Full Disclosure mailing list archives

ELSA Lancom Router Discloses the Administrator Password to Remote Users


From: winsoc <winsoc () googlemail com>
Date: Wed, 31 Aug 2005 11:25:33 +0200


It is reported that the default configuration allows a remote user to 
connect to the router via port 80 with a web browser and obtain the remote 
access password, which is apparently stored in clear text. The remote user 
can also change the router's configuration and can remotely upgrade the 
firmware. 

 *Impact:* A remote user can obtain the administrator password, change 
routing tables, and upload modified firmware.
  *Solution:* No solution was available at the time of this entry.

The author of the report has provided the following recommendations:

- Change the configuration port. 
- Give access privileges during initial configuration to only internal ip 
addresses.
- Install a firewall with appropriate rules.

 Does anyone know how to get this P/W?
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: