ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    TP-Link abandons 'forgotten' router config domains

    Scheduled Pinned Locked Moved News
    8 Posts 5 Posters 709 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DustinB3403D
      DustinB3403
      last edited by DustinB3403

      TP-Link abandons 'forgotten' router config domains.

      Read it here.

      1 Reply Last reply Reply Quote 0
      • scottalanmillerS
        scottalanmiller
        last edited by scottalanmiller

        That's a pretty big security hole to leave open.

        1 Reply Last reply Reply Quote 0
        • DustinB3403D
          DustinB3403
          last edited by

          It just gets better and better as I read more on this topic....

          1 Reply Last reply Reply Quote 2
          • DashrenderD
            Dashrender
            last edited by

            It's really not super horrible - bad, sure, but super bad.. not really.

            if you're behind the firewall, the firewall intercepts requests to this domain and redirects them to itself (it's own webserver). If you're not behind the device, then why are you going there in the first place?

            JaredBuschJ 1 Reply Last reply Reply Quote 0
            • JaredBuschJ
              JaredBusch @Dashrender
              last edited by

              @Dashrender said in TP-Link abandons 'forgotten' router config domains:

              It's really not super horrible - bad, sure, but super bad.. not really.

              It is worse than you think, but no not horrible because there are not enough devices using it out there.

              @Dashrender said:

              if you're behind the firewall, the firewall intercepts requests to this domain and redirects them to itself (it's own webserver).

              Not exactly. None of these routers work like that. They do not intercept anything. They provide a DNS answer with their own IP for this. That is not intercepting traffic. So if the machine has something other than the router for DNS, then it will go right through the router. A lot of home users try and put things like OpenDNS on their stuff and put it in the DHCP scope on these routers because they are wanting to block porn and such.

              @Dashrender said:

              If you're not behind the device, then why are you going there in the first place?

              Because people are stupid.

              DashrenderD 1 Reply Last reply Reply Quote 1
              • DashrenderD
                Dashrender @JaredBusch
                last edited by

                @JaredBusch said in TP-Link abandons 'forgotten' router config domains:

                @Dashrender said in TP-Link abandons 'forgotten' router config domains:

                It's really not super horrible - bad, sure, but super bad.. not really.

                It is worse than you think, but no not horrible because there are not enough devices using it out there.

                @Dashrender said:

                if you're behind the firewall, the firewall intercepts requests to this domain and redirects them to itself (it's own webserver).

                Not exactly. None of these routers work like that. They do not intercept anything. They provide a DNS answer with their own IP for this. That is not intercepting traffic. So if the machine has something other than the router for DNS, then it will go right through the router. A lot of home users try and put things like OpenDNS on their stuff and put it in the DHCP scope on these routers because they are wanting to block porn and such.

                @Dashrender said:

                If you're not behind the device, then why are you going there in the first place?

                Because people are stupid.

                Have you tested that and know the DNS redirection is true? If so, I see an errata in Security Now for next week.

                JaredBuschJ 1 Reply Last reply Reply Quote 0
                • JaredBuschJ
                  JaredBusch @Dashrender
                  last edited by

                  @Dashrender said in TP-Link abandons 'forgotten' router config domains:

                  Have you tested that and know the DNS redirection is true? If so, I see an errata in Security Now for next week.

                  Let me answer by asking you this.
                  Do you think all these home routers have a web proxy running on them?

                  1 Reply Last reply Reply Quote 0
                  • J
                    Jason Banned
                    last edited by

                    It's TP-Link, is anyone surprised?

                    1 Reply Last reply Reply Quote 1
                    • 1 / 1
                    • First post
                      Last post