Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


hasso

76 posts

Master Geek
+1 received by user: 19


#214749 26-May-2017 12:21
Send private message

Hi...

 

I've noticed that port 8081 on my router is open to the internet. Although it seems to be protected with a Username and Password, I have not set up this access on the router... in fact I have set it up to not allow any incoming 'non-established' traffic. So, where did it come from and how do I turn it off?

 

Hasso


Create new topic
sbiddle
30853 posts

Uber Geek
+1 received by user: 9996

Retired Mod
Trusted
Biddle Corp
Lifetime subscriber

  #1788696 26-May-2017 12:23
Send private message

It's for TR-069 management. There are no risks in this and you should not disable it.

 

 

 

 




hasso

76 posts

Master Geek
+1 received by user: 19


  #1788698 26-May-2017 12:34
Send private message

OK... since I don't have the "super admin" password, I don't think I can turn it off in any case... but I am therefore trusting Spark to manage this securely. Based on this article is that trust well founded?

 

http://www.pcworld.com/article/2463480/many-home-routers-supplied-by-isps-can-be-compromised-en-masse-researchers-say.html

 

Perhaps what a friend of mine told me is the way to go..."Put another firewall/router behind it to protect your network and only use the wireless functionality on the Spark provided HG659b for guest wifi.


hashbrown
463 posts

Ultimate Geek
+1 received by user: 131


  #1788886 26-May-2017 18:47
Send private message

I think last time I checked Shodan about 450,000 NZ IPs had that port open.



BarTender
3629 posts

Uber Geek
+1 received by user: 2572

ID Verified
Trusted
Lifetime subscriber

  #1790301 27-May-2017 16:59
Send private message

It's a complete non-issue as @sbiddle said. The TR-069 connection request port is only used to do a HTTP GET to the router and then that makes the router "phone home".

 

The worst that can happen if the username & password was compromised is the router connects back to the ACS and says "this is my configuration".

 

That PC World article is also utter BS and it says so itself

 

"So far Tal and his colleagues at Check Point have investigated vulnerabilities on the server side, but they also plan to investigate possible attack vectors against the TR-069 client implementations on devices."

 

So everyone starts freaking out about the server which is completely unrelated to the client (ie your router) which has no known attack vectors.


yitz
2238 posts

Uber Geek
+1 received by user: 594


  #1790332 27-May-2017 17:46
Send private message

I hope traffic to the ACS is unmetered wink


BarTender
3629 posts

Uber Geek
+1 received by user: 2572

ID Verified
Trusted
Lifetime subscriber

  #1790336 27-May-2017 18:01
Send private message

yitz:

I hope traffic to the ACS is unmetered wink


It's not. Get an unlimited plan and the 1mb of data it transferred over the whole month won't count against your cap.

 
 
 
 

Shop now for Dyson appliances (affiliate link).
Linux
12173 posts

Uber Geek
+1 received by user: 8469

Trusted
Lifetime subscriber

  #1790379 27-May-2017 19:17
Send private message

Scaremongering by a reporter again I see

Linux

MadEngineer
4591 posts

Uber Geek
+1 received by user: 2570

Trusted

  #1790405 27-May-2017 22:02
Send private message

ZOMG MY ISP HAS A BACKDOOR TO MY ROUTER!

 

 

 

 

 

 

Edit, oh, i see there's a thread for that here.





You're not on Atlantis anymore, Duncan Idaho.

Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.