Live data from Hacker News

Please log in with router's password

google.com

231–240 of 265 posts

Re: Please log in with router's password

#231
post #7

Earlier quoted context omitted.

People are exposing their routers to the internet. This is not a good idea.

Thanks. How do I make sure I'm not on this list?

Run a port scan on your public IP address.

Plenty of websites allow you to do it, although it's probably safer to grab a shell on any other host connected to the internet (could be even just your phone connected to its mobile network) and run a port scan (e.g. nmap) from there.

Re: Please log in with router's password

#232

Earlier quoted context omitted.

That's not how it works. Shodan continuously checks all IPs on the Internet. When you visit the website you're checking for existing information in the database. Your use of the Shodan website/ API doesn't change how Shodan crawls the Internet.

How do I check my server, which doesn't have a browser installed?

It looks like it just redirects to " rel="nofollow">https://www.shodan.io/host/, so you should be able to just plug your server's IP in instead in your regular browser.

Re: Please log in with router's password

#233
post #2

To the reader: if this is your first exposure to finding things that aren't supposed to be exposed to the internet and you're finding it interesting enough to want to learn more, there's a tool commonly used among security practitioners called Shodan that enables a much more tunable search for exposed assets. https://en.wikipedia.org/wiki/Shodan_(website) - deeper reading. I'm not affiliated. --- It's also a super ba…

Not that I didn't know about its existence, but I just entered the IP of my VPS and noticed that Portainer was bound to 0.0.0.0... I thought I had it bound to the docker bridge so now I've got to put in some time to see if all is ok. Thank you! Narrator: All was ok.

[deleted]

Re: Please log in with router's password

#235

Earlier quoted context omitted.

Grab an old office computer stick and Intel NIC and run OPNsense [0] on it. I've got an old Lenovo ThinkStation and it works brilliantly. [0] https://opnsense.org/

That is, assuming you have plenty of time. I don't. Is it too much to ask to have competently built hardware with competent software for a reasonable price enabled by mass production? I mean, just don't make stupid things like open access to it from a single point of failure where a single engineer can loose their AWS key and enable attackers to access million networks? Or build devices that overheat placed on an ope…

It depends on your experience. For me it didn't require much time at all. You might also consider it a valuable learning experience so worth making the time. I would highly recommend being on top of your own home network as you really never know when networking skills will come in handy.

Re: Please log in with router's password

#236
post #64
post #45

Earlier quoted context omitted.

We live in the endless loop folks! It took me a while to realize if it was actually the purpose of this post. Edit: Yes, it was not.

This reminds me of when Sergey Brin explained recursion to Terry Gross in this interview (14:45 seconds into the interview) https://freshairarchive.org/segments/google-founders-larry-p...

Is there a summary or text version for people unable to view a video at the moment?

Re: Please log in with router's password

#237

Earlier quoted context omitted.

That is, assuming you have plenty of time. I don't. Is it too much to ask to have competently built hardware with competent software for a reasonable price enabled by mass production? I mean, just don't make stupid things like open access to it from a single point of failure where a single engineer can loose their AWS key and enable attackers to access million networks? Or build devices that overheat placed on an ope…

It depends on your experience. For me it didn't require much time at all. You might also consider it a valuable learning experience so worth making the time. I would highly recommend being on top of your own home network as you really never know when networking skills will come in handy.

I have some ops experience but that was 20 years ago. Nowadays if I need to do something like that I have to do a bunch of research and spend a lot of time on it. Which I would prefer spending, for example, with my son teaching him programming.

I can sympathize with people that don't have technical background -- these are practically defenseless.

Re: Please log in with router's password

#239

Earlier quoted context omitted.

Once I get access to their network, what can I do? What does that do for me?

Search for vulnerable PC's, install ransomware, extract $$ from the victim. Or just generally cause havoc "for the fun of it", which seems to be a not uncommon motive for some people.

I guess you can also add it to a botnet?

Re: Please log in with router's password

#240

Earlier quoted context omitted.

How do I check my server, which doesn't have a browser installed?

It looks like it just redirects to " rel="nofollow">https://www.shodan.io/host/ , so you should be able to just plug your server's IP in instead in your regular browser.

Ah ok, I was browsing on mobile, so didn't see the entire url.

But it doesn't seem to work, unfortunately.

Post reply on HN