[Full-disclosure] Polycom hacking

b.hines at comcast.net b.hines at comcast.net
Tue Jun 26 18:51:58 BST 2007


Nice, that and an unchanged default password...

-------------- Original message -------------- 
From: StaticRez <staticrez at gmail.com> 

> Hey... 
> 
> Some of the PolyCom devices have manageable web interfaces. (Web Commander) 
> Some of these interfaces might be exploitable. 
> 
> here's one: http://webcommander.esc12.net/confsitev7_0/default.asp?Rnd= 
> 
> take care, 
> 
> StaticRez 
> 
> 
> 
> On 6/26/07, Paul Schmehl wrote: 
> > Is anyone aware of any work done in the field of hacking Polycom 
> > video-conferencing devices? Or any known hacks for Polycom devices? 
> > 
> > -- 
> > Paul Schmehl (pauls at utdallas.edu) 
> > Senior Information Security Analyst 
> > The University of Texas at Dallas 
> > http://www.utdallas.edu/ir/security/ 
> > 
> > _______________________________________________ 
> > Full-Disclosure - We believe in it. 
> > Charter: http://lists.grok.org.uk/full-disclosure-charter.html 
> > Hosted and sponsored by Secunia - http://secunia.com/ 
> > 
> > 
> 
> _______________________________________________ 
> Full-Disclosure - We believe in it. 
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html 
> Hosted and sponsored by Secunia - http://secunia.com/ 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20070626/eac73aa7/attachment.html 


Full-Disclosure is hosted and sponsored by Secunia.