Donate to Remove ads

Got a credit card? use our Credit Card & Finance Calculators

Thanks to Rhyd6,eyeball08,Wondergirly,bofh,johnstevens77, for Donating to support the site

Seriously Weird

Seek assistance with all types of tech. - computer, phone, TV, heating controls etc.
XFool
The full Lemon
Posts: 12636
Joined: November 8th, 2016, 7:21 pm
Been thanked: 2608 times

Seriously Weird

#217909

Postby XFool » April 28th, 2019, 1:05 pm

Advice please.

This is a very peculiar situation, with a long, long technical runup and background which I won't bore you with. The sudden unexpected entirely innocent outcome is:

1. I seem possibly to have accidentally and inadvertently stumbled upon a simple way of breaking into unsecured routers (devices?) on the Internet.

2. I appear (on the face of it) to quite accidentally have admin access to a router in a company in Israel.


WRT 2. I don't know why, but this router seems entirely wide open in every respect. To me this seems suspicious enough in its own right.

What is going on? What would be best to do next? (serious answers please)

TIA

Infrasonic
Lemon Quarter
Posts: 4487
Joined: November 4th, 2016, 2:25 pm
Has thanked: 648 times
Been thanked: 1264 times

Re: Seriously Weird

#217916

Postby Infrasonic » April 28th, 2019, 1:24 pm

There are quite a lot of cybersecurity security companies in Israel, maybe this 'wide open router' is a nice little honey trap waiting for a nibble?
It's a common MO to find out information on hackers digital fingerprints, plenty of servers out there with similar 'weaknesses' that are intentionally allowed to be infected with bots and other malware so it can be reverse engineered.

It could also be a malicious actor hoping to access or compromise your end with captured info...

Proceed with caution... :twisted:

XFool
The full Lemon
Posts: 12636
Joined: November 8th, 2016, 7:21 pm
Been thanked: 2608 times

Re: Seriously Weird

#217918

Postby XFool » April 28th, 2019, 1:27 pm

...as the router is so wide open, the above thoughts have already crossed my mind.

More hopefully, as there is research into security issues in universities in Israel (I think), I wondered about it being part of a research project.

ReformedCharacter
Lemon Quarter
Posts: 3140
Joined: November 4th, 2016, 11:12 am
Has thanked: 3640 times
Been thanked: 1521 times

Re: Seriously Weird

#217922

Postby ReformedCharacter » April 28th, 2019, 1:53 pm

XFool wrote:Advice please.

This is a very peculiar situation, with a long, long technical runup and background which I won't bore you with. The sudden unexpected entirely innocent outcome is:

1. I seem possibly to have accidentally and inadvertently stumbled upon a simple way of breaking into unsecured routers (devices?) on the Internet.

2. I appear (on the face of it) to quite accidentally have admin access to a router in a company in Israel.


WRT 2. I don't know why, but this router seems entirely wide open in every respect. To me this seems suspicious enough in its own right.

What is going on? What would be best to do next? (serious answers please)

TIA


It might be interesting and perhaps informative to 'do the honest thing' and inform the sys admin and see what sort of response you get.

RC

XFool
The full Lemon
Posts: 12636
Joined: November 8th, 2016, 7:21 pm
Been thanked: 2608 times

Re: Seriously Weird

#217955

Postby XFool » April 28th, 2019, 4:02 pm

ReformedCharacter wrote:It might be interesting and perhaps informative to 'do the honest thing' and inform the sys admin and see what sort of response you get.

That would be my intention. However the question is: Who & how?

Obliquely, this has (possibly) come to notice: https://infowarcon.com

And this: https://www.milcyber.org

[It is at this point, based on some previous experience, I am starting to have the feeling some on TMF may start posting that I am 'merely trolling']

XFool
The full Lemon
Posts: 12636
Joined: November 8th, 2016, 7:21 pm
Been thanked: 2608 times

Re: Seriously Weird

#217964

Postby XFool » April 28th, 2019, 4:24 pm

It's crossed my mind that the router's admin account might possibly be a pseudo-admin account. That is, it appears to be an admin account by name, but actually isn't - because the admin user name is not AFAIK the default admin name for this type of router, though closely related.

As the only way of finding out if it IS a genuine admin account is to carry out an actual admin action on the router which, if it was successful, could presumably constitute illegal hacking, I am obviously disinclined to do so...

At this point perhaps the simplest thing is to 'get me coat' and just forget about the whole matter. Anyway, to get back to a matter related to the original issue:

Anyone know of any really, really reliable DNS servers?

scotia
Lemon Quarter
Posts: 3566
Joined: November 4th, 2016, 8:43 pm
Has thanked: 2376 times
Been thanked: 1947 times

Re: Seriously Weird

#217968

Postby scotia » April 28th, 2019, 4:51 pm

Many years ago, when I was teaching a postgraduate course on computer communications, I organised a lab session on SNMP (Simple Network Management Protocol), and I told my class that many devices on the internet were wide open to this protocol. I encouraged them to explore around the University, and some adventurous souls extended their search to another University where the alarm bells rang, and there was a pointed discussion between the two Universities' Computer Services at a high level. The outcome was a severe restriction placed on the router to which my lab was connected!
So it is possible that the router you have investigated may be obtaining more info about you than you would about it! Be careful. And how did you find out about this router? Its unusual for any conventional Web user to be employing tools that would discover this router. I suspect your investigations, no matter how innocent you believe them to be, may have aroused the interest of others - even possibly certain government organisations

Slarti
Lemon Quarter
Posts: 2941
Joined: November 4th, 2016, 3:46 pm
Has thanked: 640 times
Been thanked: 496 times

Re: Seriously Weird

#217969

Postby Slarti » April 28th, 2019, 4:52 pm

If you're able to access the router you must have the address of it?

