Re: Yondoo provided router, has "password" as admin pw, won't let us change it

2023-02-09 Thread Dave Taht
I am also a big fan of installing cake (sqm-scripts) in front cable devices. On Thu, Feb 9, 2023 at 5:59 AM Todd Stiers wrote: > > [OP here] > > Just some minor follow up: > > - The tech was able to swap out their RG with the modem-only one that I had > sent (after making a couple phone calls).

Re: Yondoo provided router, has "password" as admin pw, won't let us change it

2023-02-09 Thread Todd Stiers
[OP here] Just some minor follow up: - The tech was able to swap out their RG with the modem-only one that I had sent (after making a couple phone calls). It didn't seem like they could provision a user-supplied modem remotely for some reason, but it also sounded like maybe this wasn't something

Re: Yondoo provided router, has "password" as admin pw, won't let us change it

2023-02-08 Thread Jason R. Rokeach via NANOG
It’s been a while, but attacks that take advantage of this are (or at least in the past have been) real.https://blog.sucuri.net/2014/09/website-security-compromised-website-used-to-hack-home-routers.htmlhttps://www.digitaltrends.com/web/_javascript_-malware-mobile/ I recall when this stuff first

Re: Yondoo provided router, has "password" as admin pw, won't let us change it

2023-02-08 Thread Eric Kuhnke
I agree, but if we start listing every massive security vulnerability that can be found on the intra-home LAN in consumer-grade routers and home electronics equipment, or things that people operate in their homes with the factory-default passwords, we'd be here all month in a thread with 300 emails

Re: Yondoo provided router, has "password" as admin pw, won't let us change it

2023-02-08 Thread William Herrin
On Wed, Feb 8, 2023 at 2:36 PM Eric Kuhnke wrote: > I would hope that this router's admin "password" interface is only accessible > from the LAN side. > This is bad, yes, but not utterly catastrophic. It means that any compromised device on the LAN can access the router with whatever permissions

Re: Yondoo provided router, has "password" as admin pw, won't let us change it

2023-02-08 Thread Eric Kuhnke
I would hope that this router's admin "password" interface is only accessible from the LAN side. It's not listening to the world for a login with "password", right? Have you port scanned its WAN interface and tried connecting to it to see what's listening? This is bad, yes, but not utterly catast

Re: Yondoo provided router, has "password" as admin pw, won't let us change it

2023-02-08 Thread Collider
The first router would still be vulnerable, and through it the second router. On 8 February 2023 16:06:07 UTC, Josh Luthman wrote: >What's the problem with double NAT? I can't imagine an elderly mom trying >to host Xbox games - which is 95% of the problem with double NAT these days >(the other

Re: Yondoo provided router, has "password" as admin pw, won't let us change it

2023-02-08 Thread Josh Luthman
What's the problem with double NAT? I can't imagine an elderly mom trying to host Xbox games - which is 95% of the problem with double NAT these days (the other 5% being Ubiquiti bros having to access their Unifi router from anywhere). Your screenshots didn't come through, I suspect it's stripped