lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20090804201205.32449.qmail@securityfocus.com> Date: 4 Aug 2009 20:12:05 -0000 From: wojwar@...oo.com To: bugtraq@...urityfocus.com Subject: Re: Multiple Flaws in Huawei D100 > #9 Telnet service enabled by default Anyone in LAN is able to log in using default admin:admin account with root privileges. There is no possibility to change this password (sic!) You can change telnet admin password on this device. 1. telnet as admin with passwd admin 2. type: nvram set admin_passwd=SOMESTRONGPASSWD <enter> 3. type: nvram commit <enter> 4. restart router (by switching off the power) thats all regards VoyteckV