED indicators to load a hard drive to steal data from a computer that is not connected to the Internet. Now, scientists used this method in relation to the indicators of the router.
The attractiveness of the attack is obvious - having received administrator credentials with the help of flashing lights, attackers can hack not only one computer, but the entire network as a whole. However, the attack is not so easy. First, first it is necessary to compromise the router itself, and secondly, near the device you need to install a sensor that catches the signals of indicators.
A team of researchers at the David Ben-Gurion University, led by Mordechai Guri, created a special firmware called xLED, which adds LED control to the router.
Without the firmware, you can get by if the attacker manages to increase his privileges and execute a malicious script.
After gaining control over LED indicators, attackers can cause them to flash in a special way, transmitting information using a cipher. Using a video camera, attackers can fix flicker and decrypt data. The transmission speed of information in this case does not exceed 1 Kb / s. It is much more efficient to fix flicker with optical sensors that increase the data transfer rate up to 3.5 Kb / s.