TR-069 remote management port.

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • stj
    Great Sage 齊天大聖
    • Dec 2009
    • 31044
    • Albion

    #1

    TR-069 remote management port.

    is hacked - i warned about that shit!
    http://www.theregister.co.uk/2016/11...assive_attack/
  • diif
    Badcaps Legend
    • Feb 2014
    • 6978
    • England

    #2
    Re: TR-069 remote management port.

    That's not hacking, that's poor configuration and accepting commands without authentication but I get what you're saying.
    Oh what a surprise to see TalkTalk mentioned. !

    Comment

    • stj
      Great Sage 齊天大聖
      • Dec 2009
      • 31044
      • Albion

      #3
      Re: TR-069 remote management port.

      they assume it's TR-064 used.
      the TR-069 password can be recovered from the flash - and i bet they are all the same for the isp model.
      if not i bet they are just the SHA1 of a twist on the mac address like the default wifi keys always are!!

      Comment

      • diif
        Badcaps Legend
        • Feb 2014
        • 6978
        • England

        #4
        Re: TR-069 remote management port.

        All of the other exploits used by Mirai were hard coded default usernames and passwords, I don't see why this one would be any different.
        I can only see this growing as more and more devices are added to the list over time.

        Comment

        • stj
          Great Sage 齊天大聖
          • Dec 2009
          • 31044
          • Albion

          #5
          Re: TR-069 remote management port.

          if it wasnt hidden, users could disable it.
          who owns your router if you dont have total admin rights?!!

          Comment

          • diif
            Badcaps Legend
            • Feb 2014
            • 6978
            • England

            #6
            Re: TR-069 remote management port.

            If the ISP actually carried out due diligence rather than go for the lowest bid for the hardware the users wouldn't need to disable it as it wouldn't be there.

            Most belong to the ISP in the UK.

            Comment

            • ddscentral
              Senior Member
              • Mar 2008
              • 151
              • Lithuania, EU

              #7
              Re: TR-069 remote management port.

              Originally posted by stj
              if it wasnt hidden, users could disable it.
              who owns your router if you dont have total admin rights?!!
              That's the catch. Many ISPs lock-down remote management options so that users can't disable them. I remember having to hack my ISP supplied DSL router (an ADB unit) to get full admin access so I could disable all the remote management crap.

              That's why I always use my own routers.
              Last edited by ddscentral; 11-29-2016, 12:52 PM.

              Comment

              • stj
                Great Sage 齊天大聖
                • Dec 2009
                • 31044
                • Albion

                #8
                Re: TR-069 remote management port.

                Originally posted by diif
                If the ISP actually carried out due diligence rather than go for the lowest bid for the hardware the users wouldn't need to disable it as it wouldn't be there.

                Most belong to the ISP in the UK.
                no, the custommer is either charged for them (BT) or they are supplied free on the understanding that they are a gift.
                the only company i know that retains ownership is sky.
                virgin routers are a grey area.
                then again, virgin routers are docsis3 so it's not much use for anything else in the u.k.

                Comment

                • vinceroger69
                  Badcaps Legend
                  • Mar 2012
                  • 6714
                  • uk

                  #9
                  Re: TR-069 remote management port.

                  slightly off topic but have you saw these new laws that have just came into force in the uk
                  http://www.independent.co.uk/life-st...-a7445276.html
                  https://www.theguardian.com/world/20...e-surveillance
                  Last edited by vinceroger69; 11-29-2016, 02:05 PM.

                  Comment

                  • stj
                    Great Sage 齊天大聖
                    • Dec 2009
                    • 31044
                    • Albion

                    #10
                    Re: TR-069 remote management port.

                    yes, the treason never ends.
                    but we have lots of camera mounts to hang the politicians from - and hansard to find out who is guilty!!!

                    Comment

                    • diif
                      Badcaps Legend
                      • Feb 2014
                      • 6978
                      • England

                      #11
                      Re: TR-069 remote management port.

                      Originally posted by stj
                      no, the custommer is either charged for them (BT) or they are supplied free on the understanding that they are a gift.
                      the only company i know that retains ownership is sky.
                      virgin routers are a grey area.
                      then again, virgin routers are docsis3 so it's not much use for anything else in the u.k.
                      They charge for delivery but come with the contract. They are the responsibility of the ISP.
                      Virgin modems are definitely owned by Virgin (although only in name). They can log in and view your connected devices and also will replace it when asked.

                      I believe the new laws Vince are just legalising some of what GCHQ have been doing for a while, whilst shifting the responsibility of saving the data to the ISPs.

                      With the annual cost of a decent VPN provider costing less than the price of a good night out I don't know why everyone doesn't use one.

                      Comment

                      • stj
                        Great Sage 齊天大聖
                        • Dec 2009
                        • 31044
                        • Albion

                        #12
                        Re: TR-069 remote management port.

                        because man-in-the-middle at the ISP or Gateway will compromise HTTPS and most VPN's are in the u.s. and covered by security letters - in other words, the NSA virtually run them.

