3 ms·
What's the appliance? Most current consumer routers come with a backdoor called TR-069[0] that allows the ISP to provision and update the device. Recently other
by ymse 10y ago
What's the appliance? Most current consumer routers come with a backdoor called TR-069[0] that allows the ISP to provision and update the device. Recently other appliances than routers have started using the same protocol.
The session is initiated from the client, but if you can MITM it or compromise the provisioning server all bets are obviously off.
I have mixed feelings about TR-069, but don't see how devices can stay current without something like it.
0: https://en.wikipedia.org/wiki/TR-069 https://en.wikipedia.org/wiki/TR-069
- FiloSottile 10y agoNo, I'm talking about making a HTTP request to the device (ok, two or three, but no ninja stuff) -> getting a root shell. Not intended, but not really hard to find. And it's way less replaceable than a router, so I haven't found any better than to sit on it. About TR-069, criminals don't do BGP hijacking to pop a few routers (yet?). Still, why the hell is that not encrypted. (I know why, it's just that I'm sad.)
- voltagex_ 10y agoDisclose to the vendor, wait 90-180 days, write a nice blog post. See http://www.devttys0.com/2015/04/hacking-the-d-link-dir-890l/ http://www.devttys0.com/2015/04/hacking-the-d-link-dir-890l/ for one of my "favourites". I daren't push my $200 TP-Link too hard for fear of finding something like this.