272
Netgear RP114 telnet administration detection
Firewalls
2004/11/12
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
1.0
tcp
23
open|sleep|clsose|pattern_exists *ÿûÿû*Password: *
97
There are several other possibilities to detect a Netgear RP114 - These will be implemented as independend ATK plugin in the future.
Netgear RP114
Other solutions
Configuration
The remote host seems to be a Netgear RP114. This is a small SOHO appliance firewall. It is possible to define the settings over the telnet interface. This does just rely on a simple password authentication (no user name) in clear text.
The server should be deactivated or de-installed if not necessary. To make it harder to find the server the daemon could be configured to listen at another port (e.g. 8023). Try to prevent unwanted connection attempts by filtering traffic with firewalling.
Approx. 1 hour
Yes
Yes
No
Medium
6
8
7
7
Hacking Intern - Angriffe, Strategien, Abwehr, Marc Ruef, Marko Rogge, Uwe Velten and Wolfram Gieseke, November 1, 2002, Data Becker, Düsseldorf, ISBN 381582284X
http://www.computec.ch