                        Comment

                        • diif
                          Badcaps Legend
                          • Feb 2014
                          • 6978
                          • England

                          #13
                          Re: TR-069 remote management port.

                          Lots aren't.
                          A fairly comprehensive list here.
                          https://thatoneprivacysite.net/vpn-comparison-chart/

                          Comment

                          • vinceroger69
                            Badcaps Legend
                            • Mar 2012
                            • 6714
                            • uk

                            #14
                            Re: TR-069 remote management port.

                            I have never looked into vpn service etc so dont know anything at all about it in basic terms what does it do and is it worth having it? also would you be able to use streaming boxes still or will content be blocked thanks for any advice you can offer.

                            Comment

                            • diif
                              Badcaps Legend
                              • Feb 2014
                              • 6978
                              • England

                              #15
                              Re: TR-069 remote management port.

                              Originally posted by vinceroger69
                              I have never looked into vpn service etc so dont know anything at all about it in basic terms what does it do and is it worth having it? also would you be able to use streaming boxes still or will content be blocked thanks for any advice you can offer.
                              Imagine it as a secure tunnel, though your ISP through ignoring the ever growing block list to a server in a country of your choice. Nothing is blocked and with the good ones nothing is logged. Some let you torrent too
                              I have it on my PC and my phones.

                              Comment

                              • vinceroger69
                                Badcaps Legend
                                • Mar 2012
                                • 6714
                                • uk

                                #16
                                Re: TR-069 remote management port.

                                Thanks thats good to know.

                                Comment

                                Related Topics

                                Collapse

                                • Mc_Millian
                                  Toshiba 50lf711u20 fire tv remote not pairing
                                  by Mc_Millian
                                  Hello everyone,

                                  I was wondering if anyone could help my in pairing a remote with a Toshiba fire tv?
                                  The Tv model number is: 50lf711u20 Rev B.


                                  I've already replaced all the the circuit boards within the tv along with the I.R. sensor receiver.

                                  I've tried 3 different remotes which should be fully compatible with this TV.


                                  Oddly enough. A few if the buttons on all of the remotes actually work. Even without pairing...which makes no sense.

                                  The power button, along with the volume,back,select, and directional...
                                  04-07-2022, 12:15 PM
                                • edugimeno
                                  HiSense 55A7500F won't obbey to remote after power on
                                  by edugimeno
                                  Hi! I have this TV set that does the following:
                                  1) I press the red power button on the remote
                                  2) The TV turns on normally
                                  3) After that it won't take any other command from the remote, neither power off, volume, channel, NOTHING
                                  4) We need to either pull the main cable or use the built in button at the bottom to select funcion OFF

                                  Then after it's off, it would again accept the TURN ON from the remote and same again

                                  BUT:
                                  -The remote does show the correct IR beam while observed thru a phone camera
                                  -The TV works fine while using the MiRemote...
                                  03-14-2023, 11:22 AM
                                • tmhobadcap
                                  Pioneer VSX-522-K remote control not working???
                                  by tmhobadcap
                                  I have this receiver for at least 10 years. Usually, we just use the remote for turning on/off and adjusting the volume. Recently, the remote control started not able to turn the receiver on. Later, the volume also could not be adjusted by the remote control.

                                  At first, I thought that it was the usual problem which can be fixed by cleaning the contacts on the switches and the pcb. I opened the remote and clean it with alcohol. The remote did work again after that. But after one day, it did not work again. I opened it again and clean with alcohol and contact cleaner. Again it worked...
                                  12-24-2020, 01:44 AM
                                • rustinjust
                                  Please help, where can I get a remote for my subwoofer?
                                  by rustinjust
                                  I’ve got a subwoofer that I’ve had for nearly 20 years, it did come with a basic remote which I’ve lost. It’s a generic make of subwoofer, I can’t see a brand sticker on it. It comes with 2 speakers.

                                  Question recently I’ve connected it up to my tv which has greatly improved the sound on my tv, however I’d like to be able to mute the subwoofer when ads come on or just mute it when the phone rings etc. I tried using a cheap all in one tv remote on the subwoofer and the volume button would only work to increase volume but not turn it down or mute it

                                  Is there...
                                  10-28-2023, 03:43 AM
                                • jesterace
                                  Samsung B2030HD IR Remote Receiver Dead, shorted micom?
                                  by jesterace
                                  Hi,
                                  I have this TV a small 20 inch that works perfectly except for the IR has stopped. I have confirmed that the remote control is fine and tried an alternative and even tried with IR blaster from phone. Remote 100% ok.

                                  Tried installing latest firmware but no change.

                                  TV won't respond to remote at all, not even to bring it out of standby. I have to use the touch sensitive front panel to operate, at which point TV is usable albeit with no remote.

                                  Tried replacing the IR receiver diode/bulb on front panel and no change so put the old one back. After tracing...
                                  10-26-2022, 02:20 AM
                                • Loading...
                                • No more items.
                                Working...