Live data from Hacker News

Please log in with router's password

google.com

51–60 of 265 posts

Re: Please log in with router's password

#51

Earlier quoted context omitted.

Easiest, most practical, 90% good enough: Get your IP address, grab your phone on mobile network and go to http://your.ip.address

So, if I was exposed I will see the router's login page?

If you're running their equipment, you may see your ISP provided modem's login page, which ideally should have whatever randomly generated password was on the sticker on the bottom of the modem when you got your service. A shade more secure than a router with default credentials.

Re: Please log in with router's password

#52
post #43

Earlier quoted context omitted.

These are not high end enterprise grade kit, folks. Expecting things like MFA, secondary VPN endpoints, etc is just absurd for the target audience of this device. Again, just because you wouldn't configure it this way doesn't make it wrong. It's as secure as it can be, short of throwing a bunch of other kit in front of it, and then why would you be using a $100 consumer router anyway? The only vulnerability here is t…

> The only vulnerability here is the possibility of a 0-Day. That's not exactly uncommon in cheap consumer routers. No rate limiting is as good as no authentication.

> That's not exactly uncommon in cheap consumer routers.

That's, in my opinion, the only fair criticism available here.

> No rate limiting is as good as no authentication.

Trying to even load some of the links found in Google takes 10's of seconds. That's effectively a rate limit, even if it doesn't temp-ban per IP address.

Someone would have to dump the firmware to find out, but it would be trivial for each device to generate their own salt - making a potential lack of rate limit a non-issue.

Re: Please log in with router's password

#53
post #22

Folks - these routers are secure. There is nothing to see here, move along. Here's the user manual for the TP-Link AC2300 "Archer C7", as found in the google results: https://static.tp-link.com/2019/201912/20191231/7106508598_A... Step 2 of first time setup forces a default password change. There is no way around this step. The defaults for the router also do not allow router access from the WAN port. This means: 1)…

not every tp-link model (or revision, or locale, or firmware version) that shares a web interface with the c7 requires you to manually set a password. even if that were the case, there are bound to be users who aren't security savvy and chose a very weak password (e.g. "password", "admin").

many tp-link routers also have configurable vpn servers built in, which can open up the whole network to malicious actors.

Re: Please log in with router's password

#54
post #44

Earlier quoted context omitted.

OK so what? Nothing you've stated here applies to the original post. You're fabricating some outrage about nothing relevant. The original post shows Archer C7 and C9 routers...

What original post? It was a google search that reveals some router's remote admin page, that search doesn't mention any specific router brand or model. But regardless, I was responding specifically to your comment: manually overriding this configuration usually demonstrates a sufficient enough understanding that the default credentials have likely also been changed (That's why I quoted it in my reply) And the point…

> What original post? It was a google search that reveals some router's remote admin page, that search doesn't mention any specific router brand or model.

It does, click any of the links. The specific search string OP used returns only C6, C7 and C9 routers (I clicked through 2 pages of results).

You saw TP-Link and went off about things that were valid to complain about in the past... but are not specifically with these routers, and probably no new model TP-Link or any sane manufacturer is turning out today.

> And the point I was trying to make is that merely being able to override the default remote admin setting does not ensure that the user has any idea what the ramifications are

Again, if you actually clicked through the OP, you'd notice most of the bare IP address results are dead (meaning they are no longer on the internet), and the ones with CNAME's attached appear to be professionally managed. The assumption is sound.

Re: Please log in with router's password

#56
post #8

Earlier quoted context omitted.

There are legit reasons to have a router be publicly accessible. How else would one remotely manage a router (top results in Google are businesses and universities, for example). Since the default configuration of these routers is not to expose the router on the WAN interface, manually overriding this configuration usually demonstrates a sufficient enough understanding that the default credentials have likely also be…

> There are legit reasons to have a router be publicly accessible. No, there are not. > How else would one remotely manage a router Over a WireGuard connection to a secure management network. > The only real issue would be using a default password Uh, no. Try any number of CVEs or 0-days or unknown-until-it's too-late vulnerabilities, depending on what web daemon/frameworks are used by the router's management softwar…

Even if all of that is updated and secure; with the services exposed, it's less than trivial to make that service eat the small amount of memory it has to work with, and take down the network it manages.

Re: Please log in with router's password

#57
post #45
post #21

Funny enough just 45 minutes later this very HN thread is the top result on Google.

We live in the endless loop folks! It took me a while to realize if it was actually the purpose of this post. Edit: Yes, it was not.

It is not. The purpose is to show misconfigured access points accessible through the internet

Re: Please log in with router's password

#58
post #45
post #21

Funny enough just 45 minutes later this very HN thread is the top result on Google.

We live in the endless loop folks! It took me a while to realize if it was actually the purpose of this post. Edit: Yes, it was not.

I don't think that was the purpose of this post.

Re: Please log in with router's password

#59
post #22

Folks - these routers are secure. There is nothing to see here, move along. Here's the user manual for the TP-Link AC2300 "Archer C7", as found in the google results: https://static.tp-link.com/2019/201912/20191231/7106508598_A... Step 2 of first time setup forces a default password change. There is no way around this step. The defaults for the router also do not allow router access from the WAN port. This means: 1)…

I would love to know how these are secured. I doubt there's MFA or even rate limiting. > 2) These routers were deliberately placed on the internet by people that knew enough about them to do so. That's making some very generous assumptions.

>That's making some very generous assumptions.

Disagree. In my current country of living, I'm not even sure how I'd properly expose the router I use to the public internet since I sit behind the ISP's NAT-ing, and even when I lived in the US, I am not confident I could tell you how to publicly expose the modem provided by Comcast for non-local access, much less how someone without any tech experience might do this.

If this was a prevalent problem because of default settings, I'd expect far more than 7800 results; I am not willing to concede every instance is intentional, but 7800 out of the billions of routing devices in the world showing up on this search enforces my understanding that these 7800 entries are special in some way.

>I doubt there's MFA or even rate limiting.

MFA is not common at all on consumer routers, which at least quite a few on the first page result are, same with rate limiting.

Even for Enterprise grade gear, the threat isn't the user-defined password, it's the manufacturer backdoors, which we've seen many of in the last few years. Rate limiting doesn't do much if you have a fair chance that you've got a back door.

What likely __does__ help is that as far as I know, "Enable Web Access from WAN" is by default *disabled* on most consumer routers (and enterprise? that I'm not sure of), so I think that this leads credence to the devices on the Google results being exposed intentionally to some degree. (The owners' knowledge level not withstanding, this is a fairly out of the way setting, at least on my Asus router)

Post reply on HN