BEFSR81 SNMP Community String Information Disclosure Vulnerability

From: franck dunter (dunter76_at_hotmail.com)
Date: 06/26/03

  • Next message: Paul Starzetz: "Linux 2.4.x execve() file read race vulnerability"
    Date: 26 Jun 2003 08:03:54 -0000
    To: bugtraq@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is)

    same bug http://www.securityfocus.com/bid/7317
    but for the model BEFSR81

    After my scan whit nmap, i just found SNMP open (port 161 udp).

    I scan the MIB, i found some thing very interesthing.
    on plages
    enterprises.3955.3.4.1.12.0 : the username
    enterprises.3955.3.4.1.13.0 : the password
    this bug is good for all ISP whit PPPoE on router lynksys.

    i send one before but to many useless thing on it
    please publish this one not thr other


  • Next message: Paul Starzetz: "Linux 2.4.x execve() file read race vulnerability"

    Relevant Pages

    • fat32 corruption
      ... The bug was written against 4.6 but it does not ... slot 31 INTC routed to irq 23 ... <Parallel port bus> on ppc0 ... can't assign resources ...
      (freebsd-questions)
    • Re: Address book grabbing, and Printer out of Paper
      ... > more frequent AV runs for possible detection. ... > that plug into the parallel port. ... > - How can I detect/resolve this address book grabber bug that seems to ... > Ken Burgess ...
      (microsoft.public.security)
    • [Full-disclosure] Solaris Socket Hijack - solsockjack.c
      ... Hijack Bug ... Solaris has a bug in the use of SO_REUSEADDR in that the Kernel favours any ... a work around could be setting the port numbers that are valuable to ... usage(int argc, char **argv) ...
      (Full-Disclosure)
    • [NEWS] LG Electronics LG3100p Router Multiple Security Issues (DoS)
      ... Release 1.50 is vulnerable only to first and third bug. ... When configured without access lists protecting port 23, ... First is exploitable without any access to user account on the router. ... The vendor representative was informed about the vulnerabilities on ...
      (Securiteam)
    • [UNIX] Solaris Socket Hijack Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... By binding a socket with an already binded port number of specific IP ... attackers can hijack an already binded sockets in Solaris. ... A bug with Solaris Kernel flag of SO_REUSEADDR cause the Kernel to accept ...
      (Securiteam)