PDA

View Full Version : WARNING adsl router users!



Nathan_200sx
11-02-2003, 13:53
CHANGE YOU FLIPPIN ROOT password.

Just playing about, as you do ;) and have found that the vast majority of dsl router's allow you to access the config utility "EXERNALY" by default. very dangerouse in my opinion, even more so with the average joe puplic knowing squat about security. The most worrying thing is that no one seems to be changing the default username and password for root, this almost makes me a little sad as to how vulnerable these people are. By accessing the config I can do pretty much anything with thier internal machine's or be just plain nasty and reconfig the router and change the password so they cant get back in to fix it. you can get all the default usernames and passwords by downloading any online manuals from the manufacturer of the router. The manual will contain detail of how to access this config from the internal network and give you the passwords to do so. Many make no mention of accessing it from an external ip so people dont worry about the root password.
I have mailed a few isp's where I know they send out certain routers asking them to make sure there customers 1st action is to change the password.
So guys just be aware, unfortunatly there are some scrotes out there who think it's funny or that there clever by screwing somebody up.

Vez
11-02-2003, 13:55
Well surely thats common sense.....

Nathan_200sx
11-02-2003, 13:57
Originally posted by Vez
Well surely thats common sense.....
you would think so, but I've found 15 so far with UN =DSL PW=DSL
3 fig passwords ffs!!!:rolleyes:

Vez
11-02-2003, 14:06
Shall I post what type of routers those passwords are valid for too then :D or do you want to do it....

I can also list the default passwords for a WHOLE bunch or routers if you like...

Nathan_200sx
11-02-2003, 14:15
Originally posted by Vez
Shall I post what type of routers those passwords are valid for too then :D or do you want to do it....

I can also list the default passwords for a WHOLE bunch or routers if you like...

Nah dont make it easy for people, some might look out of curiosity and screw something up by accident. I just wish people would get rid of default configs as soon as they can. Did you also know that push button lock systems come with default code as well? chubs is 2 and 4 together then 3 then turn clockwise:rolleyes: not many people change these either. we were going to put 1/2 a mil's worth of computer eqpt into a room that still had the default code on the door:eek: until I pointed this fact out to there security.