Likes Likes:  0
Resultaten 1 tot 6 van de 6
Geen
  1. #1
    cw
    Asus AAM6000EV ADSL Router Wide Open
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Asus AAM6000EV ADSL Router Wide Open

    Asus have been notified but haven't even acknowledged yet alone mentioned a=
    fix.

    If the inbuilt webserver is activated, anyone on the local network can get=
    the full user/pass list from the router without any identification=
    whatsoever by going to the ip address of the router and appending=
    /userdata
    Example, say the ip address is 192.168.0.1, go to:

    http://192.168.0.1/userdata

    This will output the contents of the userdata file which contains completely=
    unencrypted usernames and passwords. There are plenty of other files that=
    can be access with this trick, I haven't looked at the content of them so I=
    don't know what else you can do.

    This security flaw arises because the webserver on the router is mapped to=
    index.html which provides a link to /secure/Home.htm

    You are not prompted for a password until you attempt to access files under=
    /secure

    Telnet to the router, enter the user mode console and then type "flashfs"

    Type ls to see all configuration files accessible through this flaw.


  2. #2
    Michael Renzmann
    Asus AAM6000EV ADSL Router Wide Open
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Asus AAM6000EV ADSL Router Wide Open

    Hi all.

    I can confirm this behaviour for the following product:
    Asus AAM 6330BI, firmware version 71238a11

    This device is for example delivered by the german DSL-provider NetCologne.

    cw wrote:
    > If the inbuilt webserver is activated, anyone on the local network
    > can get the full user/pass list from the router without any
    > identification whatsoever by going to the ip address of the router
    > and appending /userdata Example, say the ip address is 192.168.0.1,
    > go to:
    >
    > http://192.168.0.1/userdata


    The format of the data that gets displayed there is:
    <username>.<password>.<service class>.<status>.

    The same data can be accessed by telnetting to the device and choosing
    the menu-path "System Maintenance / User Maintenance / List User" (6/5/4).

    > Telnet to the router, enter the user mode console and then type
    > "flashfs"
    > Type ls to see all configuration files accessible through this flaw.


    In order to reach the command prompt where you can enter this command
    (amongst other) you have to choose option "9. Exit User Mode Console"
    from the main menu. "help" lists all available commands.

    As mentioned by the original poster, use:
    192.168.1.1> flashfs
    192.168.1.1 flashfs> ls



    Another password disclosure: in the above mentioned device there is a
    file "snmpinit". If it is accessed by the browser (for example with
    http://192.168.1.1/snmpinit ) the read and write community strings of
    the device's snmp interface will be shown. The content of every file
    also can be accessed with "cat", for example:

    192.168.1.1 flashfs> cat snmpinit

    With my own device, the data disclosed is of the following format:

    access read <read community string>
    access write <write community string>



    It would be interesting to learn if it is possible for someone to use
    the HTTP-method "PUT" in order to change the content of the file
    "userdata" without having to know its content. I'm not brave enough to
    test it since I'm in need of a working DSL modem

    Bye, Mike


  3. #3
    Ben Wheeler
    Asus AAM6000EV ADSL Router Wide Open
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Asus AAM6000EV ADSL Router Wide Open

    On Mon, Jul 14, 2003 at 07:45:38PM +0100, cw wrote:
    > Asus have been notified but haven't even acknowledged yet alone mentioned a fix.
    >
    > If the inbuilt webserver is activated, anyone on the local network
    > can get the full user/pass list from the router without any identification


    It's far worse than that, if the state in which my router was supplied is
    typical. As I received it, the webserver was enabled by default, *and*
    was accessible from the internet as well as the local network. I had to
    explicitly set up ip_filter rules to restrict access (the same goes for
    telnet access by the way). Worse, there was a bug which caused ip_filter
    rules not to be saved properly, so they were not restored after a reset.
    Fortunately this has been fixed in the last flash update (71205a32) but
    this same update also removes the requirement to specify a username.
    You now only need any one of the valid passwords to login. Asus really
    don't seem to have a clue. Finding out what has changed between the flash
    versions, either from them or from Solwise the UK distributors, is impossible.

