[Full-disclosure] Warning: BrailleNote Apex Offers Read/Write FTP And Telnet Access To All Comers

2010-10-01 Thread Sabahattin Gucukoglu
BrailleNote Apex offers telnet and FTP access on the standard ports, with read/write privilege on the entire file system, to all comers. No authentication is required. BrailleNote is unsafe on any network whose devices you are not in full charge of, and which (by NAT or firewall) does not

Re: [Full-disclosure] Warning: BrailleNote Apex Offers Read/Write FTP And Telnet Access To All Comers

2010-10-01 Thread Thor (Hammer of God)
...@list.humanware.com Cc: full-disclosure@lists.grok.org.uk; bugt...@securityfocus.com; me- ma...@sabahattin-gucukoglu.com; supp...@humanware.com Subject: [Full-disclosure] Warning: BrailleNote Apex Offers Read/Write FTP And Telnet Access To All Comers BrailleNote Apex offers telnet and FTP access on the standard

Re: [Full-disclosure] Warning: BrailleNote Apex Offers Read/Write FTP And Telnet Access To All Comers

2010-10-01 Thread Sabahattin Gucukoglu
On 1 Oct 2010, at 22:57, Thor (Hammer of God) wrote: ⠠⠊⠋ ⠃⠁⠙ ⠛⠥⠽⠎ ⠁⠗⠑ ⠕⠝ ⠽⠕⠥⠗ ⠝⠑⠞⠺⠕⠗⠅, ⠽⠕⠥ ⠼⠚⠼⠉⠼⠊;⠗⠑ ⠎⠉⠗⠑⠺⠑⠙ ⠁⠝⠽⠺⠁⠽ (If a bad guy is on your network, you're screwed anyway) With those services closed, it doesn't take a five-second run of nmap and wget to ransack the owner's device, though. And

Re: [Full-disclosure] Warning: BrailleNote Apex Offers Read/Write FTP And Telnet Access To All Comers

2010-10-01 Thread Thor (Hammer of God)
@lists.grok.org.uk; bugt...@securityfocus.com Subject: Re: [Full-disclosure] Warning: BrailleNote Apex Offers Read/Write FTP And Telnet Access To All Comers On 1 Oct 2010, at 22:57, Thor (Hammer of God) wrote: ⠠⠊⠋ ⠃⠁⠙ ⠛⠥⠽⠎ ⠁⠗⠑ ⠕⠝ ⠽⠕⠥⠗ ⠝⠑⠞⠺⠕⠗⠅, ⠽⠕⠥ ⠼⠚⠼⠉⠼⠊;⠗⠑ ⠎⠉⠗⠑⠺⠑⠙ ⠁⠝⠽⠺⠁⠽ (If a bad guy is on your network