<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Which Routers Are Vulnerable to the D-Link HNAP Exploit?</title>
	<atom:link href="http://www.sourcesec.com/2010/01/18/which-routers-are-vulnerable-to-the-d-link-hnap-exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sourcesec.com/2010/01/18/which-routers-are-vulnerable-to-the-d-link-hnap-exploit/</link>
	<description>Security research and vulnerability assesment</description>
	<lastBuildDate>Fri, 03 Sep 2010 01:47:13 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: complete blood count results</title>
		<link>http://www.sourcesec.com/2010/01/18/which-routers-are-vulnerable-to-the-d-link-hnap-exploit/comment-page-1/#comment-264</link>
		<dc:creator>complete blood count results</dc:creator>
		<pubDate>Fri, 03 Sep 2010 01:36:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.sourcesec.com/?p=204#comment-264</guid>
		<description>The nation&#039;s actually finicky host to job credit.</description>
		<content:encoded><![CDATA[<p>The nation&#8217;s actually finicky host to job credit.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Samy</title>
		<link>http://www.sourcesec.com/2010/01/18/which-routers-are-vulnerable-to-the-d-link-hnap-exploit/comment-page-1/#comment-256</link>
		<dc:creator>Samy</dc:creator>
		<pubDate>Tue, 20 Jul 2010 15:35:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.sourcesec.com/?p=204#comment-256</guid>
		<description>Hi sergiu, the problem is solved for me now so i forgot to mention that they published ther firmware update on April 14 on the German dlink ftp site: ftp://ftp.dlink.de/dir/dir-600/driver_software/DIR-600_fw_revb_203b02_ALL_de_20100316.zip

This is Firmware Version 2.03 and the prof of concept tool does no longer work on it.</description>
		<content:encoded><![CDATA[<p>Hi sergiu, the problem is solved for me now so i forgot to mention that they published ther firmware update on April 14 on the German dlink ftp site: <a href="ftp://ftp.dlink.de/dir/dir-600/driver_software/DIR-600_fw_revb_203b02_ALL_de_20100316.zip" rel="nofollow">ftp://ftp.dlink.de/dir/dir-600/driver_software/DIR-600_fw_revb_203b02_ALL_de_20100316.zip</a></p>
<p>This is Firmware Version 2.03 and the prof of concept tool does no longer work on it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sergiu</title>
		<link>http://www.sourcesec.com/2010/01/18/which-routers-are-vulnerable-to-the-d-link-hnap-exploit/comment-page-1/#comment-254</link>
		<dc:creator>sergiu</dc:creator>
		<pubDate>Tue, 06 Jul 2010 06:43:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.sourcesec.com/?p=204#comment-254</guid>
		<description>nevermind ... FW is available also on RO ftp ...</description>
		<content:encoded><![CDATA[<p>nevermind &#8230; FW is available also on RO ftp &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sergiu</title>
		<link>http://www.sourcesec.com/2010/01/18/which-routers-are-vulnerable-to-the-d-link-hnap-exploit/comment-page-1/#comment-253</link>
		<dc:creator>sergiu</dc:creator>
		<pubDate>Fri, 02 Jul 2010 08:04:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.sourcesec.com/?p=204#comment-253</guid>
		<description>forgot to mention: i bought DIR-600 also in Europe area on 30.06.2010 (firmware ver. 2.02)</description>
		<content:encoded><![CDATA[<p>forgot to mention: i bought DIR-600 also in Europe area on 30.06.2010 (firmware ver. 2.02)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sergiu</title>
		<link>http://www.sourcesec.com/2010/01/18/which-routers-are-vulnerable-to-the-d-link-hnap-exploit/comment-page-1/#comment-252</link>
		<dc:creator>sergiu</dc:creator>
		<pubDate>Fri, 02 Jul 2010 07:41:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.sourcesec.com/?p=204#comment-252</guid>
		<description>ok Samy, can you realease to us the firmware update received from german dlink?</description>
		<content:encoded><![CDATA[<p>ok Samy, can you realease to us the firmware update received from german dlink?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Термолидер</title>
		<link>http://www.sourcesec.com/2010/01/18/which-routers-are-vulnerable-to-the-d-link-hnap-exploit/comment-page-1/#comment-251</link>
		<dc:creator>Термолидер</dc:creator>
		<pubDate>Mon, 21 Jun 2010 09:23:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.sourcesec.com/?p=204#comment-251</guid>
		<description>Thank you for the wonderful review!</description>
		<content:encoded><![CDATA[<p>Thank you for the wonderful review!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Samy</title>
		<link>http://www.sourcesec.com/2010/01/18/which-routers-are-vulnerable-to-the-d-link-hnap-exploit/comment-page-1/#comment-239</link>
		<dc:creator>Samy</dc:creator>
		<pubDate>Fri, 19 Mar 2010 13:31:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.sourcesec.com/?p=204#comment-239</guid>
		<description>I got in touch with the German dlink support and after giving them a step by step instruction on how to use the exploit script the finally admitted that there was a vulnerability and that they where able to reproduce it. I then received a firmware update which should deactivate the hidden user account on the DIR-600 making HNAP access via the standard user account impossible.

