Re: [FD] Remote Command Execution within the ASUS RT-AC68U Managing Web Interface

2014-04-06 Thread coderman
On Fri, Apr 4, 2014 at 2:25 PM, Craig Young wrote: > SOHO router security is quite bad. This is far from an isolated ping > injection as most home routers don't bother to sanitize input going to > ping functionality. in case that wasn't clear, multiple international SOHO router hardware shops ar

Re: [FD] Remote Command Execution within the ASUS RT-AC68U Managing Web Interface

2014-04-04 Thread Craig Young
Hi Paula, SOHO router security is quite bad. This is far from an isolated ping injection as most home routers don't bother to sanitize input going to ping functionality. It is common enough that I have begun just referring to it as ping injection. FYI - For tracking purposes, the CVE I had assig

[FD] Remote Command Execution within the ASUS RT-AC68U Managing Web Interface

2014-04-04 Thread Palula Brasil
=[Alligator Security Team - Security Advisory] Remote Command Execution within the ASUS RT-AC68U Managing Web Interface Author: Joaquim Brasil de Oliveira < palulabrasil () gmail com > < twitter.com/palulabr > =[Table