what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

SMCwhoops.txt

SMCwhoops.txt
Posted May 3, 2004
Authored by user86

SMC broadband routers ship with remote administration enabled by default on port 1900 on the WAN side of the router. Hitting the external IP address on port 1900 and clicking Login allows a malicious attacker to gain full access to the device. Tested against model 7008ABR and 7004VBR.

tags | exploit, remote
SHA-256 | 3eee3cdb3e0331844cad85a831f6ec24d5f5d0c1e6400811a41972102e98b154

SMCwhoops.txt

Change Mirror Download
Tested Model: 7008ABR (part number 750.9814 with firmware 1.032 installed)
Confirmed by another person on: 7004VBR (version 1, firmware 1.231)
Others may be vulnerable.

SMC broadband routers ship with remote administration enabled by default on
their port 1900 on the WAN side of the router. If you just pull one out of
the box, plug it into your internet connection and go through the "Setup
Wizard" then don't do anything beyond that point, port 1900 is open on the
router and completely passwordless, allowing ANY arbitrary person to just
visit http://1.2.3.4:1900/ where "1.2.3.4" is the router's external IP
address and hit "Login" and have full control of the router. This may allow
an arbitrary person to expose the very machines being protected by the
router.

Steps to reproduce:
1. Reset the router to factory defaults, either by logging onto its remote
administration page at http://192.168.2.1/ and clicking "Advanced Setup" then
"Tools" then "Configuration Tools" then choose "Restore barricade to factory
defaults" and click "Next." Or by holding down the router's reset button
with a paper clip for 30 seconds.

2. After the router has been reset to factory defaults, visit its
administration page at http://192.168.2.1/

3. Click "login"

4. Click "Setup Wizard" then "Next"

5. Choose the appropriate connection type you have.

6. When it is "connected" and you can web browse on the internet just fine
behind it, go back to the router's administration page at http://192.168.2.1/

7. Click "Advanced Setup" then "Status" and write down the router's WAN IP
address. (for example 1.2.3.4)

8. Now using a computer that has a different external IP address (another
machine on the internet), visit the router's port 1900 in your web browser
http://1.2.3.4:1900/

You are then greeted with a login prompt. Click "Login" and you have full
control of the router remotely. While you are there, click "Advanced Setup"
and then "System" then "Remote Management" and you can verify "Remote
Management" is supposedly disabled yet somehow you are *remotely* managing
the device.


There are two workarounds:
1. Enable the router's firewall in its "Advanced Setup"

2. Forward port 1900 of the router to a non-existent internal IP address
(such as 192.168.2.248 if it isn't in use).
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close