republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Equipment Support » Hardware By Brand » D-Link » Remotely Exploitable Vulnerability In All D-Link Gateways
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Help Configuring My Gigabit Network Adapter »
« How to change firewall settings?  
AuthorAll Replies


funchords
Hello
Premium,MVM
join:2001-03-11
Washington, DC
·Verizon Online DSL
·Skype

reply to Hofbrau
Re: Remotely Exploitable Vulnerability In All D-Link Gateways

I could not reproduce this on my DI-624 using the steps in »www.intruders.com.br/adv0206en.html ...

The alledged output file format is also very usual for that type of router.

Can anyone?


Hofbrau

@rr.com

"I could not reproduce this on my DI-624 using the steps in »www.intruders.com.br/adv0206en.html ...

The alledged output file format is also very usual for that type of router.

Can anyone?"

I sure hope no one can, since the vulnerability listed there was pretty specific to the DWL-2100 AP.

I know I cant.

Perhaps because they are two different vulnerabilities, with two different advisories?

Reading works - really.

Perhaps more time should be spent honing up the reading skills rather than apologism and minimization skills, but, that would probably only result in more time spent ambiguously and ignorantly (and amusingly) naysaying the "NAT Traversal" aspect of the UPnP IGD 1.0 specification under the general idea of "UPnP is insecure".

Cogitate,
Hofbrau

latinuser_uy

join:2004-07-15
UY


1 edit
HI,
I tested the dwl-2100ap vulnerability, from an unauthenticated browser, tried the url »ip-of-my-dwl2100ap/cgi-bin/config.cfg

I got a config file for download. It contained the wireless key in plain text format, plus the "admin" key in plain text, among other configuration stuff.

Then I tried »ip-of-my-dwl2100ap/cgi-bin/nada.cfg and toto.cfg : same results.

HW DWL-2100AP
FW 2.00

I'm using the DWL-2100ap in AP mode, WPA-PSK. From the PC I was running the browser from, I had another browser which had an expired session (up from yesterday night) to the DWL-2100ap (the 2100ap would ask me for user/password as soon as I click on any option). I'll try again doing this first thing after rebooting my computer. I guess that's going to be after I come back from the office.

There seems to be a 2.2 fw for the dwl2100ap from some non-us site, has anyone tried that one?

Regards.
Forums » Equipment Support » Hardware By Brand » D-LinkHelp Configuring My Gigabit Network Adapter »
« How to change firewall settings?  


Saturday, 05-Dec 05:41:41 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [145] Avast Antivirus Has Gone Mad
· [126] Comcast Makes NBC Universal Acquisition Official
· [104] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [101] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [90] The Bandwidth Hog Does Not Exist
· [83] FCC Ponders Moving From PSTN To IP Voice
· [81] Latest Consumer Reports Survey Not Kind To AT&T
· [74] Sprint Defuses GPS Privacy Media Bomb
· [74] New Bill Aims To Limit ETFs
Most people now reading
· False positive in Avast! or is it real? [Security]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Windows 7 boot manager editing questions [Microsoft Help]
· Farewell [Bell Canada]
· Evading throttling with uTP / uTorrent 1.9a [TekSavvy]
· [Snow Leopard] NFS Mounts - no more Directory Utility [All Things Macintosh]
· DNS options, what are YOU using? [TekSavvy]
· What to use while demonoid is down? [Filesharing Software]
· Maximizing Rogue DPS for 3.1 [World of Warcraft]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]