Hacker Domination

Reply
Netgear DG632 Router Authentication Bypass Vulnerability, Autore:Tom Neaves
view post Posted on 17/6/2009, 22:13Quote

Advanced Member

Group: Founder[HD]
Posts: 107


Status: Online: ultima azione eseguita alle ore 14:17, 6 minuti fa


Product Name: Netgear DG632 Router
Vendor: http://www.netgear.com
Date: 15 June, 2009
Author: tom@tomneaves.co.uk < tom@tomneaves.co.uk >
Original URL: http://www.tomneaves.co.uk/Netgear_DG632_A...tion_Bypass.txt
Discovered: 18 November, 2006
Disclosed: 15 June, 2009

I. DESCRIPTION

The Netgear DG632 router has a web interface which runs on port 80.
This allows an admin to login and administer the device's settings.
Authentication of this web interface is handled by a script called
"webcm" residing in "/cgi-bin/" which redirects to the relevant pages
depending on successful user authentication. Vulnerabilities in this
interface enable an attacker to access files and data without
authentication.

II. DETAILS

The "webcm" script handles user authentication and attempts to load
"indextop.htm" (via javascript below). The "indextop.htm" page requires
authentication (HTTP Basic Authorization).

---

<script language="javascript" type="text/javascript">
function loadnext() {
//document.forms[0].target.value="top";
document.forms[0].submit();
//top.location.href="../cgi-bin/webcm?nextpage=../html/indextop.htm";
}</script></head>
<body bgcolor="#ffffff" onload="loadnext()" >

Loading file ...
<form method="POST" action="../cgi-bin/webcm" id="uiPostForm">
<input type="hidden" name="nextpage" value="../html/indextop.htm" id="uiGetNext">
</form>

---

If a valid password to the default "admin" user is supplied, the script
then continues to load the "indextop.htm" page and continues to load the
other frames based on a hidden field. If user authentication is
unsuccessful, the user is returned back to "../cgi-bin/webcm". It is
possible to bypass the "webcm" script and access specific files directly
without the need for authentication.

Normal use:
http://TARGET_IP/cgi-bin/webcm?nextpage=../html/stattbl.htm

This would ask for the user to authenticate and would refuse access to
this file if authentication details were not known. All the script is
doing is making sure authentication is forced upon the user. The same
"stattbl.htm" file can be accessed without having to provide any
authentication using the following URL:

http://TARGET_IP/html/stattbl.htm

Another example:
http://192.168.0.1/cgi-bin/webcm?nextpage=...l/modemmenu.htm
(returns 401 - Forbidden)

Bypassing the "webcm" script:
http://192.168.0.1/html/modemmenu.htm
(returns 200 - OK)

In the example above (modemmenu.htm), the full source can be viewed
which discloses further directories and files within the javascript of
the page. A sample of files disclosed within modemmenu.htm and available
to download are:

/html/onload.htm
/html/form.css
/gateway/commands/saveconfig.html
/html/utility.js (full source)

There are many other files that are accessible by calling them directly
instead of going via the "webcm" script, the above are just a sample. In
addition, it is possible to specify paths to the "webcm" script as shown
below:

http://TARGET_IP/cgi-bin/webcm?nextpage=../../

This allows an attacker to enumerate what files and directories exist
within the www root directory and beyond by using 200, 403 and 404
errors as a guide.

Affected Versions: Firmware V3.4.0_ap (others unknown)

III. VENDOR RESPONSE

12 June, 2009 - Contacted vendor.
15 June, 2009 - Vendor responded. Stated the DG632 is an end of life
product and is no longer supported in a production and development
sense, as such, there will be no further firmware releases to resolve
this issue.

IV. CREDIT

Discovered by Tom Neaves

# milw0rm.com [2009-06-15]

image
CITAZIONE
Rayman (rayman007@hotmail.it)
Dragoamericano (the_new_drago@hotmail.it)
--------------------------------------------------------
Dragoamericano : tt sbagliano wallo
Rayman: mica tutti kosi' stai prendendo le somiglianze di uno!!!
Dragoamericano: in ke senso ?
Dragoamericano : e cmq di ki?
Rayman: hisoka
Rayman: lo conosci?
Dragoamericano: no
Dragoamericano : xkč?
Rayman: sahusahuhsuahusahusa
Dragoamericano: ki č?
Hai appena ricevuto un trillo da Dragoamericano
Dragoamericano : ki č?
Rayman: non conosci hisoka?
Dragoamericano : no ki č?
Rayman:ahahahahhaha
Rayman: uno ke fa 100figure di merda kome te!!!!
Rayman:loooooool

CITAZIONE
Conversazione su msn tra TheGhost & Dragoamericano :
TheGhost: Cosa č successo al tuo forum ?
Dragoamericano : Me l'hanno deffacciato...
TheGhost: Ki ??
Dragoamericano: Rayman
TheGhost: auahhauhauahuahua
TheGhost:sei un pollo!

CITAZIONE
new dragoamericano scrive:
vieni a visitare HIT rimarrai a bocca aperta...ci conto;
ShAdOw-dA3m0n scrive:
si... gią ci sn venuto tempo fą e infatti c'č un mio mess di presentazione... e prp xk sn rimasto a bocca aperta ke sn venuto quģ....
io nn vengo xk nn tradirņ mai hackerdomination!!!!
e poi dopo quella figurella ke hai fatto con il nostro forum nn capisco cn quale coraggio ti presenti ora da me....
la risp č no e sarą sempre no!!!! neanche se fosse l'unico forum rimasto nel web
new dragoamericano scrive:
ma chi ti vuole č sl pubblicita

CITAZIONE
Numą (R) scrive (16.18):
hai il cotatto di max90?
Rayman scrive (16.18):
si
Rayman scrive (16.18):
perkč?
Numą (R) scrive (16.19):
sta in linea ora?
Rayman scrive (16.19):
perkč?
Numą (R) scrive (16.19):
voglio sfotterlo un po'
Rayman scrive (16.19):
asdasd
Rayman scrive (16.19):
su cosa?
Numą (R) scrive (16.20):
sulle sue scarse conoscenze

CITAZIONE
±RaYmAn± scrive:
5851ŗ in Top Forum
Dragoamericano scrive:
l'ho visto!
±RaYmAn± scrive:
asdasdasdasdasdasdadsadssadsasd
Dragoamericano scrive:
e che dobbiamo fare xd
Dragoamericano scrive:
č la vitA
±RaYmAn± scrive:
aushuashushau

image
Click here to feed me a Rare Candy!

Get your own at PokePlushies!
image
image
image
image
image
image
image
image
image
 
P_MSG P_EMAIL Top
~Patata.
view post Posted on 29/6/2009, 12:26Quote

Utente cancellato






In poche parole,con questo metodo si bypassano le reti con le password?
(Potevi mettere in spoiler un translate fatto sul momento :asd: ).
 
Top
1 replies since 17/6/2009, 22:13
 
Reply

load
Fast reply

 
 
 

Enable emoticons
Clickable Smilies
Show All


Nickname:      Email: