data:image/s3,"s3://crabby-images/07c97/07c9700784057a48bd2b8b91713ad26a1799d359" alt="Rank: 15" data:image/s3,"s3://crabby-images/07c97/07c9700784057a48bd2b8b91713ad26a1799d359" alt="Rank: 15" data:image/s3,"s3://crabby-images/07c97/07c9700784057a48bd2b8b91713ad26a1799d359" alt="Rank: 15" data:image/s3,"s3://crabby-images/cacd2/cacd24137dfa869d716af84979bc10a59d1ea48f" alt="Rank: 15" data:image/s3,"s3://crabby-images/93838/93838d6aa69c8923e6e839ddfe8d737ef92bd87c" alt="Rank: 15"
- 帖子
- 3852
- 积分
- 13044
- 威望
- 16780
- 金钱
- 36761
- 在线时间
- 1139 小时
data:image/s3,"s3://crabby-images/ea067/ea0670f8be3aab416c7f61e9e7644b146e8898b7" alt="管理组 管理组" data:image/s3,"s3://crabby-images/306a7/306a7cdd1164c2d585697a99f6fbe8dd04b76011" alt="高手勋章 高手勋章" data:image/s3,"s3://crabby-images/76210/76210719b62397e84068bec033cf826f0c624073" alt="核心成员 核心成员" data:image/s3,"s3://crabby-images/4679a/4679a26c91fa8ac3d8fe705e3aee5a7b091e67c3" alt="原创奖章 原创奖章" data:image/s3,"s3://crabby-images/af8cb/af8cb85b63e1614eab8a5bf95df6096472ab616d" alt="帅哥勋章 帅哥勋章" data:image/s3,"s3://crabby-images/c0c7f/c0c7f7e4d84168e0ea6ada1e205110f5d2f1cfa0" alt="突出贡献奖 突出贡献奖" data:image/s3,"s3://crabby-images/1cfe0/1cfe0e86fde6f3a6e07195ec09f8bc4afde35239" alt="优质人品奖章 优质人品奖章" data:image/s3,"s3://crabby-images/5c9dd/5c9ddb87e3d8aa24f9dd52e0b9cf3f54932fce23" alt="论坛元老 论坛元老" data:image/s3,"s3://crabby-images/ad7ed/ad7ede1efea6a9fcc3e49a81c63cb63a63876d9f" alt="管理组成员 管理组成员" data:image/s3,"s3://crabby-images/03657/0365778a2faba1b86768a588811ec24c179265a4" alt="技术组成员 技术组成员"
|
D-Link Products Captcha Bypass Vulnerability
D-Link Products Captcha Bypass Vulnerability
-Link Captcha Bypass
-------------------------------------
D-Link released new firmware designed to protect against malware that
alters DNS settings by logging in to the router using default administrative
credentials. There is a flaw in the captcha authentication system that allows
an attacker to glean your WiFi WPA pass phrase from the router with only user-level
access, and without properly solving the captcha.
When you login with the captcha enabled, the request looks like this:
GET /post_login.xml?hash=c85d324a36fbb6bc88e43ba8d88b10486c9a286a&auth_code=0C52F&auth_id=268D2
The hash is a salted MD5 hash of your password, the auth_code is the captcha value that
you entered, and the auth_id is unique to the captcha image that you viewed
(this presumably allows the router to check the auth_code against the proper captcha image).
The problem is that if you leave off the auth_code and auth_id values, some pages in the
D-Link Web interface think that you’ve properly authenticated, as long as you get
the hash right:
GET /post_login.xml?hash=c85d324a36fbb6bc88e43ba8d88b10486c9a286a
Most notably, once you’ve made the request to post_login.xml, you can activate
WPS with the following request:
GET /wifisc_add_sta.xml?method=pbutton&wps_ap_ix=0
When WPS is activated, anyone within WiFi range can claim to be a valid WPS client and
retrieve the WPA passphrase directly from the router. |
|