Live data from Hacker News

Unauthenticated RCE in Motorola's MR2600 Router

mrbruh.com

11–20 of 32 posts

Re: Unauthenticated RCE in Motorola's MR2600 Router

#11
Really curious the use of the "zoom.com" domain. However, since the endpoint uses insecure HTTP, maybe this should be a simple endpoint/hostname redirection.

A search of "router/firmware/query.aspx" leads me to D-Link endpoints who also uses the "wrpd" subdomain.

Re: Unauthenticated RCE in Motorola's MR2600 Router

#12

In Germany we have "Störerhaftung" where routerowners are responsible for everything that happens through their router. I wonder how this would hold up in court, couldn't you argue that routers are generally buggy, how can they force any responsibility if they can easily be hacked?

It won't work. You would need to back up your claim with proof that someone hacked your router. You can't drive a car that is easily breakable and expect the court to clear you of any responsibility if it causes harm because it broke while you were driving.

Re: Unauthenticated RCE in Motorola's MR2600 Router

#13
post #11

Really curious the use of the "zoom.com" domain. However, since the endpoint uses insecure HTTP, maybe this should be a simple endpoint/hostname redirection. A search of "router/firmware/query.aspx" leads me to D-Link endpoints who also uses the "wrpd" subdomain.

Zoom were a very longstanding modem company who expanded into cable and routers and licensed the Motorola brand in 2016.

Re: Unauthenticated RCE in Motorola's MR2600 Router

#14

In Germany we have "Störerhaftung" where routerowners are responsible for everything that happens through their router. I wonder how this would hold up in court, couldn't you argue that routers are generally buggy, how can they force any responsibility if they can easily be hacked?

It won't work. You would need to back up your claim with proof that someone hacked your router. You can't drive a car that is easily breakable and expect the court to clear you of any responsibility if it causes harm because it broke while you were driving.

But if it’s the isp delivered router they should carry the responsibility

Re: Unauthenticated RCE in Motorola's MR2600 Router

#15

In Germany we have "Störerhaftung" where routerowners are responsible for everything that happens through their router. I wonder how this would hold up in court, couldn't you argue that routers are generally buggy, how can they force any responsibility if they can easily be hacked?

It won't work. You would need to back up your claim with proof that someone hacked your router. You can't drive a car that is easily breakable and expect the court to clear you of any responsibility if it causes harm because it broke while you were driving.

An allegory here would be someone stealing an easily stealable car (e.g. doing the Kia Challenge) and causing damage or injury. The thief would be liable, not the owner

Re: Unauthenticated RCE in Motorola's MR2600 Router

#16
post #14

Earlier quoted context omitted.

It won't work. You would need to back up your claim with proof that someone hacked your router. You can't drive a car that is easily breakable and expect the court to clear you of any responsibility if it causes harm because it broke while you were driving.

But if it’s the isp delivered router they should carry the responsibility

I would assume that liability is avoided when someone has done a reasonable effort to secure the device. The user needs to make sure they've secured their router from unauthorized access by using proper passwords. The ISP needs to make sure the router is delivered with the latest firmware and is pre-configured to be secure.

Re: Unauthenticated RCE in Motorola's MR2600 Router

#17

>42 hosts with remote management >vender doesn’t want to fix it Sometimes I wonder if the white hat hackers who find such a thing should just take it a step further and patch those hosts. Take the firmware, fix those bugs and update those 42 routers.

Someone did, a Russian dude (or at least Russian speaking) updated over a 100.000 Mikrotik routers. While he did get a few "Thank you" notes, some users was also pretty angry with him.

https://www.zdnet.com/article/a-mysterious-grey-hat-is-patch...

Re: Unauthenticated RCE in Motorola's MR2600 Router

#18

In Germany we have "Störerhaftung" where routerowners are responsible for everything that happens through their router. I wonder how this would hold up in court, couldn't you argue that routers are generally buggy, how can they force any responsibility if they can easily be hacked?

It would depend on the laws of the jurisdiction. I would imagine if you can show you kept the firmware up to date and had a secure as possible config (eg not having admin interfaces exposed to the internet), you could argue that there's no negligence - outside of maybe using a known insecure vendor; sometimes I think that would be a good idea (cough cough Fortinet).

Germany has some sensible laws about personal responsibility, like it being an offence to run out of gas on the autobahn and seriously treating driving in general as a privilege. But it requires a certain cultural mindset.

Re: Unauthenticated RCE in Motorola's MR2600 Router

#19
post #15

Earlier quoted context omitted.

It won't work. You would need to back up your claim with proof that someone hacked your router. You can't drive a car that is easily breakable and expect the court to clear you of any responsibility if it causes harm because it broke while you were driving.

An allegory here would be someone stealing an easily stealable car (e.g. doing the Kia Challenge) and causing damage or injury. The thief would be liable, not the owner

Generally any damage done by a car is the responsibility of its owner. The owner will likely be sued anyway, because they have insurance and assets, and the thief (even if known) does not.

Re: Unauthenticated RCE in Motorola's MR2600 Router

#20
post #16
post #14

Earlier quoted context omitted.

But if it’s the isp delivered router they should carry the responsibility

I would assume that liability is avoided when someone has done a reasonable effort to secure the device. The user needs to make sure they've secured their router from unauthorized access by using proper passwords. The ISP needs to make sure the router is delivered with the latest firmware and is pre-configured to be secure.

The last few routers I've had from an ISP are totally turnkey. There's no configuration, no passwords set (maybe the local Wifi password), any config is done with an app that talks to the ISP, who then updates the router settings remotely. There isn't even an admin interface you can access from the local network side.
Post reply on HN