Members Login

Rss Feeds

Get our latest content via RSS feeds.

Report a Vulnerability

Report a vulnerability or exploit that you have found to SecuMania.
vul[at]SecuMania.org

 

Recommended Links

Latest Comments

[…] self-propagating malware in the first place. Share this post: email it! | bookmark it! | digg ...
Hello Webmasters My name is Nikolai. I am making an organization for the protection internet users f...
good job you are the best . mgharba talmout :d
Hello, The reported problem has been fixed. Regards, Catalina Danila Online Rent Customer Supp...
Not Vulnerable: Luis Wang netOffice Dwins 1.3.1 visit website http://netofficedwins .sourceforge.ne...
Current version of script corrected. Security patch available to registered users in the user foru...
But i think to protect the password is not needed because it's not used in the SQL-Execute statement...
you may find that your hotfix doesnt stop the password field from having SQL injected into it. This ...
i tried cmd panel doesnt work
gcc exploit.c -o exploit $./exploit $[ ] root

Who's Online

Total: 3
Members: 0 / Guests: 3
No members online

Packet Storm

Visits today: 228
Visits yesterday: 746
Visits month: 12958
Visits total: 41063
Pages total: 634992
8E6 R3000 Internet Filter URI Security Bypass Vulnerability Print E-mail
0
Wednesday, 16 January 2008
8E6 R3000 Internet Filter URI Security Bypass Vulnerability
Class: Design Error
CVE:
Remote: Yes
Local: No
Published: Jan 16 2008 12:00AM
Updated: Jan 16 2008 06:48PM
Credit:
nnposter discovered this issue.
Vulnerable:
8E6 Technologies R3000 Internet Filter 2.0.5 .33 (firmware)
Not Vulnerable:
Description:
8e6 R3000 Internet Filter is prone to a vulnerability that allows attackers to bypass URI filters.

Attackers can exploit this issue by sending specially crafted HTTP request packets for an arbitrary website. Successful exploits allow attackers to view sites that the device is meant to block access to. This could aid in further attacks.

R3000 Internet Filter 2.0.05.33 is vulnerable; other versions may also be affected.
Exploit:
Attackers may exploit this issue through a browser.

The following examples of requests are available:

packet 1: GE
packet 2: T / HTTP/1.0\r\n




packet 1: GET / HTTP/1.0
X-SomeHeader: ...
....

packet 2: X-SomeOtherHeader: ....
Host: www.example.com
...
Solution:
Currently SecuMania is not aware of any solution for this issue.
If you are aware of more recent information, please mail us at: vul[at]SecuMania.org.
References:
Source:
Hits: 764
Comments (2)add
Help
written by S1l3Nt As5a5s1n , March 24, 2008
Hey,
How exactly do you split up the packets?? Can you do it in the browser or is it done through the cmd panel?
report abuse
vote down
vote up
Votes: +1
`help
written by [] , April 11, 2008
i tried cmd panel doesnt work
report abuse
vote down
vote up
Votes: +0
Write comment
quote
bold
italicize
underline
strike
url
image
quote
quote
smile
wink
laugh
grin
angry
sad
shocked
cool
tongue
kiss
cry
smaller | bigger

busy
 
< Prev   Next >

Polls

How do you rate the SecuMania Security Portal?
 

Cheap Car Insurance | Personal Injury Lawyer Los Angeles | Credit Cards | Hosting | Secured Loanslinks VoteThisMovie PalKeys Hey3arab arabekia