1-1 of 1 results (1 page)
D-Link remote DNS change
Dest. port: 80
Time: 02/10/2018 21:39:07
ASN/ISP: AS57043 Hostkey B.v.
Location: North Holland, Amsterdam (zipcode 1012)
This plug-in detects attempts to exploit a security issue affecting D-Link DSL-2740R devices, which permit remote, unauthenticated attackers to change the DNS settings from the WAN side. Exploitation is trivial, as it requires just to invoke a server-side page with the IP addresses of the primary and secondary DNS servers.
GET /dns.html HTTP/1.1
authorization: Basic YWRtaW46ZWJ0MjFwbWU=
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:23.0) Gecko/20100101 Firefox/20.0