4 ms·
I would guess for both good and evil. The good reason being able to login to the router to reset the password if the customer forgot it (I remember some home/s
by booop 13y ago
I would guess for both good and evil.
The good reason being able to login to the router to reset the password if the customer forgot it (I remember some home/small office routers don't reset the admin password when you use the reset button).
The evil reason being able to login remotely to any router and snoop around.
- 3rd3 13y agoBut itn’t the web interface usually not accessible from WAN?
- homeomorphic 13y agoSure, but all the adversary needs is for the user to visit a webpage that makes his/her browser contact the router (i.e. from within the LAN). If the adversary has to take into account defeating the user's password, this becomes an impractical attack. With the backdoor, however…
- deleted 13y ago[deleted]
- xyzzy123 13y agoMight be hard to set the user-agent for a JavaScript cross-origin request though...
- throwaway2048 13y agoflash allows you to generate UPNP requests, just generate one to forward the web server port to the internet, and you have an easy solution.
- smtddr 13y agoWell, I have a router that has remote-WAN-access disabled[1] ....and yet, if you type that (blurred out) IP:PORT into your browser you STILL get the prompt for user/pass. And if you type it correctly, you STILL access my router!!!!! So if my router has the same kind of UserAgent:roodkcabvogasn backdoor, I'm screwed. I really should get a new router... like...very soon. Also, I'm a conspiracy-nut and I think a significant amount of these "bugs" happen on purpose. 1. http://i.imgur.com/W06W1oB.png http://i.imgur.com/W06W1oB.png