Tutorial: Router Hacking (Leveraging Exploits with Nessus and Python)

Опубликовано: 09 Ноябрь 2010
на канале: ajatkinson2004
24,509
61

This video shows how to use the Nessus vulnerability scanner to scan for a vulnerability, then exploit the flaw using a Python script I wrote. This video details the "DD-WRT HTTP Daemon Metacharacter Injection Remote Code Execution" vulnerability and fully demonstrates a live attack. The script uses the vulnerability to force the router to reboot, in essence denying access for all users who rely on the router to access the network.

The vulnerability itself is a flaw that allows any attacker who is connected to the router to run a command of his choosing using "/cgi-bin/;[command]" appended to the URL. The attacker can also use this vulnerability to force the router to spawn a remote shell on a port of his choosing, then connect to it using a client such as Putty. Free root access. It's pretty bad.

Link To Advisory: http://www.nessus.org/plugins/index.p...


На этой странице сайта вы можете посмотреть видео онлайн Tutorial: Router Hacking (Leveraging Exploits with Nessus and Python) длительностью часов минут секунд в хорошем качестве, которое загрузил пользователь ajatkinson2004 09 Ноябрь 2010, поделитесь ссылкой с друзьями и знакомыми, на youtube это видео уже посмотрели 24,509 раз и оно понравилось 61 зрителям. Приятного просмотра!