Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you want to hear something else scary, I dumped the firmware on my modem a little while back and started exploring it:

https://twitter.com/joshumax/status/860712276717748225



Did you need to do anything special to get shell access?


Just the basics.

Plugged in my 'scope and started probing some debug headers that looked a lot like they'd be for UART, check if one is Tx and is sending out data, figure out the baud rate, hook up Rx, Tx, and GND on my UART dongle to the correct headers, and modify the bootsting in Cisco preboot to spawn a serial console which landed me into busybox as root :)


> Just the basics.

Followed by the use of >=$100 of hardware and some not-beginner skills. Snark aside, I highly recommend anyone remotely interested in what is going on in your modem/router to have a go at this. You don't need the scope if you're okay with trial and error and it's pretty hard to break anything as long as you don't connect the 3.3/5V line to start with.


I think he means people-who-work-with-routers basics :)


Nice, I would have assumed there would be additional security for production units honestly.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: