WebRamp Default Adminstrative Login Vulnerability
BID:577
Info
WebRamp Default Adminstrative Login Vulnerability
| Bugtraq ID: | 577 |
| Class: | Configuration Error |
| CVE: |
CVE-1999-0677 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Aug 03 1999 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | Posted to Bugtraq August 3, 1999 by Efrain 'ET' Torres <[email protected]>. |
| Vulnerable: |
Ramp Networks WebRamp M3 1.0 Ramp Networks WebRamp 200i 1.0 |
| Not Vulnerable: | |
Discussion
WebRamp Default Adminstrative Login Vulnerability
WebRamp systems ship with a default password for the web administration utility. The setup program does not force this password to be changed, and some WebRamp machines on the Internet are still using this default password. It is also possible through misconfiguration to disable authentication for web administration entirely. If an attacker were able to login using the default password, they would get access to various information including the ISP account, password and phone number, as well as the ability to change the routing table and the firmware. On systems with more than one modem attached, it is possible to have one modem call a remote computer, thereby providing outside access to the internal LAN.
WebRamp systems ship with a default password for the web administration utility. The setup program does not force this password to be changed, and some WebRamp machines on the Internet are still using this default password. It is also possible through misconfiguration to disable authentication for web administration entirely. If an attacker were able to login using the default password, they would get access to various information including the ISP account, password and phone number, as well as the ability to change the routing table and the firmware. On systems with more than one modem attached, it is possible to have one modem call a remote computer, thereby providing outside access to the internal LAN.
Exploit / POC
WebRamp Default Adminstrative Login Vulnerability
Default (and unchangeable) username: wradmin
Default password: trancell
This information is also available on the Ramp Networks company website.
Default (and unchangeable) username: wradmin
Default password: trancell
This information is also available on the Ramp Networks company website.
Solution / Fix
WebRamp Default Adminstrative Login Vulnerability
Solution:
As with all default passwords, the wradmin password should be changed at installation.
Solution:
As with all default passwords, the wradmin password should be changed at installation.
References
WebRamp Default Adminstrative Login Vulnerability
References:
References: