 ydrol
join:2007-06-28
4 edits | reply to Oligarchy Re: 2Wire Cross Site Request Forgery Vulnerability
On the bright side, would this be a way for people to access the MDC page, where the MDC password is super secret?
Update: I just tried this on by 2700HGV with BT 5.29.107.19 firmware , and it said an unknown error has occurred. But I might not be doing it right. I just went straight to the H04_POST and it asked me to choose a password and hint. I pressed next and got an unknown error has occurred then it took me back to the page.
Update: My mistake. The password was changed!! The Irony is the BT firmware runs without a password anyway so it was always open to abuse. This is a good thing for all those locked mdc password  but a bad thing really  |