RE: NETGEAR DG834G SPECIAL FEATURES

From: Andre Lorbach (alorbach_at_ro1.adiscon.com)
Date: 08/13/04

  • Next message: T.H. Haymore: "Re: JS/Zerolin"
    Date: Fri, 13 Aug 2004 12:22:46 +0200
    To: <thanasonic@hack.gr>, <bugtraq@securityfocus.com>
    
    

    > -----Original Message-----
    > From: thanasonic@hack.gr [mailto:thanasonic@hack.gr]
    >
    > By opening http://192.168.0.1/setup.cgi?todo=debug you enable
    > the router's debug mode.Then you just telnet at 192.168.0.1
    > at port 23 and then you have a root shell.
    >
    > Also i found that if you just telnet to 192.168.0.1 2602 you
    > will get a prompt from the service ZEBRA that is running on
    > the router.By giving "zebra" as password *which is the
    > default password* you got also a root shell.

    Wow! That's exactly the router I have and these exploits work *fear*.
    Fortunately, only on the local network, but they work!

    With what Firmware version did you test? I still have 1.04 here.

    Best regards,
    Andre Lorbach


  • Next message: T.H. Haymore: "Re: JS/Zerolin"

    Relevant Pages

    • Re: BASH as root shell (static linking)
      ... I'm wanting to use BASH as my root shell, ... As another poster stated in this thread, use the static option of the port. ...
      (freebsd-questions)
    • Re: root shell
      ... really would like to set another root shell. ... I solve this little problem by creating a bash script that sets everything I need for a comfortable root experience. ... P.S. you can remove the ANSI prompt and set it to black and white by typing "norm" any time. ...
      (comp.unix.solaris)