March 1, 2016
The payload looks like:
February 28, 2016
Alcatel-Lucent OmniSwitch 6250 Switch can be managed via telnet console or HTTP via a utility they call WebView. The switch creates a default admin account for management according to the manual.
By default, a single user management account is available at the first bootup of the switch. This account
has the following user name and password:
• user name—admin
February 3, 2016
NOVUS Automation makes software called SuperView that “is a Supervisory Control and Data Acquisition software (SCADA) that brings to the user a visual development model to create applications. Besides communication with Modbus RTU and Modbus TCP devices, also is posible to use SuperView stations operating in Client or Server modes allowing distributed supervision of a process or system.” When creating a new application in the software a default admin account is also created:
February 2, 2016
NOVUS Automation makes a variety of products for ICS and SCADA management. The NOVUS AirGate-3G Dual SIM Industrial Cellular VPN Router installs with a default admin account according to the manual:
February 1, 2016
LOYTEC electronics GmbH has a manuals download section on their site (requires authentication) showing the following devices have a default admin account:
- L-DALI DALI Light Controller
- L-INX Automation Server
- L-GATE Universal Gateway
- L-IP CEA-709/IP Router
- LIOB-10x I/O Module
- LIOB-x5x I/O Module
- LIP-ME20X L-IP BACnet Router
- LWEB-900 Building Management System
The L-Proxy CEA-709 Gateway has a different default:
January 29, 2016
Basically every BEC Technologies device uses a web interface for device management and each one has the same default admin credentials:
Web Interface: (Username and Password)
The BiPAC 7800NL 802.11n ADSL2+ Firewall Router ships with multiple accounts:
January 28, 2016
Falcon UPS devices use a SNMP HTTP agent for remote administration. According to the manual it comes with default admin credentials.
Click the Become Administrator button at the bottom of the screen. Enter USHA as the login name and admin as the password. (Case sensitive)
January 27, 2016
TerraMaster storage devices come with default admin credentials according to the online installation guide. These include the WORM-Storage, F4-NAS, F2-NAS 2 and F2-C2O.
January 26, 2016
KZ Broadband Technologies, LTD. iSurfTM 1004 and 1008 Integrated Access Devices install with a default admin account for the web interface according to the manual.
I confirmed this works on iSurf 1004 V2.10 B02D09 Pack 02, iSurf 1004 IAD V2.10 B02D09 Pack 03 and iSurf 1008+ V2.10 B02D09 Pack 23.
The router allows multiple accounts and offers different access levels making cross-site scripting a concern. There is a very basic XSS bug (CVE-2016-78001):
GET /en/cgi/SysSetContact.cgi?sys_contact=DF”><scr1pt>alert(‘DF’)</scr1pt> HTTP/1.1
The script will render on /en/sys_info.htm:
January 25, 2016
Shine WebBox installs with a default admin account according to the manual (admin / 123456). This allows remote attacker to do everything from gain internal IP to fully control the device.