Re: SMC Routers have remote administration enabled by default

From: user86 (user86_at_earthlink.net)
Date: 04/29/04

  • Next message: houseofdabus HOD: "MS04011 Lsasrv.dll RPC buffer overflow remote exploit (PoC)"
    To: bugtraq@securityfocus.com
    Date: Thu, 29 Apr 2004 01:37:43 -0400
    
    

    On Thursday 29 April 2004 01:10, user86 wrote:
    > On Wednesday 28 April 2004 12:55, user86 wrote:
    > > There are two workarounds:
    > > 1. Enable the router's firewall in its "Advanced Setup"
    > >
    > > 2. Forward port 1900 of the router to a non-existent internal IP address
    > > (such as 192.168.2.248 if it isn't in use).
    >
    > A third workaround on the 7008ABR with firmware 1.032 is to go into the
    > router's "Advanced Setup" click "System" then "Remote Management" and click
    > "Apply" (even without changing any setting) and port 1900 then closes
    > itself.

    Ugh! Scratch that third workaround! I just found out that that third
    workaround only works as long as the router stays up. If the router is
    rebooted for *any* reason, such as during a power outage or by the user
    through the web interface, port 1900 is open again when the router boots back
    up!


  • Next message: houseofdabus HOD: "MS04011 Lsasrv.dll RPC buffer overflow remote exploit (PoC)"

    Relevant Pages

    • Re: wireless/wired
      ... do it if I was starting from scratch but it's set up for the wired ... access the wireless option. ... Router Web Configurator requires a username and password. ...
      (uk.telecom.broadband)
    • Re: Re: Tesco ADSL connection dropping Help?
      ... that the voice/ADSL filtering might not be up to scratch. ... I'd try another microfilter. ... So it can't be the router. ...
      (uk.telecom.broadband)
    • Re: Re: Re: Tesco ADSL connection dropping Help?
      ... that the voice/ADSL filtering might not be up to scratch. ... I'd try another microfilter. ... the speedtouch adsl modem that tesco supplied. ... So it can't be the router. ...
      (uk.telecom.broadband)
    • Re: Re: Tesco ADSL connection dropping Help?
      ... that the voice/ADSL filtering might not be up to scratch. ... I'd try another microfilter. ... So it can't be the router. ...
      (uk.telecom.broadband)
    • Re: BT router replacement required - and id still avoid BT like the plague
      ... supplied the router are we allowed to try to install our own router? ... the original network settings so is it feasible to set up the router from ... scratch without the download function being called? ... I have had to set-up a number of routers from scratch as temporary ...
      (uk.telecom.broadband)