Nmap Development mailing list archives

D-link HNAP vuln


From: kx <kxmail () gmail com>
Date: Tue, 12 Jan 2010 12:28:40 +0100

http://www.sourcesec.com/Lab/dlink_hnap_captcha.pdf

Has anyone played with this yet? I don't have a d-link router, and I
am in an odd sorts right now, so I can't try to whip up an NSE script,
but I think it could be interesting, even just seeing the output of
GetDeviceSettings as a non-intrusive script.

Any idea how many other devices support HNAP? If there were enough
devices that returned responses, it might even be worthwhile as a
Probe.

I am hoping to get back to development soon (weeks), and I'd like to
learn LUA, so I will look into this in time, but someone else might
have more experience and better access to equipment.

Cheers,
  kx
_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://seclists.org/nmap-dev/


Current thread: