Please log in with router's password
google.com
google.com
https://en.wikipedia.org/wiki/Shodan_(website) - deeper reading. I'm not affiliated.
---
It's also a super basic intro to proper google-fu (which you can google to find others' takes on how to become somewhat effective at, erm, googling). Back when I used to blog on Microsoft-related topics, it was common to construct extremely narrow queries to find exposed confidential documents in Skydrive accounts which we could then sift through to find bloggable material.
e.g site:[skydrive domain] filetype:.pptx "Microsoft Confidential" etc.
Or one which still works:
https://www.google.com/search?q="Microsoft+Confidential"+sit...
lmao I'm going to have some fun tonight.
Almost all of this would be by mistake, no different than misconfiguring an S3 bucket.
I remember spotting someone's URL to a Google Doc on their screen which their camera caught in their YouTube video. I manually typed it into my browser's URL bar and voila, I could read that document. Nothing juicy though.
IT turned on One Drive backups for their desktop image, without communicating to users.
A week later, there's a flurry of a few tens of thousand angrygrams about users storing sensitive documents in the cloud.
... by which they meant (in user terms) "having files on your Desktop."
this video is 9 years old now, but id wager the prevalence of pulbic scada and webcams et al is still pretty high.
Edit: I take it back. Looks like the hash is good enough. 47,000 results; the first three that responded are the same kind of routers. https://www.shodan.io/search?query=hash%3A-904286784
I always recommend to watch at least both Censys and Shodan.
site:.gov "for official use only" filetype:pptx
site:.gov "for official use only" filetype:pdf
-draftThese items being accessible externally via google dorking is just poor site administration.
Too many people leave the default password on internet connected devices.
Seriously, anything is better than the default password.
That being said, a ton of devices still use default credentials but we don't have any numbers on how many exactly.
https://www.shodan.io/search/facet?query=net%3A0%2F0&facet=p...
And we don't concentrate on a single type of device/ service (the article mentions SCADA). We identify everything from industrial control systems (1) to Minecraft servers (2). The news coverage makes it sound like we're skewed towards ICS, webcams or vulnerabilities but our focus is on providing a comprehensive view of what's connected to the Internet.
If you want to quickly check if your IP is exposing anything unexpected to the Internet simply visit:
If you see a 404 then nothing public was found. Note that this looks up information in the existing Shodan database - it doesn't launch a scan.
(1) Industrial control systems: https://www.shodan.io/search/report?query=tag%3Aics
(2) Minecraft servers: https://www.shodan.io/search?query=minecraft
so... did you fix it?
Forum posts aren't outside the realm of valid sources, so where exactly is the line drawn?
You could. The person themselves couldn't. (There are guidelines about the risk of bias from primary sources, which apply very much to someone talking about themselves or their own company, so you shouldn't just blindly copy what they say into Wikipedia, but you absolutely can use them as a source)
The moderator asked me for proof that I was who I was, so I had to spend a couple days digging through my files to find my medical school diploma, board-certification document, medical licenses, etc., then scan and email them to reddit.
I did all that, and they said it wasn't sufficient proof: I needed to take a selfie with the documents and my driver's license to "prove" my bona fides.
At that point I said WTF? and bagged it.
No good deed goes unpunished.
That said, as far as where the line is drawn for sources see https://en.wikipedia.org/wiki/Wikipedia:Reliable_sources i dont think forum posts are usually considered the best sources.
But, of course, none of those posts specifically targeted their Wikipedia articles.
But do you discard the IP or save it for future scans? :p
I believe all IPV4 addresses. Skeptical on IPV6. Though the ntp pool thing was clever.
ssh -D9999 yourserver
then set up the SOCKS proxy in your browser's settings
But it doesn't seem to work, unfortunately.
Thank you!
Narrator: All was ok.
Here's the user manual for the TP-Link AC2300 "Archer C7", as found in the google results:
https://static.tp-link.com/2019/201912/20191231/7106508598_A...
Step 2 of first time setup forces a default password change. There is no way around this step.
The defaults for the router also do not allow router access from the WAN port.
This means:
1) These routers all have secured passwords that are non-default.
2) These routers were deliberately placed on the internet by people that knew enough about them to do so.
Just because it's not how you would configure your router doesn't make it wrong. There are legit reasons to place a router on the internet, so long as it's secured properly... how else would you remotely manage a router at a different physical location, for instance.
__Lastly__ click "Next Page" on the OP search results. The estimated 7,000+ results becomes 21. Many of which are HN aggregators reporting on this thread here.
So... out of the possible millions of routers TP-Link has sold in this model line, less than 21 are on the public internet - many of which no longer load via IP address (indicating they are no longer publicly accessible), and the rest have professional CNAME's attached, indicating professional management.
Nothing here...
> 2) These routers were deliberately placed on the internet by people that knew enough about them to do so.
That's making some very generous assumptions.
Again, just because you wouldn't configure it this way doesn't make it wrong. It's as secure as it can be, short of throwing a bunch of other kit in front of it, and then why would you be using a $100 consumer router anyway?
The only vulnerability here is the possibility of a 0-Day. Everything else is either misguided or screaming for the sake of it.
That's not exactly uncommon in cheap consumer routers.
No rate limiting is as good as no authentication.
That's, in my opinion, the only fair criticism available here.
> No rate limiting is as good as no authentication.
Trying to even load some of the links found in Google takes 10's of seconds. That's effectively a rate limit, even if it doesn't temp-ban per IP address.
Someone would have to dump the firmware to find out, but it would be trivial for each device to generate their own salt - making a potential lack of rate limit a non-issue.
Latency is not rate-limiting.
Salting does nothing to protect against bruteforce attacks, which are what rate limiting defends against. Salting is done to protect passwords in the event the password data is stolen.
I kind of agree with the comment that started this thread -- people that have explicitly decided to expose their consumer-grade routers directly to the Internet probably know about password managers. Even if you do guess the password and compromise the router, all you'll have is some remote office that is getting TLS errors because of your MITM, and best case control of some unpatched Windows 3.1 machine and maybe some developer's local MySQL install happily listening on port 3306 somewhere. That's not great, but it's a risk that some people are willing to take.
And usually with default password because not on the internet. People often forget or underestimate lateral movement and metasploit reverse shell kits.
You do realize that the last security update for these routers was in 2019, right? So by zero day, you mean something more like 700 day? Yeah, no way anyone could've discovered a system takeover in the last 2 years, when up against the security prowess of... TPLink?
I think it might be a good idea to edit your original comment, you'll save some face.
Disagree. In my current country of living, I'm not even sure how I'd properly expose the router I use to the public internet since I sit behind the ISP's NAT-ing, and even when I lived in the US, I am not confident I could tell you how to publicly expose the modem provided by Comcast for non-local access, much less how someone without any tech experience might do this.
If this was a prevalent problem because of default settings, I'd expect far more than 7800 results; I am not willing to concede every instance is intentional, but 7800 out of the billions of routing devices in the world showing up on this search enforces my understanding that these 7800 entries are special in some way.
>I doubt there's MFA or even rate limiting.
MFA is not common at all on consumer routers, which at least quite a few on the first page result are, same with rate limiting.
Even for Enterprise grade gear, the threat isn't the user-defined password, it's the manufacturer backdoors, which we've seen many of in the last few years. Rate limiting doesn't do much if you have a fair chance that you've got a back door.
What likely __does__ help is that as far as I know, "Enable Web Access from WAN" is by default *disabled* on most consumer routers (and enterprise? that I'm not sure of), so I think that this leads credence to the devices on the Google results being exposed intentionally to some degree. (The owners' knowledge level not withstanding, this is a fairly out of the way setting, at least on my Asus router)
Click "Next Page" - estimated results turns into 21 results in total... of which a bunch are dead links, a bunch are HN aggregators... leaving just a small handful of actual devices on the internet.
