Vulnerability matrix
DHCPing is not limited to vulnerability research although it has provided good results
in this area as shown below.
Here is a list of all vulnerabilities found using DHCPing for which exploits are already available
under the form of command line options (called macros).
Type #dhcping -showmacros for an exhaustive list of exploits available.
Please send me your findings with details (vendor, firmware ... see table below)
so that i can keep this page as much current as possible.
Also do not forget to attach a screen dump along with your email (dhcping -nocolor ... > trace)
Doing so it will be easier to maintain the list of options available in the upcoming releases.
Send all your stuff to
C3rb3r at openwall.net
Finally if you think that something is missing or incorrect in this matrix, a fixed statement for instance,
please contact me.
Thanks
DHCPing
DHCP Vendor
Vulnerable release
Advisory
Researcher
Reported on
Severity
Fixed
0.91
ALCATEL/THOMSON
Speed Touch Pro
DNS poisonning
C3rb3r
Nov 12th 2004
Serious
No
0.91
3COM
3crwe754g72-a
Script injection
Cyrille Barthelemy
Oct 18th 2004
Critical
1.27
0.91
NETWORK EVERYWHERE
NR041 V1.2 Release 03
Script injection
Daemonz
Aug 8th 2004
Critical
No
0.9
ISC
3.0.1 RC12/RC13
Stack overflows
C3rb3r
Jun 7th 2004
Critical
3.0.1 RC14
0.9
ISC
3.0.1 RC12/RC13
.bss overflows
C3rb3r
Jun 7th 2004
Critical
3.0.1 RC14
0.9
INFOBLOX
2.4.0-8/2.4.0-8A
Script injection
C3rb3r
May 31st 2004
Critical
2.4.0-9 2.4.0-9A
0.9
DLINK
614+ Rev.A (2.30)
Script injection
C3rb3r
May 24th 2004
Critical
No
0.9
DLINK
614+ Rev.A (2.30)
Signedness bug / DOS
C3rb3r
May 24th 2004
Moderate
No
0.9
DLINK
614+ Rev.A (2.30)
Resource starvation / DOS
C3rb3r
May 24th 2004
Serious
No
0.9
DLINK
614+ Rev.B (3.41)
Script injection
C3rb3r
May 24th 2004
Critical
3.43
0.9
DLINK
614+ Rev.B (3.41)
Signedness bug / DOS
C3rb3r
May 24th 2004
Moderate
3.43
0.9
DLINK
614+ Rev.B (3.41)
Resource starvation / DOS
C3rb3r
May 24th 2004
Serious
3.43
0.9
DLINK
704 2.60B2
Script injection
C3rb3r
May 24th 2004
Critical
No
0.9
DLINK
624 Rev.A (1.24)
Script injection
C3rb3r
May 24th 2004
Critical
No
0.9
DLINK
624 Rev.A (1.24)
Signedness bug / DOS
C3rb3r
May 24th 2004
Moderate
No
0.9
DLINK
624 Rev.A (1.24)
Resource starvation / DOS
C3rb3r
May 24th 2004
Serious
No
0.9
DLINK
624 Rev.B (1.28)
Script injection
C3rb3r
May 24th 2004
Critical
No
0.9
DLINK
624 Rev.B (1.28)
Signedness bug / DOS
C3rb3r
May 24th 2004
Moderate
No
0.9
DLINK
624 Rev.B (1.28)
Resource starvation / DOS
C3rb3r
May 24th 2004
Serious
No
0.9
DLINK
624 Rev.C (2.42)
Script injection
C3rb3r
May 24th 2004
Critical
2.45
0.9
DLINK
624 Rev.C (2.42)
Signedness bug / DOS
C3rb3r
May 24th 2004
Moderate
2.45
0.9
DLINK
624 Rev.C (2.42)
Resource starvation / DOS
C3rb3r
May 24th 2004
Serious
2.45