Live data from Hacker News

Please log in with router's password

google.com

1–10 of 265 posts

Re: Please log in with router's password

#2
To the reader: if this is your first exposure to finding things that aren't supposed to be exposed to the internet and you're finding it interesting enough to want to learn more, there's a tool commonly used among security practitioners called Shodan that enables a much more tunable search for exposed assets.

https://en.wikipedia.org/wiki/Shodan_(website) - deeper reading. I'm not affiliated.

---

It's also a super basic intro to proper google-fu (which you can google to find others' takes on how to become somewhat effective at, erm, googling). Back when I used to blog on Microsoft-related topics, it was common to construct extremely narrow queries to find exposed confidential documents in Skydrive accounts which we could then sift through to find bloggable material.

e.g site:[skydrive domain] filetype:.pptx "Microsoft Confidential" etc.

Or one which still works:

https://www.google.com/search?q="Microsoft+Confidential"+sit...

lmao I'm going to have some fun tonight.

Re: Please log in with router's password

#8
post #3

I don't understand. What point is being made here?

People are exposing their routers to the internet. This is not a good idea.

There are legit reasons to have a router be publicly accessible. How else would one remotely manage a router (top results in Google are businesses and universities, for example).

Since the default configuration of these routers is not to expose the router on the WAN interface, manually overriding this configuration usually demonstrates a sufficient enough understanding that the default credentials have likely also been changed.

The only real issue would be using a default password, which none of the top results shown on Google seem to have (thankfully). So, little-to-no issue here.

Re: Please log in with router's password

#9
I think this is more the fault of manufacturers than end users.

Routers should be secure by default, and it should be hard to do something that will make it insecure. The router manufacturers are the supposed experts when it comes to networking, expecting every consumer to even know the risks of exposing their router admin interface to the world is not a reasonable assumption.

Re: Please log in with router's password

#10
post #7

Earlier quoted context omitted.

People are exposing their routers to the internet. This is not a good idea.

Thanks. How do I make sure I'm not on this list?

Easiest, most practical, 90% good enough: Get your IP address, grab your phone on mobile network and go to http://your.ip.address
Post reply on HN