Zoklet.net

Go Back   Zoklet.net > Technology > Network Security & Hacking

Reply
 
Thread Tools
  #1  
Old 06-02-2009, 06:45 PM
Dfg Dfg is offline
Grander Duke
 
Join Date: Jan 2009
Location: Pakistan
Thanks: 53
Thanked 976 Times in 738 Posts
Send a message via MSN to Dfg Send a message via Skype™ to Dfg
Thumbs Up Hack: Linksys WAG54G2 - escape to OS root

Well, the hack is pretty simple and it's open for anyone to try it.
Quote:
When you are logged in to the web administration, simple injection leads to OS root access.

Cisco root OS escape

Many characters lead to injection, including at least:

* ;
* &
* |
* `` (backquotes)
* %a0

As you might have noticed, the above request is used with default administration credentials (admin/admin). It can be exploited using CSRF and these credentials (assuming a user did not change default user/password). But it is not as straightforward as in our other research: ASMAX router compromise.

One can still backdoor the router having access to web administration. Another outcome of the bug is an ablility to quite easily examine what services are running on the router, what is its internal configuration, etc. It may be a hint to find some more interesting vulnerabilities.

Also if one could find auth bypass vulnerability in http server / management software it can lead to easy full remote router compromise, as described in the ASMAX case.
Read the full article: http://www.securitum.pl/dh/Linksys_W...ape_to_OS_root

An example : http://www.securitum.pl/dh/asmax-ar-804-gu-compromise

Good Luck.
Reply With Quote
Reply

Bookmarks

Tags
escape, hack, linksys, root, wag54g2

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Do you ever root for the criminals? Actor Generally Speaking 33 12-16-2009 01:30 AM
happy square root day everyone! John Bat Country 21 03-04-2009 01:36 AM
Happy square root day! Haiti's Space Agency Bat Country 9 03-03-2009 12:50 PM
Totse linksys chats? I'mAfraidofJapan Generally Speaking 19 02-15-2009 01:57 AM


All times are GMT. The time now is 02:50 PM.


Hot Topics
On IRC
Users: 4
Messages/minute: 0
Topic: "http://www.zoklet.net/..."
Users: 14
Messages/minute: 0
Topic: "ask ibm why atlantis is real"
Users: 8
Messages/minute: 0
Topic: "vaginaboob"
Advertisements
Your ad could go right HERE! Contact us!

Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.