Do a Who Is on the address and see who owns the domain and contact them?

Slarti

XFool
The full Lemon
Posts: 12636
Joined: November 8th, 2016, 7:21 pm
Been thanked: 2608 times

Re: Seriously Weird

#218039

Postby XFool » April 28th, 2019, 11:36 pm

But there are oodles of these things all over the Internet. Essentially a wireless router for business use, the equivalent of a domestic wireless router.

Why are they everywhere, wide open, walk right in? (Apparently)

Either I'm seriously missing something, or somebody else is.

kyu66
2 Lemon pips
Posts: 249
Joined: November 14th, 2016, 5:14 pm
Has thanked: 2 times
Been thanked: 132 times

Re: Seriously Weird

#218066

Postby kyu66 » April 29th, 2019, 8:56 am

XFool wrote:But there are oodles of these things all over the Internet. Essentially a wireless router for business use, the equivalent of a domestic wireless router.

Why are they everywhere, wide open, walk right in? (Apparently)

Either I'm seriously missing something, or somebody else is.


The internet is full of open/accessible devices, through either ineptitude, mis-configuration or design (e.g. honey pots).

Have you checked the device's status using shodan.io https://en.wikipedia.org/wiki/Shodan_(website), it may provide more details.

XFool
The full Lemon
Posts: 12636
Joined: November 8th, 2016, 7:21 pm
Been thanked: 2608 times

Re: Seriously Weird

#218102

Postby XFool » April 29th, 2019, 10:30 am

To sum up:

1. Things Are As They Appear To Be

This is the simplest explanation. It means there really are loads of routers etc. on the Internet with ZERO security in place.

Normally home routers are supplied by ISPs, who set them up before dispatch. It appears that commercial routers directly supplied to companies may, as their default settings, have no security in place. The suppliers presumably expecting they will be correctly set up and looked after by knowlegeable technical staff. Obviously, this if frequently not the case.

I can only think devices are set up by non technical people. Or the 'convenience' of having an easily accessible open router interface on a private network in a trusted environment completely overlooks, through ignorance, that that private side router access is the same interface on the other, public WAN side and so is visible to everyone in the world!


2. Things Are Not As They Appear To Be

In which case, who knows?


Obviously all this must be well enough known in circles where it is already well known. It's just a bit of a shock accidentally stumbling upon it for oneself.

Well it has been, as the saying goes: "A learning experience."

Slarti
Lemon Quarter
Posts: 2941
Joined: November 4th, 2016, 3:46 pm
Has thanked: 640 times
Been thanked: 496 times

Re: Seriously Weird

#218111

Postby Slarti » April 29th, 2019, 11:12 am

XFool wrote:But there are oodles of these things all over the Internet. Essentially a wireless router for business use, the equivalent of a domestic wireless router.

Why are they everywhere, wide open, walk right in? (Apparently)

Either I'm seriously missing something, or somebody else is.


ISP supplied routers with no admin password are horribly common and even if you apply a password to what you think is the admin account the ISP will often have a super admin account where they can apply updates to the router and remove your admin password. Been there, eventually worked that out and never used an ISP supplied router since.

Slarti

swill453
Lemon Half
Posts: 7986
Joined: November 4th, 2016, 6:11 pm
Has thanked: 987 times
Been thanked: 3658 times

Re: Seriously Weird

#218120

Postby swill453 » April 29th, 2019, 11:32 am

XFool wrote:I can only think devices are set up by non technical people. Or the 'convenience' of having an easily accessible open router interface on a private network in a trusted environment completely overlooks, through ignorance, that that private side router access is the same interface on the other, public WAN side and so is visible to everyone in the world!

I would have thought the majority of routers and other network equipment in the commercial environment are entirely within their private networks and inaccessible from the Internet ie they simply don't have a "public" side. Any large company I've worked for has only had a very few well defined and well protected interfaces between the internal network and the Internet at large.

Of course that's not to say it's impossible that some companies will expose an insecure interface to the Internet. And it's also not to say that having an unsecured router within a private network is a good thing anyway.

Scott.

Slarti
Lemon Quarter
Posts: 2941
Joined: November 4th, 2016, 3:46 pm
Has thanked: 640 times
Been thanked: 496 times

Re: Seriously Weird

#218132

Postby Slarti » April 29th, 2019, 12:29 pm

Also things like the BT access points. I'm sure other companies do the same.

Slarti

Infrasonic
Lemon Quarter
Posts: 4487
Joined: November 4th, 2016, 2:25 pm
Has thanked: 648 times
Been thanked: 1264 times

Re: Seriously Weird

#218220

Postby Infrasonic » April 29th, 2019, 5:40 pm


Infrasonic
Lemon Quarter
Posts: 4487
Joined: November 4th, 2016, 2:25 pm
Has thanked: 648 times
Been thanked: 1264 times

Re: Seriously Weird

#218412

Postby Infrasonic » April 30th, 2019, 11:47 am



Return to “Technology - Computers, TV, Phones etc.”

Who is online

Users browsing this forum: Merrick and 34 guests