Skip to content

Krzysztof Burghardt’s blog

Create. Break. Fix. Repeat.

  • About
  • Contact
  • Sitemap

Tag: Encryption

syslog_tool.cgi on DASAN H660RM devices with firmware 1.03-0022 uses a hard-coded key for logs encryption

[Translate]

DASAN H660RM devices with firmware 1.03-0022 (and possibly other) uses a hard-coded key “dasanektks123” for logs encryption. Data stored using this key can be decrypted by anyone able to access this key.

This vulnerability was assigned CVE-2019-9975.

Continue reading “syslog_tool.cgi on DASAN H660RM devices with firmware 1.03-0022 uses a hard-coded key for logs encryption”

Author Krzysztof BurghardtPosted on March 18, 2019March 25, 2019Categories English, Hardware, Linux, SecurityTags DASAN, Encryption, GPON, H660RM, Linux, ONT, OpenSSL, SecurityLeave a comment on syslog_tool.cgi on DASAN H660RM devices with firmware 1.03-0022 uses a hard-coded key for logs encryption
  • About
  • Contact
  • Sitemap

Sorry. No data so far.

GPON userspace tuner kernel TV ClamFS OpenWRT keyboard Debian Linux DNS Apache event LKM funkey QEMU OpenGL strace PPP ONT H660RM FreeBSD Asus multimedia Google WordPress GNU MAC ActiveMQ Security ptrace ClamAV key PHP WINE DASAN ltrace OpenSSL input AMD64 IP Internet daemon pppd Web

Archives

  • July 2019
  • March 2019
  • February 2019
  • July 2010
  • April 2010
  • March 2010
  • November 2009
  • October 2009
  • August 2009
  • July 2009
  • May 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • September 2008
  • May 2008
  • April 2008
  • March 2008
  • January 2008
  • December 2007
  • November 2007

Pages

  • About
    • Contact
    • Certificates
    • OpenPGP public key
  • Sitemap

Popular Posts

Sorry. No data so far.

Recent Posts

  • Sam naprawiam lampę insektobójczą Blaupunkt BP-GIK04
  • diag_tool.cgi on DASAN H660RM devices with firmware 1.03-0022 allows spawning ping processes without any authorization leading to information disclosure and DoS attacks
  • Boa Webserver on DASAN H660RM devices with firmware 1.03-0022 saves post data, including credentials, to /tmp/boa-temp
  • syslog_tool.cgi on DASAN H660RM devices with firmware 1.03-0022 uses a hard-coded key for logs encryption
  • DASAN H665 has vendor backdoor built into BusyBox’s /bin/login

Archives

  • July 2019 (1)
  • March 2019 (3)
  • February 2019 (1)
  • July 2010 (1)
  • April 2010 (1)
  • March 2010 (1)
  • November 2009 (1)
  • October 2009 (2)
  • August 2009 (1)
  • July 2009 (1)
  • May 2009 (1)
  • March 2009 (3)
  • February 2009 (1)
  • January 2009 (5)
  • December 2008 (1)
  • November 2008 (2)
  • September 2008 (3)
  • May 2008 (5)
  • April 2008 (1)
  • March 2008 (5)
  • January 2008 (3)
  • December 2007 (6)
  • November 2007 (9)

Tags

  • ActiveMQ
  • AMD64
  • Apache
  • Asus
  • ClamAV
  • ClamFS
  • daemon
  • DASAN
  • Debian
  • DNS
  • event
  • FreeBSD
  • funkey
  • GNU
  • Google
  • GPON
  • H660RM
  • input
  • Internet
  • IP
  • kernel
  • key
  • keyboard
  • Linux
  • LKM
  • ltrace
  • MAC
  • multimedia
  • ONT
  • OpenGL
  • OpenSSL
  • OpenWRT
  • PHP
  • PPP
  • pppd
  • ptrace
  • QEMU
  • Security
  • strace
  • tuner
  • TV
  • userspace
  • Web
  • WINE
  • WL-500g
  • About
  • Contact
  • Sitemap
Krzysztof Burghardt’s blog Proudly powered by WordPress
English English Afrikaans Afrikaans العربية العربية Беларуская Беларуская български български català català česky česky Cymraeg Cymraeg dansk dansk Deutsch Deutsch ελληνική ελληνική español español eesti eesti فارسی فارسی suomi suomi français français Gaeilge Gaeilge galego galego עברית עברית हिन्दी हिन्दी hrvatski hrvatski magyar magyar bahasa Indonesia bahasa Indonesia íslenska íslenska italiano italiano 日本語 日本語 한국어 한국어 lietuvių lietuvių latviešu latviešu македонски македонски bahasa Melayu bahasa Melayu Malti Malti Nederlands Nederlands norsk norsk polski polski português português română română русский русский slovenčina slovenčina slovenščina slovenščina shqipe shqipe српски српски svenska svenska Kiswahili Kiswahili ภาษาไทย ภาษาไทย Filipino Filipino Türkçe Türkçe українська українська tiếng Việt tiếng Việt ייִדיש ייִדיש 中文 (简体) 中文 (简体) 中文 (繁體) 中文 (繁體) powered byGoogle