    It takes a particularly special kind of incompetence to keep the passwords
    unencrypted and accessible via the webserver. I certainly won't be buying
    another of their products.

    The only workaround I know of is to set up ip_filter rules, which is way
    beyond the capabilities of most home users (truthfully, quite a number
    may not even have changed the default login password). I'm not aware of
    any way to disable the httpd completely. Anyone?

    Ben Wheeler


  4. #4
    cw
    Asus AAM6000EV ADSL Router Wide Open
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Asus AAM6000EV ADSL Router Wide Open

    On Tue, 15 Jul 2003 14:01:34 +0100, Ben Wheeler wrote:
    >=A0It's far worse than that, if the state in which my router was
    >=A0supplied is typical. As I received it, the webserver was enabled by
    >=A0default, *and* was accessible from the internet as well as the
    >=A0local network.


    I too got my router from Solwise however I do not find this to be the case.=
    I have no ip filters set up yet both the telnet and web servers are only=
    accessible from the local network. This was true with both 71205a10 and=
    71205a32 firmware.

    > Fortunately this
    >=A0has been fixed in the last flash update (71205a32) but this same
    >=A0update also removes the requirement to specify a username. You now
    >=A0only need any one of the valid passwords to login.


    I did notice that too

    *waits for another round of out of office/dead mailbox auto-responders*


  5. #5
    Michael Renzmann
    Asus AAM6000EV ADSL Router Wide Open
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Asus AAM6000EV ADSL Router Wide Open

    Hi all.

    cw wrote:
    >> It's far worse than that, if the state in which my router was
    >> supplied is typical. As I received it, the webserver was enabled by
    >> default, *and* was accessible from the internet as well as the
    >> local network.

    > I too got my router from Solwise however I do not find this to be the
    > case. I have no ip filters set up yet both the telnet and web servers
    > are only accessible from the local network. This was true with both
    > 71205a10 and 71205a32 firmware.


    As for the device I have in use here (delivered pre-configured from my
    provider): not reachable from the internet. Firmware version is 71238a11.

    >> Fortunately this has been fixed in the last flash update (71205a32)
    >> but this same update also removes the requirement to specify a
    >> username. You now only need any one of the valid passwords to
    >> login.


    Finding new firmware versions is hard if the vendor doesn't list a
    product on his website. At least I wasn't able to find it there (tried
    the global website as well as the german). Any ideas where else to look
    for a newer firmware version?

    > *waits for another round of out of office/dead mailbox
    > auto-responders*


    Yeah, that's fun. I received something about 10 messages. Out of office
    replies, anti-spam-notices ("please click on the following link to
    confirm your message"), "unable to deliver" messages... why can't people
    remove inactive accounts, and why can't they tell the mailinglist
    program to switch them temporarily off the feed?

    Bye, Mike


  6. #6
    cw
    Asus AAM6000EV ADSL Router Wide Open
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Asus AAM6000EV ADSL Router Wide Open


    Hi all,
    I was looking into the info provided by Michael Renzmann where he said:

    "The same data can be accessed by telnetting to the device and choosing
    the menu-path "System Maintenance / User Maintenance / List User" (6/5/4)."

    On the AAM6000EV, the "User Maintenance" option is not under System=
    Maintenance and I haven't spotted it anywhere else (though I haven't=
    searched in depth).

    What I did notice was that after using the web vulnerability to get the=
    router username and password, an attacker could then go on to get the=
    username and password for the internet account that the router is=
    configured to use, hence potentially giving access to email and other=
    services.

    Use the menu path "System Maintenance > View All Configuration" (6,1)

    Scan through the output for the following section:

    Module 'ppp':

    Then look for the following line

    1 welogin username password logintype

    In the UK this can be very useful. People using BT ADSL will have a username=
    that is username@domain.tld, for example a Freeserve user would likely be=
    username@freeserve.co.uk

    So not only does this allow you to get router access, but further poor=
    configuration allows you to get all the details you need to access the=
    hosts internet account.


Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics