28 Oct 2019 |
@rtwx:matrix.org | Redacted or Malformed Event | 21:55:45 |
zyk | Mhmm. I have a Linux box acting as a router here. One NIC plugged directly into ONT, the other down links to a switch/wifi | 21:59:39 |
zyk | Took quite a bit of setup to get it right. But at least I can be sure nobody is messing with my stuff. | 22:06:32 |
@themantiss:matrix.org | mikrotik 4 life | 22:41:12 |
zyk | https://www.cvedetails.com/vulnerability-list/vendor_id-12508/product_id-23641/year-2019/Mikrotik-Routeros.html | 22:43:14 |
@themantiss:matrix.org | if the firewall is set correctly nothing there is an issue, it's just that setting them properly is not easy, the learning curve is a vertical wall | 22:44:40 |
zyk | fair | 22:47:50 |
zyk | i just like poking fun at their vuln list | 22:47:58 |
zyk | it's always long | 22:48:00 |
@themantiss:matrix.org | aha yep | 22:48:25 |
zyk | i acutally used to have a couple of Routerboards at the edge of a hosting env i managed | 22:48:37 |
zyk | 100 X2 AH | 22:48:46 |
zyk | I think? | 22:48:48 |
zyk | 1100* | 22:48:50 |
zyk | huge fan of that interface once you figure it out | 22:49:26 |
zyk | I like things that don't hide advanced options/features | 22:49:44 |
zyk | even if that makes them a little tricker to pick up initially | 22:49:52 |
@rtwx:matrix.org | Redacted or Malformed Event | 22:53:33 |
@rtwx:matrix.org | Redacted or Malformed Event | 22:53:51 |
29 Oct 2019 |
@idanoo:matrix.m2.nz | zyk: | 00:18:08 |
@idanoo:matrix.m2.nz | yep | 00:18:09 |
@idanoo:matrix.m2.nz | It worries me a lot | 00:18:11 |
@idanoo:matrix.m2.nz | TR-069 isn't too bad though | 00:18:14 |
zyk | idanoo: I had no idea there was an offical standard for this. Looks like it can even do NAT traversal for management of set-top boxes and stuff | 05:47:56 |
@idanoo:matrix.m2.nz | Yeah - most NZ ISPs seem to use it as an auto-provision of routers based on MAC addresses | 05:48:39 |
@idanoo:matrix.m2.nz | Still... they can technically push anything to the router, like removing wifi pass/etc :/ | 05:48:57 |
zyk | Mm I see my MyRepublic router has some ACS server setting in it | 05:49:15 |
zyk | I wonder how badly they’ve fucked up their cert validation/etc | 05:49:42 |
zyk | Yeah it seems like a ton of stuff is possible | 05:50:17 |
zyk | And if you could MiTM it there would be all kinds of fun/profit | 05:50:46 |