exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

zyxelP681.txt

zyxelP681.txt
Posted Sep 15, 2004
Authored by Venglin

Zyxel P681 SDSL routers disclose random portions of memory in ARP requests.

tags | advisory
SHA-256 | a8bca94387e9cd38728d7e3e9d38ccd9f127ae129768830595a01aae1c94881f

zyxelP681.txt

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello,

Zyxel P681 with ZyNOS S/W Version: Vt020225a | 2/25/2002 installed leaks
random portions of memory in ARP requests:

21:47:05.709295 arp who-has x.x.x.x tell x.x.x.x
0x0000 0001 0800 0604 0001 00a0 c526 3cc1 xxxx ................
0x0010 xxxx 0000 0000 0000 xxxx xxxx 0a48 6f73 .............Hos
0x0020 743a 3233 392e 3235 352e 3235 352e t:239.255.255.

and after telnet login, packets contains fragments of session!

21:48:24.804384 arp who-has x.x.x.x tell x.x.x.x
0x0000 0001 0800 0604 0001 00a0 c526 3cc1 xxxx ................
0x0010 xxxx 0000 0000 0000 xxxx xxxx 5b32 323b ............[22;
0x0020 3439 4833 392e 3235 352e 3235 352e 49H39.255.255.

21:50:34.537114 arp who-has x.x.x.x tell x.x.x.x
0x0000 0001 0800 0604 0001 00a0 c526 3cc1 xxxx ................
0x0010 xxxx 0000 0000 0000 xxxx xxxx 4849 6e66 ............HInf
0x0020 6f72 6d61 7469 6f6e 1b5b 363b 3439 ormation.[6;49

21:51:00.175642 arp who-has x.x.x.x tell x.x.x.x
0x0000 0001 0800 0604 0001 00a0 c526 3cc1 xxxx ................
0x0010 xxxx 0000 0000 0000 xxxx xxxx 3333 4856 ............33HV
0x0020 6572 7369 6f6e 3a35 352e 3235 352e ersion:55.255.

21:52:01.542252 arp who-has x.x.x.x tell x.x.x.x
0x0000 0001 0800 0604 0001 00a0 c526 3cc1 xxxx ................
0x0010 xxxx 0000 0000 0000 xxxx xxxx 3b33 3748 ............;37H
0x0020 6f72 1b5b 3231 3b34 3048 5245 5455 or.[21;40HRETU


- --
* Fido: 2:480/124 ** WWW: http://www.frasunek.com/ ** NICHDL: PMF9-RIPE *
* JID: venglin@jabber.atman.pl ** PGP ID: 2578FCAD ** HAM-RADIO: SQ8JIV *
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFBRfuHkxEnBiV4/K0RAtXYAKCjA/6gHjDH8tEoESOC/Xql00+ZhQCgtVFx
PP96Pg8gPC4KHb7dXWLDpXU=
=sUX9
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

December 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    0 Files
  • 2
    Dec 2nd
    41 Files
  • 3
    Dec 3rd
    0 Files
  • 4
    Dec 4th
    0 Files
  • 5
    Dec 5th
    0 Files
  • 6
    Dec 6th
    0 Files
  • 7
    Dec 7th
    0 Files
  • 8
    Dec 8th
    0 Files
  • 9
    Dec 9th
    0 Files
  • 10
    Dec 10th
    0 Files
  • 11
    Dec 11th
    0 Files
  • 12
    Dec 12th
    0 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close