Earlier quoted context omitted.
You can install openWRT on their router and gain full access to their network.
Once I get access to their network, what can I do? What does that do for me?
Please log in with router's password
161–170 of 265 posts
Re: Please log in with router's password
#162Funny enough just 45 minutes later this very HN thread is the top result on Google.
Re: Please log in with router's password
#163Earlier quoted context omitted.
And I'd bet a nice amount that most of them have the default passwords. Some years ago I wrote a little tool to iterate all of an ISP's ip addresses and around 90% were using default passwords. Mostly homes, but some businesses.
According to a comment above, these routers require an admin password change when setup with no way around that.
Re: Please log in with router's password
#164Earlier quoted context omitted.
> Folks - these routers are secure. There is nothing to see here, move along. If experience is any guide, they are not. Consumer routers have horrible track of embarrassing, easily exploitable vulnerabilities. That are not patched for a long time or ever. And exposing your router to public like that suggests the owner knows very little about security. This typically goes in hand with other neglect. Tell me, how many…
What router does HN recommend for consumers? I personally run Ubiquiti Unifi gear, but they're not exactly consumer friendly (more geared to power users).
Re: Please log in with router's password
#165Earlier quoted context omitted.
All I'm going to say about Shodan is... Too many people leave the default password on internet connected devices. Seriously, anything is better than the default password.
Note that Shodan doesn't try to login using default credentials. If you see banners advertising their defaults it just means that the device is telling you what its defaults are - it doesn't mean that the device is still using them. That being said, a ton of devices still use default credentials but we don't have any numbers on how many exactly.
Re: Please log in with router's password
#166Earlier quoted context omitted.
+1. I don't think I ever saw a document marked UNCLASSIFIED// that was not marked UNCLASSIFIED//FOUO. I'm not convinced that there is such a thing as a document that should be marked unclassified that should not also be marked FOUO.
Press releases
Re: Please log in with router's password
#167Earlier quoted context omitted.
Note that Shodan doesn't try to login using default credentials. If you see banners advertising their defaults it just means that the device is telling you what its defaults are - it doesn't mean that the device is still using them. That being said, a ton of devices still use default credentials but we don't have any numbers on how many exactly.
I wasn't implying Shodan did this. Shodan just lets you find things. Google reveals default passwords quite readily though. It's alarming how often they work to login.
Re: Please log in with router's password
#168Re: Please log in with router's password
#169Folks - these routers are secure. There is nothing to see here, move along. Here's the user manual for the TP-Link AC2300 "Archer C7", as found in the google results: https://static.tp-link.com/2019/201912/20191231/7106508598_A... Step 2 of first time setup forces a default password change. There is no way around this step. The defaults for the router also do not allow router access from the WAN port. This means: 1)…
> these routers are secure. Owner of a C7 v4 here. There has not been a firmware update from TP-Link since December 2019 (note that v4 is the second-most recent HW revision). No way these are not affected by at least some CVE somewhere in their stack. Calling them secure is a leap of faith that TP-Link does not deserve. I recently flashed openwrt exactly to be able to be on a more recent stack. I would never dream ex…
any chance you can explain that to my mum?
Re: Please log in with router's password
#170To the reader: if this is your first exposure to finding things that aren't supposed to be exposed to the internet and you're finding it interesting enough to want to learn more, there's a tool commonly used among security practitioners called Shodan that enables a much more tunable search for exposed assets. https://en.wikipedia.org/wiki/Shodan_(website) - deeper reading. I'm not affiliated. --- It's also a super ba…
The Wikipedia article is unfortunately woefully out of date in describing what Shodan does. For example, Shodan collects data on thousands of ports: https://www.shodan.io/search/facet?query=net%3A0%2F0&facet=p... And we don't concentrate on a single type of device/ service (the article mentions SCADA). We identify everything from industrial control systems (1) to Minecraft servers (2). The news coverage makes it soun…
so... did you fix it?