LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-08-2014, 12:45 AM   #1
//////
Member
 
Registered: Nov 2005
Location: Land of Linux :: Finland
Distribution: Arch Linux && OpenBSD 7.4 && Pop!_OS && Kali && Qubes-Os
Posts: 824

Rep: Reputation: 350Reputation: 350Reputation: 350Reputation: 350
Router security.


after seeing one post about routers i became interested about my own.

it is a zyxel wmg3326-d20a and i found out that its web configuration page were accessible through internet, next thing to do was learning about its rate limiting of logins. i found out that it has no rate limiting at all, so i downloaded THC-Hydra, online login cracker and ran it against my routers login page.

Code:
[root@slackbox ville]# hydra 192.168.10.1 http-form-post "/login.cgi:UserName=^USER^&password=^PASS^&hiddenPassword=^PASS^&submitValue=1:The username or password is not correct" -l admin -P /root/passwords.txt
Hydra v8.1-dev (c) 2014 by van Hauser/THC - Please do not use in military or secret service organizations, or for illegal purposes.

Hydra (http://www.thc.org/thc-hydra) starting at 2014-11-08 08:27:00
[DATA] max 16 tasks per 1 server, overall 16 tasks, 2151221 login tries (l:1/p:2151221), ~8403 tries per task
[DATA] attacking service http-post-form on port 80
[80][www-form] host: 192.168.10.1   login: admin   password: !/.,1;*$@_-
1 of 1 target successfully completed, 1 valid password found
Hydra (http://www.thc.org/thc-hydra) finished at 2014-11-08 08:27:17
[root@slackbox ville]# wc -l /root/passwords.txt
2151221 /root/passwords.txt
[root@slackbox ville]#
it took about 10 seconds to crack it, the most worrying point is that that admin account has wrong password, it isnt mine, my own password for admin works also.

any thoughts? i have resetted it to factory defaults but that wrong admin pass works still. the response my router gives is :
Code:
HTTP/1.0 200 OK.
but the page it gives is blank.

i tried to deny access to login page thru net but havent still found out how i should do it.
 
Old 11-08-2014, 01:34 PM   #2
//////
Member
 
Registered: Nov 2005
Location: Land of Linux :: Finland
Distribution: Arch Linux && OpenBSD 7.4 && Pop!_OS && Kali && Qubes-Os
Posts: 824

Original Poster
Rep: Reputation: 350Reputation: 350Reputation: 350Reputation: 350
Quote:
Originally Posted by ////// View Post
but the page it gives is blank.
i think that holds the key to this problem. because it is giving a blank page hydra doesnt see the string "The username or password is not correct" from the response page when it tries to log in. which means false positive i think.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Router set up security clifford227 Linux - Security 8 10-29-2010 04:45 PM
is router security not important neilcpp Linux - Security 40 02-13-2009 09:14 AM
new router and security questions paperplane Linux - Security 4 01-12-2008 06:34 PM
Security on a Netgear Router phantom_cyph Linux - Wireless Networking 13 02-22-2007 01:01 PM
router/AP security true_atlantis Linux - Hardware 1 08-26-2005 03:55 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:48 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration