The arrow of time

Ivan Voras' blog

Beware of stupidly configured ADSL routers

My old ADSL modem+router was acting strangely (it wasn't 100% stable even at the start - but it was free...) so I bought a new one. Good thing I, practically by accident, tried to connect to it from the outside (from the WAN / Internet side) via Telnet. There it was, wide open, with a default username/password of "admin" / "admin".

Microtek's ADSL modem+router apparently has this interesting feature built-in by default: it's wide open for administration from then WAN (Internet) side. This, among other things, includes plain Telnet on port 23.

This needs to be secured immediately by the very intuitively named control "ACL" (the plain firewall is called "Filter" and it doesn't influence administration services!). On the plus side, the configuration is quite powerful, allowing separate "opening" of Web, Telnet and SNMP configuration / monitoring services on separate IPs.

Lesson learned - always run a session of nmap from the WAN side on new equipment.

Post your comment here!

Your name:
Comment title:
Text:
Type "xxx" here:

Comments are subject to moderation and will be deleted if deemed inappropriate. All content is © Ivan Voras. Comments are owned by their authors (who agree to basically surrender all rights by publishing them :) )..