Router Hacking Challenge.
I decided to put up a little challenge.
I'm intrigued by router issues, the folks at gnucitizen have submitted numerous router exploits in the last months. Problem is, they hack their own router brand. Something I cannot test myself because I don't own it. Since I'm always short on the green, I thought it would be a good idea for each of us to inspect and pentest our own router. This way we can figure out how severe the router vulnerability landscape really is. The incentive is that you'll learn hacking routers, and this way you get something out of it also. So are you up to it? can you handle it? can you find a vulnerability in your personal router? Then you are the perfect candidate to join!
The contest runs from 2 February until 29 February. If there are enough submissions, I will write about it and compose a list of the best router hacks that where submitted. I also pick my personal favorite out of that list as the main winner. The Hacker Webzine currently grows each day. The site has 100 to 150K hits each week, so this can give you a lot of attention and spotlight! The rules are very flexible, every kind of exploit is allowed. From buffer overflows to CSRF issues that plague many routers. My personal favorites are CSRF issues since they always work in any situation.
You can submit your entries to this email: hackerwebzine[at]gmail[dot]com.
Happy router hacking!
For some inspiration, you can visit gnucitizen.org or take a look at this example that shows a CSRF issue that was discovered last week on the 2Wire router brand:
2Wire Routers 'H04_POST' Access Validation Vulnerability.
http://127.0.0.1/xslt?PAGE=H04_POST&PASSWORD=admin&PASSWORD_CONF=admin
The challenge post is here: http://www.0x000000.com/index.php?i=508
Edited 3 time(s). Last edit at 02/02/2008 09:25AM by Ronald.