You likely couldn't. That setting is usually gated behind some sort of "technician" or "mso" account (or not present, or only accessible from the devices telnet/ssh interface). Of course, it's probably not difficult to guess Comcast's password; past experience with other companies suggests you try things like "comcast" or "C0mc4s7". (Not even joking, Suddenlink and Spectrum/TWC.)
> much less how someone without any tech experience might do this.
Easy. It's a button that their kid clicked while playing around.
> MFA is not common at all on consumer routers, which at least quite a few on the first page result are, same with rate limiting.
Are you trying to say that's a positive for exposing it on the internet...?
If experience is any guide, they are not.
Consumer routers have horrible track of embarrassing, easily exploitable vulnerabilities. That are not patched for a long time or ever.
And exposing your router to public like that suggests the owner knows very little about security. This typically goes in hand with other neglect. Tell me, how many home users that are not security conscious keep their routers regularly patched and will replace the router when the manufacturer stops supporting them?
UPnP is on by default, yeah
I personally run Ubiquiti Unifi gear, but they're not exactly consumer friendly (more geared to power users).
All of the competition either requires intimate knowledge of networking internals, is twice as expensive or both.
Once you log in it appears to be running a version of OpenWRT, although they don't specify that on their website.
When the EdgeRouter-4 I have dies, I suspect I'm going to need to find a new hardware brand, this time preferably running OpenWRT. Potentially it could get to the point where I'll have to look for an ARM based server with low enough power usage and a few independent network interfaces and just run pfSense or VyOS or something...
However, it's likely that your ER-4 will far outlast the majority of devices you can find running OpenWRT. They're very well built units.
I expect I will eventually move to embedded server hardware (even maybe Xeon-D) on a machine running vSphere or something with a router VM and other VMs for stuff I want to run. Just have a few separate NICs and pair it with a separate managed switch (which I already have anyway).
I don't.
Is it too much to ask to have competently built hardware with competent software for a reasonable price enabled by mass production?
I mean, just don't make stupid things like open access to it from a single point of failure where a single engineer can loose their AWS key and enable attackers to access million networks?
Or build devices that overheat placed on an open shelf in home office in truly unreasonably hot Polish climate?
I can sympathize with people that don't have technical background -- these are practically defenseless.
I'm willing to invest time once to get something better working. I'm not willing to invest time on an on-going basis to keep my router secure. My normal router is a !@#$%, but the company does push out security updates.
Most of the DIY projects I've seen require me to do it manually.
many tp-link routers also have configurable vpn servers built in, which can open up the whole network to malicious actors.
Exposing your router's admin page to the internet is not good security practice. These routers are protected by nothing but a password, and I couldn't see anything in the manual that enforces password length/complexity. So while the password might be non-default, it could still be incredibly insecure.
Also, to expose these routers to the internet, all it takes is a single checkbox to enable "Remote management". So your assumption that these have all been deliberately placed on the internet also doesn't hold up because I can definitely see a curious home user playing with these settings without realising the impact of this. There have been tons of similar reports in the past where home users have exposed things to the internet without realising the impact.
Secure passwords is just a tiny subset of non-default passwords. Chances of an average human being being able to come up with a password with enough entropy to be called as secure is pretty low.
> These routers were deliberately placed on the internet by people that knew enough about them to do so.
This means these people knows how to expose the management interface to the internet. It does not mean these people have enough knowledge on securing their devices -- based on their actions, it is more likely that the opposite is true.
So you think the chance of human beings to come up with 4 random words is pretty low?
You can't brute force millions of guesses per second through a web interface. 40 bits of entropy is already plenty for internet usage especially when the password is properly hashed with something like bcrypt.
> Secure passwords is just a tiny subset of non-default passwords
Actually the exact opposite is true. Since only low entropy and publicly known (which are mostly low entropy) passwords are insecure there are much more secure than non secure passwords.
For the sake of argument, let's say all passwords with less than 40 bits of entropy are insecure. Even if we restrict the set of possible passwords to only 10 characters of lowercase a-z we have about 47 bits of entropy. So the set of insecure passwords would only be about 1/128 or less than 1% of all allowed passwords.
I've always wondered how effective the random words thing is. sure, there are like 100k english words in current use according to google, but it seems like a list of the most common few hundred of those words would crack a lot of passwords.
30 bits of entropy isn't particularly secure against locally cracking a password hashed with sha256 or a similar non password hash. However at 1000 guesses per second it would already take 28 days to brute-force and 1000 guesses per second is pretty fast against any password stored with a properly configured password hash like bcrypt.
I personally auto-generate readable passwords for most websites at ~70 entropy pure brute-force and ~50 entropy if my algorithm and set of inputs would be exposed.
> Actually the exact opposite is true. Since only low entropy and publicly known (which are mostly low entropy) passwords are insecure there are much more secure than non secure passwords.
You're confusing "passwords that are in use" with the set "passwords that are possible". We have data via password dumps that suggests of the "passwords that are in use" the set that qualifies as "secure" is indeed a tiny subset of passwords.
Anyway, the point is, people are terrible at generating (and remembering) secure passwords. By ruling out the default password just means it is not going to be the most insecure one, but the chances of the custom password being secure is still pretty low.
I would love for more websites to implement something like the zxcvbn password strength meter [1], but unfortunately I keep seeing new services or recently refreshed ones using outdated and hurtful policies like requiring numbers and special characters.
> The estimated 7,000+ results becomes 21. Many of which are HN aggregators reporting on this thread here.
Nope, Google is just collapsing them because they are all identical copies of the same "page", being the same login screen. Most of them look like routers, you can ask Google to "include" them all and see for yourself. https://www.google.com/search?q=%22Please+log+in+with+router...
Make that 47,000 of them on Shodan: https://www.shodan.io/search?query=hash%3A-904286784
> 1) These routers all have secured passwords that are non-default.
You have a very interesting definition of "secured" if you think they are all actually secured.
> 2) These routers were deliberately placed on the internet by people that knew enough about them to do so.
Just because they knew enough to click a checkbox doesn't mean they knew enough to do so. If they knew enough, they wouldn't have done so.
You seem to be under the mistaken impression that embedded devices (like consumer routers) don't usually have glaring security holes. But they do.
Aside from the anecdata, a counter argument is that the router manufacturer has taken no steps to obscure the routers from search engines. Sure someone could simply IP scan, but you have to admit this is a little absurd.
Who said secure password? Yes, they are not the default, but people are terrible at choosing password, most will choose weak password that are easy to exploit with a dictionary attack.
> 2) These routers were deliberately placed on the internet by people that knew enough about them to do so.
A people that know what it's doing would never expose a router web interface on the internet. Most people doesn't know how to configure his router, and let the ISP technician configure it, and they probably expose the router interface so they can access it remotely for maintenance, but it's not a great idea...
> There are legit reasons to place a router on the internet, so long as it's secured properly...
There aren't. Also you can choose a secure password, but these router interfaces are full of bugs, and highly exploitable. Add to this the fact that the manufacturer rarely updates the firmware of these devices...
> how else would you remotely manage a router at a different physical location, for instance.
With a VPN? By creating an SSH tunnel to one machine inside the local network? By connecting remotely (via RDP, VNC, TeamViewr, whatever) to one PC inside the local network? There are a ton of better solutions.
Also if you don't have a static public IP address, as it's in most situations nowadays, how do you access it remotely anyway? With dynamic DNS but it's not reliable. The best solution to me is using a VPN (I can connect to my home network from anywhere in the world and access all the hosts, including router and other networking equipment of course).
Owner of a C7 v4 here. There has not been a firmware update from TP-Link since December 2019 (note that v4 is the second-most recent HW revision). No way these are not affected by at least some CVE somewhere in their stack. Calling them secure is a leap of faith that TP-Link does not deserve.
I recently flashed openwrt exactly to be able to be on a more recent stack.
I would never dream exposing that UI to the Internet as-is. They don't even have any form of brute forcing protection. If they really needed access to the router remotely, it would be much saner to expose an SSH server with pubkey-only access or VPN, both with brute forcing protection, and allow tunnelling to the router UI only from the LAN side.
Either who set those up really has nothing to lose if they get owned, or they do not know what they are doing. In both cases, it does not qualify as being a secure setup. (Sure, they may also be honeypots - in which case your argument was incorrect anyway, as they are secure, but they are not routers)
any chance you can explain that to my mum?
It would be safer to leave open to the public only a secure protocol based on strong cryptographic keys instead of a password. Or you have to be signed in to a VPN to see the page.
> brute forcing protection
Try too many passwords? Try again in 1 minute. Again? 30 minutes
> allow tunnelling to the router UI only from the LAN side
I think this one means don't expose it to the internet at all. Just from your local network. >
Although not specified to TP-Link, There are many exploits on other brands that can bypass the Authentication. For example this one:
https://medium.com/tenable-techblog/bypassing-authentication...
Even allowing access the web server from internet could be dangerous.
If "placing it on the internet" was proof of excellent security knowledge & practices, then nothing on the internet would be insecure.
Just because they knew enough to know how to place it on the internet doesn't mean they understood the implications of that decision.
It’s fine to expose router configuration (although it’s not ideal), but if you know that you are doing, you’ll at least place it behind a VPN.
Most routers are perfectly fine with a limited set of knobs accessible to the public Internet behind reasonably secure access ports. Bastion it behind SSH and/or SOCKS if you're paranoid, but seriously, as long as we're not talking a $50 Target 'router', it's probably fine. My Ubiquiti gear is indexed. It also reliably e-mails me when it successfully authenticates a user and can distinguish between inside and outside access to ACL what it can do.
Just saying, easy with the "if you know what you're doing" thing, because opinions differ (particularly with beyondcorp in an IT setting). Gluing a VPN back together through an SSH tunnel so you can get at the "fail over to my DSL connection" button inside your network is a really crappy deal at 3 a.m. with a few beers in you and 200ms in between.
Maybe it’s just a matter of difference of criteria, but I would certainly not be fine with this. You have a lot of ways to prevent this from happening, and it only opens an attack surface to APTs.
Being indexed means being searchable, being searchable means exposing yourself to automated targeted attacks.
Edit: Yes, it was not.
https://freshairarchive.org/segments/google-founders-larry-p...
https://genius.com/Jonathan-coulton-dance-soterios-johnson-d...
Plenty of websites allow you to do it, although it's probably safer to grab a shell on any other host connected to the internet (could be even just your phone connected to its mobile network) and run a port scan (e.g. nmap) from there.
Since the default configuration of these routers is not to expose the router on the WAN interface, manually overriding this configuration usually demonstrates a sufficient enough understanding that the default credentials have likely also been changed.
The only real issue would be using a default password, which none of the top results shown on Google seem to have (thankfully). So, little-to-no issue here.
I don't think that's a reasonable assumption at all -- the router should ensure that the admin cred has been set to a (reasonably secure) password. Just because someone read on a web page that they should enable remote admin doesn't mean that they understand the risk.
And it should warn that exposing the admin interface to the internet may make the router more vulnerable to remote exploits - basically the same type warning that browsers show for a bad SSL cert should be shown for insecure router configs - tell the user that it's insecure and is a really bad idea before they do it.
You're making some wild assumptions here.
Even your basic free Comcast router comes with sane defaults, and tons of warnings for every configuration change.
Here's the user manual for the TP-Link AC2300 - The Archer C7 found in the google results this post links to:
https://static.tp-link.com/2019/201912/20191231/7106508598_A...
Step 2 forces the default password to be changed. There is no way around that step.
None of your assumptions are true here.
https://www.tp-link.com/us/support/faq/66/
1. Open the web browser and in the address bar type in: http://192.168.1.1
2. Type the username and password in the login page. They are both admin by default.
3. Click Security->Remote Management on the left side
4. To enable this function, please change the Remote Management IP address from 0.0.0.0 to a specific authorized remote IP address.
Here's the warning they give at the bottom of the manual:
Few people read the entire manual, if they read it at all, they read enough to do what they want, and fewer still know what "Use this with caution" means. I don't even know what it means. I typed 255.255.255.255 carefully, is that sufficient caution?
Type 255.255.255.255 Remote Management IP Address means that you can connect to the router remotely from anywhere via Internet, this is not recommended and please use it with caution
We suggest changing the default log in Username and Password if the Remote Management feature is enabled, especially if you typed 255.255.255.255 as the Remote Management IP address.
And, your link is old, to say the least. That screenshot is from the Windows XP era.
You're trying to lampoon TP-Link for things that simply are not true anymore, nor have been for a long while.
I'll repeat again - the defaults on these routers is to prohibit WAN access and they force a password change at setup. What more are you complaining about?
Updated 04-18-2019 07:10:55 AM
This Article Applies to: TL-WR841N (and a couple dozen others).
You can buy a TL-WR841N today for $20. It was released in 2015, so it may be an "old" router, but old routers never die, they just get cheaper.
But regardless, I was responding specifically to your comment:
manually overriding this configuration usually demonstrates a sufficient enough understanding that the default credentials have likely also been changed
(That's why I quoted it in my reply)
And the point I was trying to make is that merely being able to override the default remote admin setting does not ensure that the user has any idea what the ramifications are. I'm surprised you're even arguing against that.
It does, click any of the links. The specific search string OP used returns only C6, C7 and C9 routers (I clicked through 2 pages of results).
You saw TP-Link and went off about things that were valid to complain about in the past... but are not specifically with these routers, and probably no new model TP-Link or any sane manufacturer is turning out today.
> And the point I was trying to make is that merely being able to override the default remote admin setting does not ensure that the user has any idea what the ramifications are
Again, if you actually clicked through the OP, you'd notice most of the bare IP address results are dead (meaning they are no longer on the internet), and the ones with CNAME's attached appear to be professionally managed. The assumption is sound.
"Please log in with router's password" -"hacker news" -C6 -C7 -C9 -C90 -C60 -A9 -A7 -A6 -AX3000 -MR100 -MR150 -MR200 -MR600 -MR6400 -AC2300 -AC2600 -AX50 -C6U -VR300 -VR600 -VR2100 -TD-W9970 -TD-W9960
Sure, and you can change that password to "foobar" or whatever bad password you want. And I bet that login page doesn't have any rate limiting or a lockout after too many failed logins.
Fortunately, though, I don't think there are any of these that enable remote admin by default, so the owner would need to do that explicitly. Hopefully they've paired that with a strong password. Even then, I still wouldn't advise anyone actually doing this...
(Your manual link is broken; it takes me to a page that just links to TP-Links main marketing website.)
No, there are not.
> How else would one remotely manage a router
Over a WireGuard connection to a secure management network.
> The only real issue would be using a default password
Uh, no. Try any number of CVEs or 0-days or unknown-until-it's too-late vulnerabilities, depending on what web daemon/frameworks are used by the router's management software.
The businesses and universities you see in the list are likely:
* a result of people hooking up rouge devices
* organizations operating without competent IT management
* honeypots
Given what it is... it's as secure as it can be. Short of a 0-Day lurking somewhere, or an active CVE, the configuration is fine. Not to mention all the top results appear to be operated by organizations that certainly know what they are doing.
https://www.tp-link.com/us/user-guides/Archer-C7/chapter-12-...
Although, remote management isn't much of a consumer feature to begin with.
If they are, great. If not, then consumer-grade router admin interfaces should not be exposed to the public internet, ever.
- spend 100 bucks on a specific router
- have a static IP
- put your router web ui on the Internet
then yeah, you are definitely the type who should be also able to put a VPN to properly manage it. I don't really get your defense of this practice. It is bad and risky, and there are no good reasons to expect it to be a sane config for a router.
As opposed to actually solving that problem? I mean, if GMail, Jira, GitHub and GitLab all manage to provide secure web UIs, then what's the excuse of routers?
Why should the manufacturers just offload the technical complexity to the end user, as opposed to supporting something like 2FA through TOTP or an equivalent? Sure, that's not to say that any piece of software doesn't need extensive security testing, but at the very least they should attempt to establish a perimeter of sorts for their web application and use whatever popular auth mechanisms have been widely used in the industry in the last 5 years.
As for the eventual "routers don't receive updates" counterpoint: if my Debian boxes can receive unattended security updates, what makes it so that my router couldn't? If lots of self-hosted software like GitLab is relatively secure, what's to prevent routers from receiving a similar treatment and attention?
Personally, i'm just writing this to bring the odd juxtaposition to light - that things we oftentimes take for granted in regards to typical web apps are somehow not only not often implemented but also are unthinkable for some reason when it comes to devices like routers. I don't believe that this is a good thing and some sort of a convergence should happen sooner or later - GNU/Linux or BSD based router software that all of the vendors could adopt and, ideally, an open source web UI alongside mechanisms to keep it up to date automatically.
Of course, for some odd business reasons, that's unlikely to happen. Looking at the current state of routers, i find it extremely odd that every vendor has their own piece of software that's so different from the others out there, even down to many of the terms that are used to configure the operation modes etc. Yet, when we want to purchase a personal computer, we don't buy one with DellOS or HP-OS or what have you...
> The only real issue would be using a default password, which none of the top results shown on Google seem to have (thankfully). So, little-to-no issue here.
You might want to think twice about attempting to log in to a system you weren't authorized to use. That's illegal in most jurisdictions.
Some years ago I wrote a little tool to iterate all of an ISP's ip addresses and around 90% were using default passwords. Mostly homes, but some businesses.
If you want something very general and comprehensive, you can read this, although it is probably too involved for a basic "website": https://owasp.org/www-project-web-security-testing-guide/sta...
https://skylar.tech/create-fast-websites-from-your-home-netw...
I've selfhosted on 64Kbit/s modem then xDSL for years without a problem (apart from bots trying default passwords). If you are really afraid you'll run into DDOS attacks and whatnot, consider using a small 2-5$/mo VPS as reverse-proxy instead of CloudFlare to retain control of your infrastructure.
Since you're not hosting the site on the router itself, presumably you're forwarding port 80 from the router to the Raspberry Pi, so unless the security of the Pi ends up being broken, the router should be safe.
(Also I'd recommend using Let's Encrypt to get an automatically-renewing TLS cert so you can serve https on port 443 as well, and even redirect port 80 to it. It's not that difficult to set up, and you'll be improving the privacy and security of those who visit your site.)
ISP router (with disabled wlan) <-> firewall <- home router (with wlan)
and the firewall can then separate the network by port. WAN for the firewall is the LAN Port of my ISP router.
Is that a good setup?
See if ngrok can do what you want to do
Skip past the first few results, then you'll see a list of likely easily-hackable home routers. If you were to try user/pass combos like "admin"/"admin" on these results I bet you'd have successful logins on several of them.
Don't actually do this (seriously, the penalties aren't light), the demonstration of the search results is enough to make the point.
https://duckduckgo.com/?q=%22Please+log+in+with+router%27s+p...
disallow allBrb going through all software I ever wrote looking whether they could benefit from this too.
[0] https://www.google.com/search?q=%22Type+in+Username+and+Pass...
[1] https://www.google.com/search?q=intitle%3A%22Outlook+web+app...
Or just generally cause havoc "for the fun of it", which seems to be a not uncommon motive for some people.
This would be even easier if-- because a person putting their router on the internet might not understand good security practices-- they might also be more likely to do things like punch holes through NAT without understanding the risks and proper precautions.
Even without the user misusing NAT, a router will often give a list of connected devices, internal IP, and other details. An attacker with admin access to the router can easily punch their own holes through NAT to any of those devices, run port scans, and find vulnerabilities to exploit.
