Any folks on Viewqwest fibre?

Status
Not open for further replies.

crewcutboy

Member
Joined
Mar 24, 2004
Messages
477
Reaction score
1
and you're obviously an obnoxious moron who jumps to conclusion just because you hide behind this wall of anonymity.
 

i-Movies

Senior Member
Joined
Jan 29, 2009
Messages
1,565
Reaction score
15
it's not MUCH of a security issue because nothing can be done with those keys! it's not the admin password.

once you enter, from DHCP list, you can see the devices attached on that Router, with their own private IP, hostname, Mac address, and if you are lucky, the hostname could tell you what it is, ie, MyBookLive, you will know that is a NAS, add that IP to port forwarding, you can access NAS admin page, turn on its SSH, add port 22 to port forwarding too, you are free to login to NAS, download or delete contents, install spammer... that's very serious attack.

if you are not lucky, you can't access any of its devices, you may just change its wireless password, disable GE port WAN access, change setup password, drive the owner crazy and complain to NOC@VQ to death, that's hoax.

nobody accepts either way, so let's hope VQ fix it.
 

viewqwest

Featured Sponsor for Internet Bandwidth & Networki
Joined
Nov 24, 2011
Messages
2,305
Reaction score
0
once you enter, from DHCP list, you can see the devices attached on that Router, with their own private IP, hostname, Mac address, and if you are lucky, the hostname could tell you what it is, ie, MyBookLive, you will know that is a NAS, add that IP to port forwarding, you can access NAS admin page, turn on its SSH, add port 22 to port forwarding too, you are free to login to NAS, download or delete contents, install spammer... that's very serious attack.

if you are not lucky, you can't access any of its devices, you may just change its wireless password, disable GE port WAN access, change setup password, drive the owner crazy and complain to NOC@VQ to death, that's hoax.

nobody accepts either way, so let's hope VQ fix it.

It's not actually a security issue of the router but rather an oversight on the part of Viewqwest.

We are resolving this issue by changing all of the passwords now. In future random passwords will be assigned to the default login.
 

i-Movies

Senior Member
Joined
Jan 29, 2009
Messages
1,565
Reaction score
15
It's not actually a security issue of the router but rather an oversight on the part of Viewqwest.

We are resolving this issue by changing all of the passwords now. In future random passwords will be assigned to the default login.

Changing the default password is ok for me, but I thought the router could do it better... My experience with some other wireless routers, they all by default, disable remote admin access, and if u really need it, you can config remote access port to prevent the URL from being easily guessed.
 

edwin21

Supremacy Member
Joined
Apr 23, 2000
Messages
5,038
Reaction score
0
Changing the default password is ok for me, but I thought the router could do it better... My experience with some other wireless routers, they all by default, disable remote admin access, and if u really need it, you can config remote access port to prevent the URL from being easily guessed.

zhone is not some typical wireless router, it so all in one, that a misconfig could open the admin page on WAN, VQ need the remote admin to configure the zhone, if the config is right, the remote admin should only open on VQ NOC vlan and the LAN side.
 

i-Movies

Senior Member
Joined
Jan 29, 2009
Messages
1,565
Reaction score
15
zhone is not some typical wireless router, it so all in one, that a misconfig could open the admin page on WAN, VQ need the remote admin to configure the zhone, if the config is right, the remote admin should only open on VQ NOC vlan and the LAN side.

Agree.......
 

ceecookie

Arch-Supremacy Member
Joined
Dec 26, 2006
Messages
22,176
Reaction score
581
Interesting, i found out you can also telnet the Zhone router. After logging in, it provides a Cisco IOS-like configuration down to the "enable" command

Is the Zhone running on Cisco IOS? :s22:
 

viewqwest

Featured Sponsor for Internet Bandwidth & Networki
Joined
Nov 24, 2011
Messages
2,305
Reaction score
0
zhone is not some typical wireless router, it so all in one, that a misconfig could open the admin page on WAN, VQ need the remote admin to configure the zhone, if the config is right, the remote admin should only open on VQ NOC vlan and the LAN side.

This is an interesting point. Lets see what we can do to make this happen.
 

edwin21

Supremacy Member
Joined
Apr 23, 2000
Messages
5,038
Reaction score
0
the good thing is bridge mode user need not worry, only router mode user are affected
 

chaicka

Arch-Supremacy Member
Joined
Jan 1, 2000
Messages
22,530
Reaction score
2
This is an interesting point. Lets see what we can do to make this happen.
Maybe VQ can commission a small security task force within this community to 'poke around' VQ's fibernet. I am sure there are a few who is good in this and has ethnic.

SB, where are u? Hehehehe...
 

liangtam

High Supremacy Member
Joined
Aug 20, 2002
Messages
38,771
Reaction score
85
When I saw the screenshot, I wanted to go poke around, but I guess not... :)

Anyway, can the DNS option be changed after logging in?
 

edwin21

Supremacy Member
Joined
Apr 23, 2000
Messages
5,038
Reaction score
0
can bridge mode user also have access to the admin config using the unused lan port on zhone?

it is possible to set bridging the unuse lan port with port isolation to wifi and set it as extra AP for the home network

so become internet -> bridged zhone -> own router -> router lan port to zhone router unused port bridged to wifi as AP
 

AntonS

Member
Joined
Oct 1, 2011
Messages
451
Reaction score
0
Changing the default password is ok for me, but I thought the router could do it better... My experience with some other wireless routers, they all by default, disable remote admin access, and if u really need it, you can config remote access port to prevent the URL from being easily guessed.

Due to the security concerns, we have decided to block remote WAN access to the Zhone, as well as SSH/Telnet access. Access to the Zhone's webUI will only be available from the LAN.
If anyone requires access from the WAN, please inform us by email with your details.
 

i-Movies

Senior Member
Joined
Jan 29, 2009
Messages
1,565
Reaction score
15
Due to the security concerns, we have decided to block remote WAN access to the Zhone, as well as SSH/Telnet access. Access to the Zhone's webUI will only be available from the LAN.
If anyone requires access from the WAN, please inform us by email with your details.

That's good enough, thanks for following up.
 

jasmanng

Junior Member
Joined
Sep 4, 2005
Messages
28
Reaction score
0
Due to the security concerns, we have decided to block remote WAN access to the Zhone, as well as SSH/Telnet access. Access to the Zhone's webUI will only be available from the LAN.
If anyone requires access from the WAN, please inform us by email with your details.

Did VQ also block port forwarding by any chance?
I'm unable to access my desktop since yesterday; it was ok beforehand.
 

liangtam

High Supremacy Member
Joined
Aug 20, 2002
Messages
38,771
Reaction score
85
You can change the DNS, but question is, for what purpose? To use opendns and the likes?

You can also change the DHCP LAN IP range, Zhone's LAN IP, etc.

To forward traffic to a intermediary rogue server and grab your traffic of course.
But all is fine now, since they block the 2 ports.
 
Status
Not open for further replies.
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ. Forum members and moderators are responsible for their own posts.

Please refer to our Community Guidelines and Standards, Terms of Service and Member T&Cs for more information.
Top