router firmwarecode
OH MY GOD THERE'S AN UNAUTHENTICATED API TO SET THE *ADMIN PASSWORD*
I SENT A REQUEST TO IT TO SEE HOW IT WOULD BOUNCE BECAUSE I THOUGHT "oh hey they wouldnt do that i wonder how it errors" BUT NO
$.post("BelkinAPI/DBPasswordSet", {"RequestID":6969,'PassWd':"im gay"}, console.log, "json")
THIS JUST SETS THE PASSWORD
router firmwarecode
Is there an API method to turn on remote management, too?
Because if so, you might want to get in touch with people who can make sure critical level cert advisories get published...
router firmwarecode
@ghedipunk well, not if you're outside the network, because youd have to be able to access it to do it
router firmwarecode
*I* don't have to be inside of your network to get your browser to execute arbitrary Javascript to send POST requests to your router.
I don't even have to get you to visit my site; I just put the code in an ad, and let the ad networks pwn the Belkin owners for me.
router firmwarecode
@ghedipunk well, i dont know if it has anti-csrf, but...
router firmwarecode
@boots Do you have to be inside the network for this to work, though?
router firmwarecode
@mdm noooope
router firmwarecode
@boots What port is it over? That should be closed to the outside by default, right.
router firmwarecode
@mdm it is, 8080
remote management is not on by default, but the router settings imply it's fine if you have an admin password set
router firmwarecode
@boots Ah -- I knew I hated remote management for a reason. :P
router firmwarecode
@mdm honestly, oem router firmware is just
always bad
like, i dont know any oem firmware that isn't the worst
router firmwarecode
@boots I don't know what to say to that.
Well fuck?