ARRIS cable modem has backdoor in its backdoor
https://w00tsec.blogspot.de/2015/11/arris-cable-modem-has-backdoor-in.html?m=1
"While researching on the subject, I found a previously
undisclosed backdoor on ARRIS cable modems, affecting many of
their devices including TG862A, TG862G, DG860A. As of this
writing, Shodan searches indicate that the backdoor affects over
600.000 externally accessible hosts and the vendor did not state
whether it's going to fix it yet."
- - -
If you have any ARRIS cable modem, you might want to check
http://192.168.100.1/cgi-bin/tech_support_cgi (from inside your local
net). If you get a tech interface, that's bad news. If you get a 404,
that's better news, but I would doubt definitive. Some people are
reporting user interfaces that appear the same as in the photo, others
that look different. But go ahead and try that URL for now.
--Lauren--
Lauren Weinstein ([email protected]): http://www.vortex.com/lauren
Founder:
- Network Neutrality Squad: http://www.nnsquad.org
- PRIVACY Forum: http://www.vortex.com/privacy-info
Co-Founder: People For Internet Responsibility: http://www.pfir.org/pfir-info
Member: ACM Committee on Computers and Public Policy
Lauren's Blog: http://lauren.vortex.com
Google+: http://google.com/+LaurenWeinstein
Twitter: http://twitter.com/laurenweinstein
Tel: +1 (818) 225-2800 / Skype: vortex.com
I have consulted to Google, but I am not currently doing so.
My opinions expressed here are mine alone.
_______________________________________________
nnsquad mailing list
http://lists.nnsquad.org/mailman/listinfo/nnsquad