Re: [Full-disclosure] Multiple CSRF and XSS vulnerabilities in ADSL modem Callisto 821+

2011-08-02 Thread MustLive
e'd fix it). Best wishes & regards, MustLive Administrator of Websecurity web site http://websecurity.com.ua - Original Message - From: -= Glowing Sex =- To: MustLive Cc: full-disclosure@lists.grok.org.uk Sent: Saturday, July 30, 2011 1:42 AM Subject: Re: [Full-

[Full-disclosure] Multiple CSRF and XSS vulnerabilities in ADSL modem Callisto 821+

2011-07-31 Thread MustLive
Hello list! I want to warn you about new multiple security vulnerabilities in ADSL modem Callisto 821+ (SI2000 Callisto821+ Router). Which I disclosed last week. These are Cross-Site Request Forgery and Cross-Site Scripting vulnerabilities. In April I've already drew attention of Ukrtelecom's rep

Re: [Full-disclosure] Multiple CSRF and XSS vulnerabilities in ADSL modem Callisto 821+

2011-07-29 Thread -= Glowing Sex =-
So... advanced... So, you could maybe have to think if the router has port 80 open and i assume a remote-service,most isp's would have the port 80 remote-assist open for possibly helping a customer,I know that is the first thing i switch to 'off' ,and actually, my isp went thru that with me on inst

[Full-disclosure] Multiple CSRF and XSS vulnerabilities in ADSL modem Callisto 821+

2011-07-29 Thread MustLive
Hello list! After discussion with Michael Simpson about these vulnerabilities in Callisto 821+, I want to warn you about new multiple security vulnerabilities in ADSL modem Callisto 821+ (SI2000 Callisto821+ Router). These are Cross-Site Request Forgery and Cross-Site Scripting vulnerabilities. I

[Full-disclosure] Multiple CSRF and XSS vulnerabilities in ADSL modem Callisto 821+

2011-07-18 Thread MustLive
Hello list! I want to warn you about new multiple security vulnerabilities in ADSL modem Callisto 821+ (SI2000 Callisto821+ Router). These are Cross-Site Request Forgery and Cross-Site Scripting vulnerabilities. In April I've already drew attention of Ukrtelecom's representative (and this modem w

[Full-disclosure] Multiple CSRF and XSS vulnerabilities in ADSL modem Callisto 821+

2011-07-17 Thread MustLive
Hello list! I want to warn you about new multiple security vulnerabilities in ADSL modem Callisto 821+ (SI2000 Callisto821+ Router). These are Cross-Site Request Forgery and Cross-Site Scripting vulnerabilities. In April I've already drew attention of Ukrtelecom's representative (and this modem