[NEWS] ELSA Lancom 1100 Office Security Problems
From: support@securiteam.comDate: 01/02/02
- Previous message: support@securiteam.com: "[UNIX] Cherokee Webserver Directory Traversal and Elevated Privileges Vulnerabilities"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: support@securiteam.com To: list@securiteam.com Date: Wed, 2 Jan 2002 08:07:28 +0100 (CET)
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -
ELSA Lancom 1100 Office Security Problems
------------------------------------------------------------------------
SUMMARY
Phoenix Sistemi Security reports several security problems in
<http://www.elsa.com/international/europe/produkte/netzwerk/lc_1100_off.htm> ELSA Lancom 1100 Office. An attacker can steal the RAS password, change routing tables, and place a modified firmware to sniff data.
DETAILS
Vulnerable systems:
ELSA Lancom 1100 Office
ELSA Lancom 1100 Office has to be configured by browser on an HTTP
connection over port 80 on the router IP. An intruder can connect with a
browser to the router ip (Intranet or Internet) and change the routing
tables or steal the RAS password that is stored in a field covered with
asterisks. The passwords are stored in clear text and can be seen by
editing the html source.
That is not all; the upgrade of the firmware could be done remotely just
going in its appropriate page placed in the configuration table, and an
attacker can upgrade a customized firmware that will sniff all the data
passing by the router.
Solutions & Recommendations:
Changing the configuration port is a good idea to prevent random attacks.
Another good idea would be to give access privileges to first-time
configuration just to an internal ip addresses. The RAS password should be
stored in a file different from the html, or that part of configuration
could be done with a JavaScript.
An easy user-side solution could be to install a firewall with appropriate
rules, so that no one from the Internet would have access to it.
ADDITIONAL INFORMATION
The information has been provided by <mailto:security@phx.it> Davide Del
Vecchio.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: support@securiteam.com: "[UNIX] Cherokee Webserver Directory Traversal and Elevated Privileges Vulnerabilities"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
- Solaris Security Summary
... Administering Security on the Solaris OE ... Configuration control,
facility management, and system ... Authentication: The ability to prove who you are. ...
(comp.unix.solaris) - Re: DCOM calls fails - access denied
... That's exactly how I understood the ASP.NET security. ... But why does one configuration
work but not the other? ... should get the token from IIS. ... If you set there
a domain account, ... (microsoft.public.dotnet.framework.aspnet.security) - [TOOL] LogAgent, ASCII Log Monitor
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... LogAgent tries to fill that gap
by monitoring the log files on ... for network-wide log file centralization. ...
# This program gets its configuration from the file config.txt, ... (Securiteam) - Re: Wireless Access Point on external router?
... The security configuration Owen has documented uses WPA2, ... it will work automatically
for any wireless client PC that you ... switch to RWW and stop caring about VPN).
... (microsoft.public.windows.server.sbs) - RE: [Full-Disclosure] Name One Web Site Compromised by Download.Ject?
... look at their security and have clauses in the contracts indicating what can ...
configuration was IT Director with a few analysts reporting through CFO. ... in stupid
things or under stupid management they don't have the time to put ... The 17 year old hackers
have all of the time in ... (Full-Disclosure)