Visualizzazione post con etichetta hardware. Mostra tutti i post
Visualizzazione post con etichetta hardware. Mostra tutti i post

Sitecom WLM-2501 Change Wireless Passphrase

Posted on martedì 13 marzo 2012 by Ivano Binetti

Yesterday I've discovered new CSRF vulnerabilities in Sitecom WLM-2501 300N wireless modem/router which allow an attacker to change a lot of device parameter and, most of all, to change wireless passphrase.

To know more about these vulnerabilities please read my Original Advisory.

Other sources have published my Advisory:
Packet Storm
Offensive Security Exploit-DB
Inj3ct0r

IBM X-Force published my D-Link DSL-2640B Advisories

Posted on domenica 26 febbraio 2012 by Ivano Binetti

Today IBM X-Force published two of my advisories related to vulnerabilities discoverd into D-Link DSL-2640B ADSL Router / Access Point.
If you would like to read more about them:
http://xforce.iss.net/xforce/xfdb/73316
http://xforce.iss.net/xforce/xfdb/73379

IBM X-Force published my Cisco Linksys WAG54GS Advisory

Posted on by Ivano Binetti

Today IBM X-Force has published my Advisory related to a security flaw which I've discovered in Cisco Linksys WAG54GS router which allow an attacker to change administrator password.

For more informations:
http://xforce.iss.net/xforce/xfdb/73345

D-Link DSL-2640B "0day" Vulnerabilities

Posted on giovedì 23 febbraio 2012 by Ivano Binetti

SecurityFocus (http://www.securityfocus.com/) has assigned me three BID (Bugtraq ID) related to "0day" Dlink and Cisco Linksys vulnerabilities regarding design flaws and exploitable using CSRF:

Following you can read more details about them:
http://www.securityfocus.com/bid/52096
http://www.securityfocus.com/bid/52129
http://www.securityfocus.com/bid/52105

D-Link DSL-2640B Authentication Bypass

Posted on mercoledì 22 febbraio 2012 by Ivano Binetti

New "0day" vulnerability found.
For more details:

http://www.exploit-db.com/exploits/18511/
http://packetstormsecurity.org/files/110117/D-Link-DSL-2640B-Authentication-Bypass.html
http://www.securityfocus.com/bid/52129

Cisco Linksys WAG54GS (ADSL Router) change admin password

Posted on martedì 21 febbraio 2012 by Ivano Binetti

Today I found a new "0day" vulnerability into Cisco Linksys WAG54GS Wifi Adsl Router and published related exploit in order to change default administrator ("admin") password. For more details:

http://www.exploit-db.com/exploits/18503/
http://packetstormsecurity.org/files/110040/Cisco-Linksys-WAG54GS-Cross-Site-Request-Forgery.html
http://www.securityfocus.com/bid/52105

You can simply modify this exploit in order to change other router's parameters.
Enjoy it!

D-Link DSL-2640B (ADSL Router) CSRF "0day" Vulnerability

Posted on lunedì 20 febbraio 2012 by Ivano Binetti

I've discovered a new "0day" vulnerability:

http://www.securityfocus.com/bid/52096/info
http://www.exploit-db.com/author/?a=3557
http://packetstormsecurity.org/files/author/9536/

This vulnerability allows to change administrator password of D-Link DSL-2640B ADSL Router.