Back door into almost any Router??

Started by Westbranch, May 04, 2016, 03:59:19 PM

Previous topic - Next topic

Westbranch

I went into my ISP co. local office to talk about passwords and encryption  issue I am having at the lake with the android app by Graham ( that replaces/compliments the Local App...) 

A side bar discussion about "Are your usage amounts higher than you expect them to be?" lead to  "Have you updated the F/W on the router?" as hackers have discovered a back door into just about all the major brands of routers and they can use/steal your bandwidth time... without you noticing...till the bill comes in...

Anybody aware of this?

ADD: from reading the :

ASUS RT-N10P Firmware Version 3.0.0.4.378.6117
- Release Note -

Security fixes
- Enhanced the login authentication strength and fixed CSRF related issues.
- Forced administrator to change the default password "admin" in internet setup wizard.
- Added protection mechanism for GUI login brute-force attack for login username and password.
- Administrator can assign a specified IP to login GUI in Administration > System > "Allow only specified IP.


Bug fixes
- Fixed lease time and lease expires time
- Fixed ethernet connection fail in IPv6 when WAN hwaddr is cloned.
- Fixed allowed and blocked incoming icmp firewall rules.
- Fixed dnsmasq buffer overflow issue.
KID FW1811 560W >C&D 24V 900Ah AGM
CL150 29032 FW V.2126-NW2097-GP2133 175A E-Panel WBjr, 3Px4s 140W > 24V 900Ah AGM,
2 Cisco WRT54GL i/c DD-WRT Rtr, NetGr DS104Hub
Cotek ST1500 Inv  want a 24V  ROSIE Inverter
OmniCharge3024  Eu1/2/3000iGens
West Chilcotin 1680+W to come

ClassicCrazy

So sounds like  someone if they were in range could get into an old router that hasn't been updated - but I would think you would still be able to see their device connected on the router webpage that shows LAN and wireless devices - though true most people would never look at that stuff.

Larry
system 1
Classic 150 , 5s3p  Kyocera 135watt , 12s Soneil 2v 540amp lead crystal for 24v pack , Outback 3524 inverter
system 2
 5s 135w Kyocero , 3s3p 270w Kyocera  to Classic 150 ,   8s Kyocera 225w to Hawkes Bay Jakiper 48v 15kwh LiFePO4 , Outback VFX 3648 inverter
system 3
KID / Brat portable

TomW

Quote from: ClassicCrazy on May 05, 2016, 08:43:04 AM
I would think you would still be able to see their device connected on the router webpage that shows LAN and wireless devices - though true most people would never look at that stuff.

Larry

CC;

Curiously enough, even with 25 plus or minus devices on my internal network I recognize "foreign" MAC addresses.

Since I moved to town I could easily have access to a lot of networks because they use default passwords on the routers. I went on a drive with my laptop and strictly for research I opened up several routers by simply using a list and script to hammer the router with common  encryption keys.  And this is a tiny burg < 3K souls.

Lots of open networks you can join with no login needed plus the cafe, library, rec center all run open networks.

Just because it is "open" doesn't mean you can use it legally.  8)

I figure people are ambivalent about it

Just for fun here.

Tom
Do NOT mistake me for any kind of "expert".

( ͡° ͜ʖ ͡°)


24 Trina 310 watt modules, SMA SunnyBoy 7.7 KW Grid Tie inverter.

I thought that they were angels, but much to my surprise, We climbed aboard their starship and headed for the skies

Westbranch

if they were in range could get into an old router that hasn't been updated

Her comments were that this is pretty fresh and any router more than a couple of years old is vulnerable as well as off site hacks from afar...

Tom did you 'see ' any routers that did not broadcast their existence, That is a feature I always set, though it is not fool proof if you have a laptop < W7... our carpenter was out a while back and he had used the access last year, no changes except to his phone, upgrades, and he had a hell of a time connecting again, had to push the send button on the router so he could connect... his phone would not 'see' my router ID (name)
KID FW1811 560W >C&D 24V 900Ah AGM
CL150 29032 FW V.2126-NW2097-GP2133 175A E-Panel WBjr, 3Px4s 140W > 24V 900Ah AGM,
2 Cisco WRT54GL i/c DD-WRT Rtr, NetGr DS104Hub
Cotek ST1500 Inv  want a 24V  ROSIE Inverter
OmniCharge3024  Eu1/2/3000iGens
West Chilcotin 1680+W to come

TomW

WB;

Yeah, you should uncheck "Enable SSID Broadcast"  so the router is hidden. You usually need the name of the router to interact with it.

Here I have remote management disabled.

Its not easy keeping up with this interweb thingy..

Now off to email that Nigerian Prince my financial data so I can collect my fee for helping him transfer his cash out of the country.  :o

Tom
Do NOT mistake me for any kind of "expert".

( ͡° ͜ʖ ͡°)


24 Trina 310 watt modules, SMA SunnyBoy 7.7 KW Grid Tie inverter.

I thought that they were angels, but much to my surprise, We climbed aboard their starship and headed for the skies