Ascend Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

(ASCEND) security hole in p50





In the p50 running +5.1A+ ive discovered a security hole while fiddling around
last week.

The 3 levels of access are pointless because once you have the telnet password,
it allows you to go into diagnostic mode and dump the p50's config to a 
tftp server, complete with all passwords for the unit....

Silly silly ascend.

     ---------------------------------------------------------------------
    | Skeeve Stevens - myinternet    personal.url: http://www.skeeve.net/ |
    | email://skeeve@skeeve.net/     work.url: http://www.myinternet.net/ |
    | phone://612.9876.4527/         mobile://0414.SKEEVE/      [753-383] |
    |              No kids, no chat room, no smiley faces.                |
    | - This email is (c) 1997 by Skeeve Stevens - All rights reserved -  |
     ---------------------------------------------------------------------
++ Ascend Users Mailing List ++
To unsubscribe:	send unsubscribe to ascend-users-request@bungi.com
To get FAQ'd:	<http://www.nealis.net/ascend/faq>


Follow-Ups: