| 8E6 R3000 Internet Filter URI Security Bypass Vulnerability |
|
Credit:
| nnposter discovered this issue. |
|
Vulnerable:
|
8E6 Technologies R3000 Internet Filter 2.0.5 .33 (firmware)
|
|
Description:
|
8e6 R3000 Internet Filter is prone to a vulnerability that allows attackers to bypass URI filters.
Attackers can exploit this issue by sending specially crafted HTTP request packets for an arbitrary website. Successful exploits allow attackers to view sites that the device is meant to block access to. This could aid in further attacks.
R3000 Internet Filter 2.0.05.33 is vulnerable; other versions may also be affected.
|
| Exploit:
|
Attackers may exploit this issue through a browser.
The following examples of requests are available:
packet 1: GE packet 2: T / HTTP/1.0\r\n
packet 1: GET / HTTP/1.0 X-SomeHeader: ... .... packet 2: X-SomeOtherHeader: .... Host: www.example.com ...
|
|
Solution:
| Currently SecuMania is not aware of any solution for this issue.
If you are aware of more recent information, please mail us at: vul[at]SecuMania.org. |
|
References:
|
|
How exactly do you split up the packets?? Can you do it in the browser or is it done through the cmd panel?