[Full-disclosure] ELSA Lancom Router Discloses the Administrator Password to Remote Users

From: winsoc (winsoc_at_googlemail.com)
Date: 08/31/05

  • Next message: Martin Schulze: "[Full-disclosure] [SECURITY] [DSA 792-1] New pstotext packages fix arbitrary command execution"
    Date: Wed, 31 Aug 2005 11:25:33 +0200
    To: full-disclosure@lists.grok.org.uk
    
    
    

    >
    > It is reported that the default configuration allows a remote user to
    > connect to the router via port 80 with a web browser and obtain the remote
    > access password, which is apparently stored in clear text. The remote user
    > can also change the router's configuration and can remotely upgrade the
    > firmware.
    >
     *Impact:* A remote user can obtain the administrator password, change
    routing tables, and upload modified firmware.
      *Solution:* No solution was available at the time of this entry.

    The author of the report has provided the following recommendations:

    - Change the configuration port.
    - Give access privileges during initial configuration to only internal ip
    addresses.
    - Install a firewall with appropriate rules.

     Does anyone know how to get this P/W?

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/


  • Next message: Martin Schulze: "[Full-disclosure] [SECURITY] [DSA 792-1] New pstotext packages fix arbitrary command execution"

    Relevant Pages

    • Re: VPN client disconnects
      ... laptop still DC'd like clockwork...... ... This platform has an ASA 5505 Security Plus license. ... Configuration last modified by timparker at 09:05:26.038 EDT Fri Apr 3 ... I need to try and help the remote user ...
      (comp.dcom.sys.cisco)
    • Join domain without configuring Outlook
      ... We have a remote user that has Outlook over the Internet already configured. ... printers we don't want the current Outlook configuration to be altered. ... What's the preferred method, join the laptop to the domain manually or by ...
      (microsoft.public.windows.server.sbs)
    • Linked Servers & index access
      ... I'm looking at the linked server configuration and am stuck on a why ... if you want a remote user to be able to use the indexes on ...
      (microsoft.public.sqlserver.server)
    • Re: SSH port 22 is invisible from the internet!! :(
      ... I want to allow a remote user to login with ssh on to my system. ... I use iptables as a firewall and have added a rule to open the port 22: ...
      (Debian-User)
    • Re: Getting alot of failed logins to my SBS 2003 Server
      ... to get 400mb+ files from a remote user on a Mac to my server w/o using ... which like an idiot I had left to the default port. ... Re blocking at all, unless you're using ISA, ...
      (microsoft.public.windows.server.sbs)