186
SMC Routers remote administration without authentication
Network Devices
2004/09/07
Nico 'Triplex' Spicher
Triplex at IT-Helpnet dot de
http://triplex.it-helpnet.de
http://www.it-helpnet.de
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/13
1.2
Made some slight modifications in version 1.1. Corrected the plugin structure and added the accuracy values in 1.2
tcp
1900
open|send GET / HTTP/1.0\n\n|sleep|close|pattern_exists 200
10
This plugin was written with the ATK Attack Editor.
user86
user86 at earthlink dot net
SMC Routers 7008ABR, 7004VBR and other models
Other routers
Missing authentication
SMC broadband routers ship with remote administration (completely passwordless) enabled by default on their port 1900 on the WAN side of the router.
Enable FW & forward port 1900 of the router to a non-existent internal IP address.
Aprox. 20 Minutes
Yes
Yes
No
High
4
8
9
6
Hacking Intern - Angriffe, Strategien, Abwehr, Marc Ruef, Marko Rogge, Uwe Velten and Wolfram Gieseke, November 1, 2002, Data Becker, Düsseldorf, ISBN 381582284X
http://www.computec.ch