Live data from Hacker News

Please log in with router's password

google.com

101–110 of 265 posts

Re: Please log in with router's password

#101
post #23
post #2

To the reader: if this is your first exposure to finding things that aren't supposed to be exposed to the internet and you're finding it interesting enough to want to learn more, there's a tool commonly used among security practitioners called Shodan that enables a much more tunable search for exposed assets. https://en.wikipedia.org/wiki/Shodan_(website) - deeper reading. I'm not affiliated. --- It's also a super ba…

Are Skydrive documents somewhat public or are people just sharing them by mistake? I don't use it nor am I that familiar with it.

You can create a long complicated link to share with other people, even people without Skydrive/OneDrive/Dropbox/Google Drive accounts. But sometimes people publish these links somewhere where a search engine's crawler sees it and follow it.

I remember spotting someone's URL to a Google Doc on their screen which their camera caught in their YouTube video. I manually typed it into my browser's URL bar and voila, I could read that document. Nothing juicy though.

Re: Please log in with router's password

#102
post #52

Earlier quoted context omitted.

> The only vulnerability here is the possibility of a 0-Day. That's not exactly uncommon in cheap consumer routers. No rate limiting is as good as no authentication.

> That's not exactly uncommon in cheap consumer routers. That's, in my opinion, the only fair criticism available here. > No rate limiting is as good as no authentication. Trying to even load some of the links found in Google takes 10's of seconds. That's effectively a rate limit, even if it doesn't temp-ban per IP address. Someone would have to dump the firmware to find out, but it would be trivial for each device t…

The load times are most likely primarily caused either by slow JS or high RTT/multiple requests, either of which could be trivially bypassed by an attacker. Or an attacker could just fire off 100 requests at the same time and saturate the bandwidth anyway, despite a high latency. And any high latency would likely be significantly lower if you happen to be in the same geographic area.

Latency is not rate-limiting.

Re: Please log in with router's password

#103
Hi folks, not much to see here.

These routers are very well designed, receive regular firmware updates and are overall very solid. The only router that I haven't had to reboot since I've owned it (for nearly 18 months now). Had no random configuration resets, interface bugs, WiFi drop-outs, QoS issues ... just, solid.

So seeing that people have exposed it to the internet - sure, that's not recommended. But I don't think that it is something to be overly concerned about. It doesn't feel like your normal internet of crap router.

And as others have said, this is not the default setting, and you're actually warned when you try and enable external access. But for some, this is useful. Since this router supports a VPN server, external access could be the only way to troubleshoot it if you're not on-site.

Re: Please log in with router's password

#104
post #8

Earlier quoted context omitted.

People are exposing their routers to the internet. This is not a good idea.

There are legit reasons to have a router be publicly accessible. How else would one remotely manage a router (top results in Google are businesses and universities, for example). Since the default configuration of these routers is not to expose the router on the WAN interface, manually overriding this configuration usually demonstrates a sufficient enough understanding that the default credentials have likely also be…

Every single remote site we have is managed via a VPN connection. The VPN endpoints are mostly the site's firewall but you could just as easily manage the router from a TeamViewer (LOL) connection into a system behind it.

> The only real issue would be using a default password, which none of the top results shown on Google seem to have (thankfully). So, little-to-no issue here.

You might want to think twice about attempting to log in to a system you weren't authorized to use. That's illegal in most jurisdictions.

Re: Please log in with router's password

#105
post #75

Click "Next Page" folks - estimated 7,000+ results turns into 21 results - many of which are dead, many others are HN aggregators, leaving the total amount of these model routers on the public internet to be a small handful - all of which appear to be professionally managed with CNAMEs, etc. All the outrage in this thread over nothing...

Ahem:

>In order to show you the most relevant results, we have omitted some entries very similar to the 22 already displayed. If you like, you can repeat the search with the omitted results included.

Re: Please log in with router's password

#106

Earlier quoted context omitted.

> The only vulnerability here is the possibility of a 0-Day. That's not exactly uncommon in cheap consumer routers. No rate limiting is as good as no authentication.

I'm a big fan of rate limiting (and even rate limit my static pages) but if your password is secure enough, the lack of a rate limit isn't going to help attackers. I kind of agree with the comment that started this thread -- people that have explicitly decided to expose their consumer-grade routers directly to the Internet probably know about password managers. Even if you do guess the password and compromise the rou…

> maybe some developer's local MySQL install happily listening on port 3306 somewhere.

And usually with default password because not on the internet. People often forget or underestimate lateral movement and metasploit reverse shell kits.

Re: Please log in with router's password

#109
post #2

To the reader: if this is your first exposure to finding things that aren't supposed to be exposed to the internet and you're finding it interesting enough to want to learn more, there's a tool commonly used among security practitioners called Shodan that enables a much more tunable search for exposed assets. https://en.wikipedia.org/wiki/Shodan_(website) - deeper reading. I'm not affiliated. --- It's also a super ba…

Some fun things here, as a google search: site:.gov "for official use only" filetype:pptx site:.gov "for official use only" filetype:pdf

fyi, "for official use only" or "fouo" is a slightly more than meaningless designation to shield stuff against FOIA inquiries. most of the stuff you'll find is pretty boring. a little more: https://en.wikipedia.org/wiki/For_Official_Use_Only#United_S...

Re: Please log in with router's password

#110

Hi folks, not much to see here. These routers are very well designed, receive regular firmware updates and are overall very solid. The only router that I haven't had to reboot since I've owned it (for nearly 18 months now). Had no random configuration resets, interface bugs, WiFi drop-outs, QoS issues ... just, solid. So seeing that people have exposed it to the internet - sure, that's not recommended. But I don't th…

Oh, great! It's stable! That means it couldn't possibly have any 0days or weak passwords.
Post reply on HN