Re: [Full-disclosure] Sprint / Verizon MiFi CSRF+CSS Gives up GPS info to attacker

2010-01-16 Thread A. Ramos
Hello all, Just another one: you can access to the configuration backup without authentication at: /config.xml.sav On Fri, Jan 15, 2010 at 17:12, Adam Baldwin adam_bald...@ngenuity-is.com wrote: The MiFi by Novatel Wireless (re-branded and sold by multiple vendors such as Sprint and Verizon)

Re: [Full-disclosure] Sprint / Verizon MiFi CSRF+CSS Gives up GPS info to attacker

2010-01-16 Thread Adam Baldwin
On 1/16/10 8:13 AM, A. Ramos wrote: Hello all, Just another one: you can access to the configuration backup without authentication at: /config.xml.sav If you have the Sprint MiFi with the latest firmware rev (AP 11.47.17 Router 018.0101) The correct path is /config.xml.savefile -Adam