Penetration Testing mailing list archives

Re: Cayman Router


From: Russell Handorf <rhandorf () mail russells-world com>
Date: Wed, 14 Nov 2001 13:03:10 -0500

http://www.securityfocus.com/bid/3017

to escalate privs, go to the webpage, and then where it has the passwords in the fields.... view the source of the webpage (passwords are there clear text).

for more and better information regarding this, talk to adrian lamo.

At 05:13 AM 11/14/2001 -0800, you wrote:
I have come across a Cayman router which still has the
default password set as blank, however I am classified
only as a user not admin.

Can anyone supply any help in how to show the client
that this is dangerous or esculate priv to admin ?

Regards


__________________________________________________
Do You Yahoo!?
Find the one for you at Yahoo! Personals
http://personals.yahoo.com

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/

==================================
Russell Handorf
oooo, shiney ::Wanders after it::

www.russells-world.com
www.inside-aol.com
www.terrorists.net
www.bad-mother-fucker.org
www.philly2600.net

"Computer games don't affect kids, I mean if Pacman affected us as kids, we'd all be running around in darkened rooms, munching pills and listening to repetitive music." ~unknown
==================================

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/


Current thread: