271
Netgear RP114 web administration detection
Firewalls
2004/11/12
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
1.0
tcp
80
open|send GET / HTTP/1.0\n\n|sleep|clsose|pattern_exists HTTP/#.# ### *WWW-Authenticate: Basic realm="RP114"*Server: ZyXEL-RomPager*
99
There are several other possibilities to detect a Netgear RP114 - These will be implemented as independend ATK plugin in the future.
Netgear RP114
Other solutions
Configuration
The remote host seems to be a Netgear RP114. This is a small SOHO appliance firewall. It is possible to define the most important settings over the web interface.
The server should be deactivated or de-installed if not necessary. To make it harder to find the server the daemon could be configured to listen at another port (e.g. 8081). Try to prevent unwanted connection attempts by filtering traffic with firewalling.
Approx. 1 hour
Yes
Yes
No
Medium
5
8
7
6
Hacking Intern - Angriffe, Strategien, Abwehr, Marc Ruef, Marko Rogge, Uwe Velten and Wolfram Gieseke, November 1, 2002, Data Becker, Düsseldorf, ISBN 381582284X
http://www.computec.ch