7 ms·
I don't understand. What point is being made here?
by core-e 5y ago
I don't understand. What point is being made here?
- fungiblecog 5y agoPeople are exposing their routers to the internet. This is not a good idea.
- csomar 5y agoProbably people not aware of exposing their routers to the Internet.
- core-e 5y agoThanks. How do I make sure I'm not on this list?
- mixedCase 5y agoEasiest, most practical, 90% good enough: Get your IP address, grab your phone on mobile network and go to http://your.ip.address http://your.ip.address
- iamcreasy 5y agoSo, if I was exposed I will see the router's login page?
- Arrath 5y agoIf you're running their equipment, you may see your ISP provided modem's login page, which ideally should have whatever randomly generated password was on the sticker on the bottom of the modem when you got your service. A shade more secure than a router with default credentials.
- kelnos 5y agoI'd hope you don't even see that. Your ISP shouldn't be exposing that to the internet by default, either. Ideally you get connection refused or an eventual timeout.
- cafxx 5y agoRun a port scan on your public IP address. Plenty of websites allow you to do it, although it's probably safer to grab a shell on any other host connected to the internet (could be even just your phone connected to its mobile network) and run a port scan (e.g. nmap) from there.
- Alupis 5y agoThere are legit reasons to have a router be publicly accessible. How else would one remotely manage a router (top results in Google are businesses and universities, for example). Since the default configuration of these routers is not to expose the router on the WAN interface, manually overriding this configuration usually demonstrates a sufficient enough understanding that the default credentials have likely also been changed. The only real issue would be using a default password, which none of the top results shown on Google seem to have (thankfully). So, little-to-no issue here.
- Johnny555 5y agomanually overriding this configuration usually demonstrates a sufficient enough understanding that the default credentials have likely also been changed I don't think that's a reasonable assumption at all -- the router should ensure that the admin cred has been set to a (reasonably secure) password. Just because someone read on a web page that they should enable remote admin doesn't mean that they understand the risk. And it should warn that exposing the admin interface to the internet may make the router more vulnerable to remote exploits - basically the same type warning that browsers show for a bad SSL cert should be shown for insecure router configs - tell the user that it's insecure and is a really bad idea before they do it.
- Alupis 5y agoHow do you know this router doesn't already do that? You're making some wild assumptions here. Even your basic free Comcast router comes with sane defaults, and tons of warnings for every configuration change. Here's the user manual for the TP-Link AC2300 - The Archer C7 found in the google results this post links to: https://static.tp-link.com/2019/201912/20191231/7106508598_Archer%20C2300(US)_QIG_V2.pdf https://static.tp-link.com/2019/201912/20191231/7106508598_A... Step 2 forces the default password to be changed. There is no way around that step. None of your assumptions are true here.
- Johnny555 5y agoHere's another TP-link manual: https://www.tp-link.com/us/support/faq/66/ https://www.tp-link.com/us/support/faq/66/ 1. Open the web browser and in the address bar type in: http://192.168.1.1 http://192.168.1.1 2. Type the username and password in the login page. They are both admin by default. 3. Click Security->Remote Management on the left side 4. To enable this function, please change the Remote Management IP address from 0.0.0.0 to a specific authorized remote IP address. Here's the warning they give at the bottom of the manual: Few people read the entire manual, if they read it at all, they read enough to do what they want, and fewer still know what "Use this with caution" means. I don't even know what it means. I typed 255.255.255.255 carefully, is that sufficient caution? Type 255.255.255.255 Remote Management IP Address means that you can connect to the router remotely from anywhere via Internet, this is not recommended and please use it with caution We suggest changing the default log in Username and Password if the Remote Management feature is enabled, especially if you typed 255.255.255.255 as the Remote Management IP address.
- angott 5y agoThere are thousands of TP-LINK routers whose WAN port 80/443 is exposed to the Internet, allowing access to their administration interface if you know the password (or a vulnerability is present).
- toxicFork 5y agoAnd I'd bet a nice amount that most of them have the default passwords. Some years ago I wrote a little tool to iterate all of an ISP's ip addresses and around 90% were using default passwords. Mostly homes, but some businesses.
- power78 5y agoAccording to a comment above, these routers require an admin password change when setup with no way around that.
- deleted 5y ago[deleted]
- toxicFork 5y agoSounds like they learned their lesson
- deleted 5y ago[deleted]
- MontrealRaised 5y agoThe ISP assigned a unique password and puts it as a label beneath the router - in my case. I kept it. I consider it save enough.
- iamcreasy 5y agoI was planning to host a simple website on my RasberryPi using Dynamic DNS - which I think requires me to expose port 80 to the internet. Is that safe?
- syncsynchalt 5y agoIt's a demonstration of google dorking. Construct a google search term that returns attackable hosts. Skip past the first few results, then you'll see a list of likely easily-hackable home routers. If you were to try user/pass combos like "admin"/"admin" on these results I bet you'd have successful logins on several of them. Don't actually do this (seriously, the penalties aren't light), the demonstration of the search results is enough to make the point.
- deleted 5y ago[deleted]