Хабр Курсы для всех
РЕКЛАМА
Практикум, Хекслет, SkyPro, авторские курсы — собрали всех и попросили скидки. Осталось выбрать!
TP-Link WDR740ND/WDR740N routers have a hidden debugging shell with root privileges that could be abused by attackers.
The username is hard coded in the HTTP server binary and the password cannot be changed from the management interface so the following credentials are almost guaranteed to work:
/userRpmNatDebugRpm26525557/linux_cmdline.html.
User:osteam
Password:5up
«Update: People have been reporting on forums that models WR743ND,WR842ND,WA-901ND,WR941N,WR941ND,WR1043ND,WR2543ND,MR3220,MR3020,WR841N also have access to this root shell.»
Modification V1.00 (BWE.4 )b1 / Jun 13, 2011
1. [Modification]
Symptom:Support hidden URL which named tools_archangel.cgi to control debug
message.
Application Note:Tools_archangel.cgi can control the arch_angel daemon
whether send Syslog or not to our Syslog server.
Бэкдор в роутерах TP-LINK