Live data from Hacker News

Please log in with router's password

google.com

21–30 of 265 posts

Re: Please log in with router's password

#22
Folks - these routers are secure. There is nothing to see here, move along.

Here's the user manual for the TP-Link AC2300 "Archer C7", as found in the google results:

https://static.tp-link.com/2019/201912/20191231/7106508598_A...

Step 2 of first time setup forces a default password change. There is no way around this step.

The defaults for the router also do not allow router access from the WAN port.

This means:

1) These routers all have secured passwords that are non-default.

2) These routers were deliberately placed on the internet by people that knew enough about them to do so.

Just because it's not how you would configure your router doesn't make it wrong. There are legit reasons to place a router on the internet, so long as it's secured properly... how else would you remotely manage a router at a different physical location, for instance.

__Lastly__ click "Next Page" on the OP search results. The estimated 7,000+ results becomes 21. Many of which are HN aggregators reporting on this thread here.

So... out of the possible millions of routers TP-Link has sold in this model line, less than 21 are on the public internet - many of which no longer load via IP address (indicating they are no longer publicly accessible), and the rest have professional CNAME's attached, indicating professional management.

Nothing here...

Re: Please log in with router's password

#23
post #2

To the reader: if this is your first exposure to finding things that aren't supposed to be exposed to the internet and you're finding it interesting enough to want to learn more, there's a tool commonly used among security practitioners called Shodan that enables a much more tunable search for exposed assets. https://en.wikipedia.org/wiki/Shodan_(website) - deeper reading. I'm not affiliated. --- It's also a super ba…

Are Skydrive documents somewhat public or are people just sharing them by mistake? I don't use it nor am I that familiar with it.

Re: Please log in with router's password

#24
post #3

I don't understand. What point is being made here?

It's a demonstration of google dorking. Construct a google search term that returns attackable hosts.

Skip past the first few results, then you'll see a list of likely easily-hackable home routers. If you were to try user/pass combos like "admin"/"admin" on these results I bet you'd have successful logins on several of them.

Don't actually do this (seriously, the penalties aren't light), the demonstration of the search results is enough to make the point.

Re: Please log in with router's password

#25
post #14

Earlier quoted context omitted.

manually overriding this configuration usually demonstrates a sufficient enough understanding that the default credentials have likely also been changed I don't think that's a reasonable assumption at all -- the router should ensure that the admin cred has been set to a (reasonably secure) password. Just because someone read on a web page that they should enable remote admin doesn't mean that they understand the risk…

How do you know this router doesn't already do that? You're making some wild assumptions here. Even your basic free Comcast router comes with sane defaults, and tons of warnings for every configuration change. Here's the user manual for the TP-Link AC2300 - The Archer C7 found in the google results this post links to: https://static.tp-link.com/2019/201912/20191231/7106508598_A... Step 2 forces the default password t…

Here's another TP-link manual:

https://www.tp-link.com/us/support/faq/66/

1. Open the web browser and in the address bar type in: http://192.168.1.1

2. Type the username and password in the login page. They are both admin by default.

3. Click Security->Remote Management on the left side

4. To enable this function, please change the Remote Management IP address from 0.0.0.0 to a specific authorized remote IP address.

Here's the warning they give at the bottom of the manual:

Few people read the entire manual, if they read it at all, they read enough to do what they want, and fewer still know what "Use this with caution" means. I don't even know what it means. I typed 255.255.255.255 carefully, is that sufficient caution?

Type 255.255.255.255 Remote Management IP Address means that you can connect to the router remotely from anywhere via Internet, this is not recommended and please use it with caution

We suggest changing the default log in Username and Password if the Remote Management feature is enabled, especially if you typed 255.255.255.255 as the Remote Management IP address.

Re: Please log in with router's password

#26

I think this is more the fault of manufacturers than end users. Routers should be secure by default, and it should be hard to do something that will make it insecure. The router manufacturers are the supposed experts when it comes to networking, expecting every consumer to even know the risks of exposing their router admin interface to the world is not a reasonable assumption.

So it's the car companies fault if I crash my car? They should limit vehicle speed to 5mph so I don't hurt myself or others. I have used many of these routers. Admin access on the wan port is blocked by default and must be enabled by the user.

You are making a very good point: the order of gear shifting was tightly regulated after a lot of accidents caused by NDLR order (instead of the now-standard PRNDL). In fact most automotive interfaces have regulations to standardize them after enough accidents were caused by people getting new cars that had different interfaces.

Re: Please log in with router's password

#28
post #3

I don't understand. What point is being made here?

It's a demonstration of google dorking. Construct a google search term that returns attackable hosts. Skip past the first few results, then you'll see a list of likely easily-hackable home routers. If you were to try user/pass combos like "admin"/"admin" on these results I bet you'd have successful logins on several of them. Don't actually do this (seriously, the penalties aren't light), the demonstration of the sear…

[deleted]

Re: Please log in with router's password

#29
post #23
post #2

To the reader: if this is your first exposure to finding things that aren't supposed to be exposed to the internet and you're finding it interesting enough to want to learn more, there's a tool commonly used among security practitioners called Shodan that enables a much more tunable search for exposed assets. https://en.wikipedia.org/wiki/Shodan_(website) - deeper reading. I'm not affiliated. --- It's also a super ba…

Are Skydrive documents somewhat public or are people just sharing them by mistake? I don't use it nor am I that familiar with it.

> Are Skydrive documents somewhat public or are people just sharing them by mistake? I don't use it nor am I that familiar with it.

Almost all of this would be by mistake, no different than misconfiguring an S3 bucket.

Post reply on HN