|
|||||||||||
|
Promise NAS NS4300N GUI bug
From: Tor Houghton <torh(at)bogus.net>
Date: Thu Sep 27 2007 - 17:19:27 EDT
There is a bug in the Promise NAS NS4300N web GUI (firmware version 1.1.0.5)
which allows an authenticated (admin) user to change the password of the
The user management portion of the web interface allows the admin user to
change user's passwords. The PHP script that handles this does not check to
see if the admin is changing a user account or system accounts such as
By changing the value of the 'user' parameter to 'root' (from whatever user id whose password is being changed, e.g. 'admin' if you have not defined any users) in the POST request to /usercp.php, we can provide a known password for the root account and thereby login to the NAS (which is normally not possible because Promise has not divulged root's password). The vendor has not been notified, but this is hardly a critical issue..? Tor
moonshade:~$ telnet 192.168.5.16 2380
BusyBox v1.00-rc2 (2006.11.07-01:55+0000) Built-in shell (ash) Enter 'help' for a list of built-in commands.
root is allowed to login.
-- http://www.bogus.net/~torhReceived on Thu Sep 27 18:49:02 2007 This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:18:25 EDT |
||||||||||
|
|||||||||||