3 ms·
> Perhaps their high-level thought process is like this? Yes, I think you're right and it was difficult to understand. The thinking is that, as you can trigger
by swinglock 6y ago
> Perhaps their high-level thought process is like this?
Yes, I think you're right and it was difficult to understand. The thinking is that, as you can trigger Telia servers to connect to you, using software which appears past its expiration date, you may be able to exploit that software to root their command and control server. Do that and you own Telias whole botnet of customers.
- tpmx 6y agoStrictly speaking they didn't show that two separate consumer routers have the same remote management password.
- swinglock 6y agoThey didn't show it but they did say the old routers share the same password. I can take that at face value, it's easy enough for a Lithuanian researcher to verify by asking a friend, I assume they did. They say later models allow only pub keys but didn't go into more details. I would assume they all have the same keys in firmware if not shown otherwise. Either way, the Telia CnC server would know all unique (if so) passwords or keys, so it may make little difference if exploited.
- tpmx 6y ago> but they did say the old routers share the same password Ah, missed that.