quinta-feira, 1 de outubro de 2009

SpeedTouch - modem vulnerability

Something I just found out:

How to access to a SpeedTouch Administration Web Page!


You need to have access to one speedtouch web administration page.
Once you access it through you web browser just exit or, don't exit at all, without logging out. that is the important part.
After that you have to access the network where the other speedtouch is in, and which you want to access and don't know the password. Just type de web adminstration url and you're in.


Some notes:

this is probably because of a cookie validation that is not being done
just tested on 2 different speedtouch
used the url: http://speedtouch.lan for this