|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
If you have found a vulnerability, please send to our SecurityAlert Database : secalert()securityreason()com
Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com |
|
|
Home SecurityAlert Database |
|
|
Topic : | DoS 2wire Gateway
|
SecurityAlert : 1489
CVE : CVE-2006-4523
SecurityRisk : Low (About)
Remote Exploit : Yes
Local Exploit : Yes
Exploit Available : Yes
Credit : PRETH00NKER
Published : 05.09.2006
Affected Software : | 2 w i r e G a t e w a y |
 Advisory Content : [Refer:http://www.mexhackteam.org/prethoonker/DoS_ADV_2Wire.txt]
#################################################### << Denegation
of Service >>
### 2 w i r e G a t e w a y
###
### Preth00nker [at] gmail [dot] com
### BY PRETH00NKER
### http://mexhackteam.org
###
### Special dedication for my friends of:
### < < http://www.elhacker.net > >
###
######################################################
[ Introduction ]
(*) 2wire Gateway User Interface: It Work with the Modems / Routers
of 2Wire, Inc., it take the work out of manage a local network.
the Users see important information about the DSL connection,
devices on the network, firewall logs, and more. Optional notification
features let users know if there is a problem and guides them to a fix.
(*) CRLF: It's a special character or sequence of characters
signifying the end of a line of text.
[Char] [ Complete name ] [Hex] [ascii]
CR = Carriage Return = A = 10
LF = Line_Feed = D = 13
[ Explanation ]
When a evil request is maked and sended at 2wire Webserver
and this can't process the request, result as a Denegation
of service (DoS).
The error comes at the moment of include a End_of_line (CRLF)
into any variable, when we're using a GET method it's
imposible (inside a normal situation), but, it's really true?..
[ PoC ]
http://www.mexhackteam.org/prethoonker/DoS%20%20.cpp
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|
|
|
|