I tried it out and it seems to work. Sadly you are not able to deactivate the user account via the web-configuration. Only this Firmware update seems to work, but it is not yet publicly available on their support website neither are they publicly admitting that their is a problem with the DIR-600.</description>
		<content:encoded><![CDATA[<p>I got in touch with the German dlink support and after giving them a step by step instruction on how to use the exploit script the finally admitted that there was a vulnerability and that they where able to reproduce it. I then received a firmware update which should deactivate the hidden user account on the DIR-600 making HNAP access via the standard user account impossible.</p>
<p>I tried it out and it seems to work. Sadly you are not able to deactivate the user account via the web-configuration. Only this Firmware update seems to work, but it is not yet publicly available on their support website neither are they publicly admitting that their is a problem with the DIR-600.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: craig</title>
		<link>http://www.sourcesec.com/2010/01/18/which-routers-are-vulnerable-to-the-d-link-hnap-exploit/comment-page-1/#comment-238</link>
		<dc:creator>craig</dc:creator>
		<pubDate>Thu, 11 Mar 2010 02:25:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.sourcesec.com/?p=204#comment-238</guid>
		<description>Thanks for the extra info Samy. As specified elsewhere in the paper, some D-Link routers run HNAP on port 80 while others use port 8099; it looks like the DIR-600 uses port 80 which is why specifying port 8099 doesn&#039;t work. 

If you want to know which port is being used for HNAP, browse to http://192.168.0.1/HNAP1/; if HNAP is being run on a port other than 80, it will redirect your browser to the appropriate port.</description>
		<content:encoded><![CDATA[<p>Thanks for the extra info Samy. As specified elsewhere in the paper, some D-Link routers run HNAP on port 80 while others use port 8099; it looks like the DIR-600 uses port 80 which is why specifying port 8099 doesn&#8217;t work. </p>
<p>If you want to know which port is being used for HNAP, browse to <a href="http://192.168.0.1/HNAP1/" rel="nofollow">http://192.168.0.1/HNAP1/</a>; if HNAP is being run on a port other than 80, it will redirect your browser to the appropriate port.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Samy</title>
		<link>http://www.sourcesec.com/2010/01/18/which-routers-are-vulnerable-to-the-d-link-hnap-exploit/comment-page-1/#comment-237</link>
		<dc:creator>Samy</dc:creator>
		<pubDate>Sat, 06 Mar 2010 23:47:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.sourcesec.com/?p=204#comment-237</guid>
		<description>I have to correct myself the Version 2.01 i have installed is actually the latest release.
D-Link just calls it 2.01b01 on their german support website instead of 2.01. Aniway i did the firmware update and its the same release and vulnerable!

this is the output i get from hnap0wn when it sucessfully changed the admin password:

samy@MeanMachine:~/Downloads$ ./hnap0wn 192.168.0.1 xml/SetDeviceSettings.xml

Trying SOAPAction header exploit...

SOAPAction header exploit failed! Trying privilege escalation exploit...



  
    
      REBOOT
    
  
</description>
		<content:encoded><![CDATA[<p>I have to correct myself the Version 2.01 i have installed is actually the latest release.<br />
D-Link just calls it 2.01b01 on their german support website instead of 2.01. Aniway i did the firmware update and its the same release and vulnerable!</p>
<p>this is the output i get from hnap0wn when it sucessfully changed the admin password:</p>
<p>samy@MeanMachine:~/Downloads$ ./hnap0wn 192.168.0.1 xml/SetDeviceSettings.xml</p>
<p>Trying SOAPAction header exploit&#8230;</p>
<p>SOAPAction header exploit failed! Trying privilege escalation exploit&#8230;</p>
<p>      REBOOT</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Samy</title>
		<link>http://www.sourcesec.com/2010/01/18/which-routers-are-vulnerable-to-the-d-link-hnap-exploit/comment-page-1/#comment-236</link>
		<dc:creator>Samy</dc:creator>
		<pubDate>Sat, 06 Mar 2010 23:22:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.sourcesec.com/?p=204#comment-236</guid>
		<description>Hi Craig, i am not running the latest release, i am running the pre installed Firmware Version 2.01

I will install the newer version and then test again.

I also found out that you now have a newer version of you proof of concept artikel out. You added the part that you schould specify the port &quot;8099&quot; wenn trying to execute hnap0wn. I have to tell you that this new Command does not work and the script will fail with the dir-600 whereas the old command without the port 8099 and just the ip works perfectly.</description>
		<content:encoded><![CDATA[<p>Hi Craig, i am not running the latest release, i am running the pre installed Firmware Version 2.01</p>
<p>I will install the newer version and then test again.</p>
<p>I also found out that you now have a newer version of you proof of concept artikel out. You added the part that you schould specify the port &#8220;8099&#8243; wenn trying to execute hnap0wn. I have to tell you that this new Command does not work and the script will fail with the dir-600 whereas the old command without the port 8099 and just the ip works perfectly.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
