Groups | Search | Server Info | Login | Register
Groups > comp.dcom.modems.cable > #213
| From | Bit Twister <BitTwister@mouse-potato.com> |
|---|---|
| Newsgroups | alt.privacy.anon-server, alt.cable-tv, comp.dcom.modems.cable |
| Subject | Re: Over 135 million modems vulnerable to denial-of-service flaw |
| Date | 2016-04-11 14:02 +0000 |
| Organization | A noiseless patient Spider |
| Message-ID | <slrnngnbq4.o3m.BitTwister@wb.home.test> (permalink) |
| References | <c8854324eae8e8977009ee17a2d1c7c1@anemone.mooo.com> <cd11d3ae4a959cae97ed5066f8ce47f8@remailer.privacy.at> |
Cross-posted to 3 groups.
On Mon, 11 Apr 2016 12:10:23 +0200 (CEST), Anonymous Remailer (austria) wrote: > > In article <c8854324eae8e8977009ee17a2d1c7c1@anemone.mooo.com> > Jeremy Bentham <nobody@anemone.mooo.com> wrote: >> >> http://www.zdnet.com/article/millions-of-routers-vulnerable-to-unpatched-reboot-flaw/ > > That zdnet article is erroneous and inaccurate. > Resetting those cable modems does nothing but cause them to > reboot and reload a config file. But if that config file contents were reset to factory defaults it might not connect to the ISP provider. > BUT, an attacker has to be ON a PRIVATE RFC 1918 network, > inaccessible from the Internet in ALL cases. But you do not understand the exploit. As far as the modem is concerned it saw the reset from the user on the LAN. > They would also have to connect to each modem in order to > accomplish said feat. They don't have to. The user gets it when looking at an infected web page. As the article indicated it is a LAN side exploit. > It would take a very long time to scan > the entire address space and find any modems in it. Just how many users do you think get into their modem and change the LAN gateway address. The address and web page is hard coded for that modem. See http://192.168.100.1/cmConfigData.htm?BUTTON_INPUT1=Reset+All+Defaults
Back to comp.dcom.modems.cable | Previous | Next — Previous in thread | Next in thread | Find similar
Re: Over 135 million modems vulnerable to denial-of-service flaw "Anonymous Remailer (austria)" <mixmaster@remailer.privacy.at> - 2016-04-11 12:10 +0200
Re: Over 135 million modems vulnerable to denial-of-service flaw Cornelis Tromp <nobody@holland.remailer.nl> - 2016-04-11 13:43 +0100
Re: Over 135 million modems vulnerable to denial-of-service flaw Bit Twister <BitTwister@mouse-potato.com> - 2016-04-11 14:02 +0000
Re: Over 135 million modems vulnerable to denial-of-service flaw Fritz Wuehler <fritz@spamexpire-201604.rodent.frell.theremailer.net> - 2016-04-13 17:27 +0000
csiph-web