Security musings (reflectorium)
Security musings (reflectorium)
Script injection via DHCP
Now this is fun. - It seems that with one SOHO wireless router (AirPlus DI-614+) you can make the administrator run malicious scripts when he looks at the the web-based management console.
In a nutshell:
+ you send a maliciously hand-crafted DHCP packet
+ which the router takes and verbatimly embeds in the DHCP administrative and logs web pages it offers to the admin
Details are at
http://www.securityfocus.com/archive/1/366615