186 SMC Routers remote administration without authentication Network Devices 2004/09/07 Nico 'Triplex' Spicher Triplex at IT-Helpnet dot de http://triplex.it-helpnet.de http://www.it-helpnet.de Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch 2004/11/13 1.2 Made some slight modifications in version 1.1. Corrected the plugin structure and added the accuracy values in 1.2 tcp 1900 open|send GET / HTTP/1.0\n\n|sleep|close|pattern_exists 200 10 This plugin was written with the ATK Attack Editor. user86 user86 at earthlink dot net SMC Routers 7008ABR, 7004VBR and other models Other routers Missing authentication SMC broadband routers ship with remote administration (completely passwordless) enabled by default on their port 1900 on the WAN side of the router. Enable FW & forward port 1900 of the router to a non-existent internal IP address. Aprox. 20 Minutes Yes Yes No High 4 8 9 6 Hacking Intern - Angriffe, Strategien, Abwehr, Marc Ruef, Marko Rogge, Uwe Velten and Wolfram Gieseke, November 1, 2002, Data Becker, Düsseldorf, ISBN 381582284X http://www.computec.ch