|
Brought to you by:
Suppliers of:
|
|
|
| |
| The UPS management software contains a built-in web server which allows for remote management of the UPS. The management interface is protected by a username and password. Authentication is performed via Basic authentication. There is a small stack-based overflow in the base64 decoding routine which handled the Basic authentication data. |
| |
Credit:
The information has been provided by Elazar Broad.
|
| |
Vulnerable Systems:
* Belkin BullDog Plus UPS Management Software version 4.0.2 Build 1219
Exploit:
The size of the buffer is too small for shellcode, however, this can be stored in the GET request, which sits at esp+0x58.
|
|
|
|
|