A search of "router/firmware/query.aspx" leads me to D-Link endpoints who also uses the "wrpd" subdomain.
Unauthenticated RCE in Motorola's MR2600 Router
11–20 of 32 posts
Re: Unauthenticated RCE in Motorola's MR2600 Router
#12In Germany we have "Störerhaftung" where routerowners are responsible for everything that happens through their router. I wonder how this would hold up in court, couldn't you argue that routers are generally buggy, how can they force any responsibility if they can easily be hacked?
Re: Unauthenticated RCE in Motorola's MR2600 Router
#13Really curious the use of the "zoom.com" domain. However, since the endpoint uses insecure HTTP, maybe this should be a simple endpoint/hostname redirection. A search of "router/firmware/query.aspx" leads me to D-Link endpoints who also uses the "wrpd" subdomain.
Re: Unauthenticated RCE in Motorola's MR2600 Router
#14In Germany we have "Störerhaftung" where routerowners are responsible for everything that happens through their router. I wonder how this would hold up in court, couldn't you argue that routers are generally buggy, how can they force any responsibility if they can easily be hacked?
It won't work. You would need to back up your claim with proof that someone hacked your router. You can't drive a car that is easily breakable and expect the court to clear you of any responsibility if it causes harm because it broke while you were driving.
Re: Unauthenticated RCE in Motorola's MR2600 Router
#15In Germany we have "Störerhaftung" where routerowners are responsible for everything that happens through their router. I wonder how this would hold up in court, couldn't you argue that routers are generally buggy, how can they force any responsibility if they can easily be hacked?
It won't work. You would need to back up your claim with proof that someone hacked your router. You can't drive a car that is easily breakable and expect the court to clear you of any responsibility if it causes harm because it broke while you were driving.
Re: Unauthenticated RCE in Motorola's MR2600 Router
#16Earlier quoted context omitted.
It won't work. You would need to back up your claim with proof that someone hacked your router. You can't drive a car that is easily breakable and expect the court to clear you of any responsibility if it causes harm because it broke while you were driving.
But if it’s the isp delivered router they should carry the responsibility
Re: Unauthenticated RCE in Motorola's MR2600 Router
#17>42 hosts with remote management >vender doesn’t want to fix it Sometimes I wonder if the white hat hackers who find such a thing should just take it a step further and patch those hosts. Take the firmware, fix those bugs and update those 42 routers.
https://www.zdnet.com/article/a-mysterious-grey-hat-is-patch...
Re: Unauthenticated RCE in Motorola's MR2600 Router
#18In Germany we have "Störerhaftung" where routerowners are responsible for everything that happens through their router. I wonder how this would hold up in court, couldn't you argue that routers are generally buggy, how can they force any responsibility if they can easily be hacked?
Germany has some sensible laws about personal responsibility, like it being an offence to run out of gas on the autobahn and seriously treating driving in general as a privilege. But it requires a certain cultural mindset.
Re: Unauthenticated RCE in Motorola's MR2600 Router
#19Earlier quoted context omitted.
It won't work. You would need to back up your claim with proof that someone hacked your router. You can't drive a car that is easily breakable and expect the court to clear you of any responsibility if it causes harm because it broke while you were driving.
An allegory here would be someone stealing an easily stealable car (e.g. doing the Kia Challenge) and causing damage or injury. The thief would be liable, not the owner
Re: Unauthenticated RCE in Motorola's MR2600 Router
#20Earlier quoted context omitted.
But if it’s the isp delivered router they should carry the responsibility
I would assume that liability is avoided when someone has done a reasonable effort to secure the device. The user needs to make sure they've secured their router from unauthorized access by using proper passwords. The ISP needs to make sure the router is delivered with the latest firmware and is pre-configured to be secure.