Re: Linksys WRT54G Denial of Service Vulnerability

Eerik.Kiskonen_at_toptronics.fi
Date: 12/05/03

  • Next message: Shaun Colley: "Jason Maloney's Guestbook XSS Vulnerability."
    To: Michael Renzmann <security@dylanic.de>
    Date: Fri, 5 Dec 2003 16:47:41 +0200
    
    

    Buffalo WBR-G54 (Firmware 1.30) is not vulnerable. It answers with "bad
    request" and the http server continues working without problems.

    ---- clip ---
    [stnz@starship stnz]# nc 192.168.11.1 80
    GET
    HTTP/1.0 400 Bad Request
    Server: micro_httpd
    Date: Tue, 01 Jan 2002 06:04:15 GMT
    Content-Type: text/html
    Connection: close

    <HTML><HEAD><TITLE></TITLE><meta http-equiv="Pragma"
    content="no-cache"></HEAD>
    <BODY BGCOLOR="#FFFFFF">
    Can't parse request.
    ---- clip ---

    -
    Ystävällisin terveisin/Best Regards
    Turun Tietokeskus Oy/Eerik Kiskonen
    Tekninen asiantuntija/Technical specialist
    Satakunnantie 110, 20320 TURKU, Finland
    Direct. +358-2-273 4244
    Fax. +358-2-273 4220
    E-mail: eerik.kiskonen@toptronics.fi
    Web. http://www.turuntietokeskus.fi

    Michael Renzmann <security@dylanic.de>
    04.12.2003 06:33

     
            To: test@techcentric.net
            cc: bugtraq@securityfocus.com
            Subject: Re: Linksys WRT54G Denial of Service Vulnerability

    Hi all.

    test@techcentric.net wrote:
    > Linksys WRT54G Denial of Service Vulnerability

    There are some devices out there that are technically identical to the
    WRT54G (for example the Buffalo WBR-G54). Can anyone confirm whether
    they share this issue?

    Bye, Mike


  • Next message: Shaun Colley: "Jason Maloney's Guestbook XSS Vulnerability."

    Relevant Pages

    • [NT] Multiple Vulnerabilities in PY Software Active Webcam WebServer
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... including Denial of Service and Information Disclosure. ... Floppy Disk Request Denial of Service: ... be paused, that means the other user cannot access the HTTP Server, thus ...
      (Securiteam)
    • HTTP server problem when running two clients
      ... A client sends 100 requests in a sequentially order. ... When I run the HTTP server with one client it works ok. ... HINTERNET hRequest = NULL; ... // Create an HTTP Request handle. ...
      (microsoft.public.win32.programmer.networks)
    • HTTP client socket inputstream help
      ... resource from an http server. ... the InputStream from the socket is coming up empty after requesting the ... the request has been received from the http server because I'm also ...
      (comp.lang.java.programmer)
    • HTTP SERVER (httpsv1.6.2) 404 Denial of Service
      ... HTTP SERVER 404 Denial of Services ... If u send to the server between 40-1000 requests to nonexisting pages the process will die. ... Bug Found By Prili - impriligmail.com ... print $socket $request; ...
      (Bugtraq)
    • Re: interconnection between two processes
      ... PB> The HTTP server will fork a new CGI process for each request. ... PB> - unix sockets ...
      (comp.unix.programmer)

    Loading