Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: Lousy password handling in BreezeCOM
From: hille () DARKGATE EQUINOXE DE (Thilo Hille)
Date: Thu, 10 Dec 1998 20:21:43 +0100


as far as i know its possible to set installerrights via snmp.
there is also a kind of DOS in the way of updating the firmware.
the tftpserver requires no authorization to upload the firmware and reset.
so someone could easily upload any file.
after that you have to send the affected device to breezecom to
get a new firmware cause the tftpserver is part of the firmware....

the only protection is to set up no ip-configuration.


Thilo Hille
Equinoxe Internet Galerie
Adlerstr.7
79098 Freiburg

Fon: 0761-382263
Fax: 0761-382265
email: hille () equinoxe de
***** www.equinoxe.de *******



  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]