Tuesday, 16 May 2017

iiNet Budii(1031) Local File Listing (USBwebserver)

This is a method to list the local files on the router via wftp (USBwebsever) :
Requires login and usb inserted into the aux usbports(fat/nfts)(*1)
Either goto:

To turn on the fileserver,
now point your browser here: 

(notice the URLencode because the straight transversal is rejected by the websever not even making its way to the app 
but with encoded slashes we beat the checks)

  and click save 

now we goto:

And we see our routers internal files.

we can wget out a copy of the systems memory with this enabled and scrape/view many of the files including the passwd file in the web browser:


No comments:

Post a Comment