Full Disclosure mailing list archives
ELSA Lancom Router Discloses the Administrator Password to Remote Users
From: winsoc <winsoc () googlemail com>
Date: Wed, 31 Aug 2005 11:25:33 +0200
It is reported that the default configuration allows a remote user to connect to the router via port 80 with a web browser and obtain the remote access password, which is apparently stored in clear text. The remote user can also change the router's configuration and can remotely upgrade the firmware.
*Impact:* A remote user can obtain the administrator password, change routing tables, and upload modified firmware. *Solution:* No solution was available at the time of this entry. The author of the report has provided the following recommendations: - Change the configuration port. - Give access privileges during initial configuration to only internal ip addresses. - Install a firewall with appropriate rules. Does anyone know how to get this P/W?
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- ELSA Lancom Router Discloses the Administrator Password to Remote Users winsoc (Aug 31)