no one is safe ...

Reply to comment

Similar exploit in DIR-685

I thought you might be interested in a similar vulnerability I found in the DIR-685 and wrote about in the October 2011 issue of Linux Journal and gave a talk on here: http://greenfly.org/talks/security/practice_hacking.html

The main difference is in my case the page is tools_vct.php and the variable is 'exeshell' but you can run telnetd as root all the same.

Reply

  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
* three = nine
Solve this math question and enter the solution with digits. E.g. for "two plus four = ?" enter "6".