[<prev] [next>] [day] [month] [year] [list]
Message-ID: <12fe359e-1915-b70c-8f63-2115e9cb5f99@gmail.com>
Date: Tue, 25 Jun 2019 18:35:35 +0200
From: Marty <noshishi8@...il.com>
To: fulldisclosure@...lists.org
Subject: [FD] D-LINK admin password in plain text if "user" or "User" use
blank password
The problem in the following models :
DIR-652
DIR-615
DIR-827
DIR-615
DIR-657
DIR-825
If login to web interface as "User" or "user" , and navigate to url :
http://<ip>:port/wizard_wan.asp
in web code page:
view-source:<ip>:port/wizard_wan.asp
scroll down page and bang :
administrator password in plain text
ports : 8080 or 8081 .
---
Ta wiadomość została sprawdzona na obecność wirusów przez oprogramowanie antywirusowe Avast.
https://www.avast.com/antivirus
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/
Powered by blists - more mailing lists