 | reply to NSA_CIA
Re: Time Warner Cable Exposes 65,000 Routers to Remote Attacks Mr. Chen gave us the port numbers there.
quote: ports 8080, 8181 and 23
The article goes on to say the temporary patch has left remote admin open, but deprived attackers of the ability to ascertain the admin credentials using the javascript hole. In the meantime, they didn't change the standard admin credentials from the values Chen found previously. So since they have surely been dissemminated or can be ascertained from context, the temporary patch is really not stopping a determined attacker.
Bottom line if you have this CPE equipment get rid of it immediately and demand a plain old bridge modem from TW, and bring your own router/AP. -- Scott Brown Consulting |