Web Hack List

Collected research

SSID Script Injection

usefulfor.com/security » Blog Archive » SSID Script Injection

A rogue access point beaconing a malicious SSID gets its payload rendered and executed in the neighbouring-networks scan page of another AP's web admin interface. Two fake APs beat the 32-character SSID limit by joining the payload across both with JavaScript comment markers. The loaded script then CSRFs apply.cgi to switch off WPA. Demonstrated on DD-WRT.

Record

Document
usefulfor.com/security » Blog Archive » SSID Script Injection
Published by
usefulfor.com
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of usefulfor.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .