SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

Belkin Wireless G Plus MIMO Router F5D9230-4 Authentication Bypass Vulnerability


Arrow  SecurityAlert : 3566
Arrow  CVE : CVE-2008-0403
Arrow  SecurityRisk : Medium  Security Risk Medium  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : Yes
Arrow  Exploit Available : Yes
Arrow  Credit : darkfig
Arrow  Published : 23.01.2008

Arrow  Affected Software : Belkin Wireless G Plus MIMO Router



Arrow  Advisory Content :  

##

## VULNERABILITY:

##

## Belkin Wireless G Plus MIMO Router F5D9230-4

## Authentication Bypass Vulnerability

##

##

## AUTHOR:

##

## DarkFig < gmdarkfig (at) gmail (dot) com >

## http://acid-root.new.fr/?0:17

## #acidroot (at) irc.wordlnet (dot) com [email concealed]

##

##

## INTRODUCTION:

##

## I recently bought this router for my local

## network (without modem integrated), now I can tell

## that it was a bad choice. When my ISP disconnects

## me from internet, in the most case I have to reboot

## my Modem and the Router in order to reconnect.

## So I coded a program (which send http packets) to reboot

## my router, it asks me the router password, and reboots it.

## One day I wrote a bad password, but it worked. So I

## decided to make some tests in order to see if there was

## a vulnerability.

##

##

## DESCRIPTION:

##

## Apparently when we the router starts, it create a file

## (without content) named user.conf, then when we go to

## SaveCfgFile.cgi, the configuration is save to the file

## user.conf. But the problem is that we can access

## (and also change) to the file SaveCfgFile.cgi without

## login.

##

##

## PROOF OF CONCEPT:

##

## For example we can get the configuration file here:

## http://<ROUTER_IP>/SaveCfgFile.cgi

##

## pppoe_username=...

## pppoe_password=...

## wl0_pskkey=...

## wl0_key1=...

## mradius_password=...

## mradius_secret=...

## httpd_password=...

## http_passwd=...

## pppoe_passwd=...

##

##

## Tested on the latest firmware for this product

## (version 3.01.53).

##

##

## PATCH

##

## Actually there is no firmware update, but I contacted the

## author, if they'll release a patch, it will be available here:

## http://web.belkin.com/support/download/download.asp

## ?download=F5D9230-4〈=1&mode=

##






Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

PHP RSS PHP Alert

» PHP Hashtables Denial of
   Service

» PHP 5.3.6 multiple null
   pointer dereference

» PHP 5.3.6 ZipArchive
   invalid use glob(3)

» libzip 0.9.3
   _zip_name_locate NULL
   Pointer Dereference (incl
   PHP 5.3.5)

ADT

Protect your family and valuables with Home Security Systems

Copyright © SecurityReason.com. All Rights Reserved.