All the outrage in this thread over nothing...
They could all be receiving hugs of death from the HN traffic.
>In order to show you the most relevant results, we have omitted some entries very similar to the 22 already displayed. If you like, you can repeat the search with the omitted results included.
I (un)fortunately can't remember the certain query needed, but it's not too hard to find it — I'm sure it's been mentioned on various news articles or YouTube videos. If I remember, it relied on the cameras all sharing the same filename for the PHP page to access the interface.
These routers are very well designed, receive regular firmware updates and are overall very solid. The only router that I haven't had to reboot since I've owned it (for nearly 18 months now). Had no random configuration resets, interface bugs, WiFi drop-outs, QoS issues ... just, solid.
So seeing that people have exposed it to the internet - sure, that's not recommended. But I don't think that it is something to be overly concerned about. It doesn't feel like your normal internet of crap router.
And as others have said, this is not the default setting, and you're actually warned when you try and enable external access. But for some, this is useful. Since this router supports a VPN server, external access could be the only way to troubleshoot it if you're not on-site.
Of course, nothing is unhackable. If a state actor wants to get inside your router, you'll lose no matter what. And you don't need to have https:// exposed on WAN to get hacked in that way. The 0-day could just as easily be on the transceiver or on the WAN layer itself.
The only way to protect yourself from a 0-day is to live in a tin foil bubble and simply never use a mobile phone or the internet.
I really don't think that's the case for router manufacturers.
> The only way to protect yourself from a 0-day is to live in a tin foil bubble and simply never use a mobile phone or the internet.
Or have fewer attack surfaces. Like notoriously buggy routers.
They're a (consumer) router manufacturer. I don't care how good they are within that field, no, their track record is NOT quality. Worse yet, 90% of their code comes from the same vendors as every other router manufacturer.
> you can extrapolate that their process is pretty good at dealing with security problems as well.
That is a complete non sequitur; plenty of businesses have made useable, functional (widely-used!) software but had a head-in-the-sand approach to security.
> Of course, nothing is unhackable.
Exactly, which is why only things which must be exposed to the public should be exposed to the public.
The rest of your argument is assuming the attack surface is the same whether remote management is on or off; or that the amount of attack surface doesn't matter. Either way is simply not correct. By the way, an issue in the "transceiver" would require physical proximity. I'm not sure what the "WAN layer" is, but if you mean like... the Ethernet port and interface, that would require physical access.
If the remote management was off, you would likely be targeting nothing more than the units IP/TCP, UDP, whatever stack. With the remote management ON, you could target that, you could target the HTTP server, or you could target the admin panel running on it. Each of those are much more likely to have security holes for several reasons, but moreover there's simply no reason for them to be accessible publicly, while the routing and NAT functions are necessary to the purpose of the device.
Archer C7 v4's last firmware update, Dec 2019. Archer C7 v5's last firmware update, Jan 2021.
Might be solid, but I guess "regular" is relative.
Routers should be secure by default, and it should be hard to do something that will make it insecure. The router manufacturers are the supposed experts when it comes to networking, expecting every consumer to even know the risks of exposing their router admin interface to the world is not a reasonable assumption.
They should limit vehicle speed to 5mph so I don't hurt myself or others.
I have used many of these routers. Admin access on the wan port is blocked by default and must be enabled by the user.
Of course, both with the car and the router there are good arguments that you should be able to do the dumb thing if you know you need it. If it has to be explicitly enabled after intense warnings, the protective duty (as someone knowing better) can possibly be considered fulfilled - or you can still argue that it should be especially hard to do to block out people who don’t listen to warnings.
These routers were put on the internet on purpose, by people that seem to know what they are doing (universities and businesses), and none seem to have default credentials. Seems reasonable to me.
I have never seen a router that had its admin page visible to the WAN by default.
I'd wager there's a non-zero percentage of routers which have the modem (or ISP router) plugged into a LAN port.