<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hub 2 -- Lax Admin Security? in My Router</title>
    <link>https://community.plus.net/t5/My-Router/Hub-2-Lax-Admin-Security/m-p/1903181#M34378</link>
    <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/44959"&gt;@madra&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No, just being realistic.&lt;/P&gt;</description>
    <pubDate>Fri, 23 Dec 2022 16:19:49 GMT</pubDate>
    <dc:creator>Baldrick1</dc:creator>
    <dc:date>2022-12-23T16:19:49Z</dc:date>
    <item>
      <title>Hub 2 -- Lax Admin Security?</title>
      <link>https://community.plus.net/t5/My-Router/Hub-2-Lax-Admin-Security/m-p/1903122#M34367</link>
      <description>&lt;P&gt;I've been pretty used to visiting my routers internal IP address on my home network and being dumped right into the admin section.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Today I activated 'Static IP' add-on for my broadband package and visited my router via its static IP address on my phone [which has never connected to my router before]. I was pretty shocked to find that the router admin section is partially open for anyone to snoop around, who chances upon my IP.&amp;nbsp; Now, I'm not saying it's completely wide open. If I try to dive into any of the sections to change a setting, I'm asked for the admin password --thank god! However, there's still a lot of potentially private info that's freely visible on the router admin screen, without entering the admin password:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;* The 'Hub Status' page, which gives, amongst other things; connection status, upload and download speed, uptime, router serial number, router firmware version.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;* Basic WiFi page, which gives; which channel frequencies [2,4GHz and/or 5GHz] are active, which channel each is using,&amp;nbsp; whether I have WPS enabled, network name, security type, wireless mode.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;* My devices page, which gives a list of every device connected to my router, with their individual IP addresses. This is a shocking security hole. So, now I'm not only at risk from anyone with an exploit for my router, but for anyone with an exploit for anyone of the dozen or so devices connected to it!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Am I missing something here? Or is there some pretty atrocious security on this router?&amp;nbsp; With my last broadband router, if I visited its public IP address, I couldn't see anything at all without logging in.&amp;nbsp; This one seems to give any potential hackers a wealth of useful information to help them along.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2022 22:56:08 GMT</pubDate>
      <guid>https://community.plus.net/t5/My-Router/Hub-2-Lax-Admin-Security/m-p/1903122#M34367</guid>
      <dc:creator>madra</dc:creator>
      <dc:date>2022-12-22T22:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: Hub 2 -- Lax Admin Security?</title>
      <link>https://community.plus.net/t5/My-Router/Hub-2-Lax-Admin-Security/m-p/1903127#M34368</link>
      <description>&lt;P&gt;Are you sure your phone was connected via the mobioe network and not via your home wifi ?&lt;/P&gt;
&lt;P&gt;AFAIK thev router is not accesible remotely by default. Howevervif you were connected to your home network, then NAT loopback would allow access internally without going out to the internet and back&lt;/P&gt;</description>
      <pubDate>Fri, 23 Dec 2022 07:49:30 GMT</pubDate>
      <guid>https://community.plus.net/t5/My-Router/Hub-2-Lax-Admin-Security/m-p/1903127#M34368</guid>
      <dc:creator>MisterW</dc:creator>
      <dc:date>2022-12-23T07:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: Hub 2 -- Lax Admin Security?</title>
      <link>https://community.plus.net/t5/My-Router/Hub-2-Lax-Admin-Security/m-p/1903128#M34369</link>
      <description>&lt;P&gt;In support of the above post you can check the open ports on your router&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.yougetsignal.com/tools/open-ports/" target="_self"&gt;https://www.yougetsignal.com/tools/open-ports/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Select "Scan all Common Ports" found at the bottom of the command ports list on the right.&lt;/P&gt;
&lt;P&gt;I have been unable to connect to my router from the internet using my public static IP address but I can on my local LAN.&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Dec 2022 08:26:43 GMT</pubDate>
      <guid>https://community.plus.net/t5/My-Router/Hub-2-Lax-Admin-Security/m-p/1903128#M34369</guid>
      <dc:creator>Dan_the_Van</dc:creator>
      <dc:date>2022-12-23T08:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: Hub 2 -- Lax Admin Security?</title>
      <link>https://community.plus.net/t5/My-Router/Hub-2-Lax-Admin-Security/m-p/1903132#M34370</link>
      <description>&lt;DIV style="background: #EDF3F5; padding: 10px; margin-top: 20px; margin-right: 10px; border: 2px solid #CFD8DC; border-radius: 10px; box-shadow: 8px 8px 7px #676D70; font-size: 10pt;"&gt;&lt;STRONG&gt;Moderators Note&lt;/STRONG&gt;
&lt;P style="font-size: 10pt;"&gt;This topic has been moved from Full Fibre to My Router&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 23 Dec 2022 08:58:51 GMT</pubDate>
      <guid>https://community.plus.net/t5/My-Router/Hub-2-Lax-Admin-Security/m-p/1903132#M34370</guid>
      <dc:creator>Baldrick1</dc:creator>
      <dc:date>2022-12-23T08:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: Hub 2 -- Lax Admin Security?</title>
      <link>https://community.plus.net/t5/My-Router/Hub-2-Lax-Admin-Security/m-p/1903152#M34373</link>
      <description>&lt;P&gt;&amp;nbsp; &amp;gt;Are you sure your phone was connected via the mobioe network and not via your home wifi ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ah. that's a point.&amp;nbsp; I was checking in the house, so my mobile would have been going through my house WiFi. I'll have to test again when I'm out and about.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That said, I'd never connected to my router via my phone. So, even if [as seems likely] my phone was using my home WiFi network,&amp;nbsp; I was still seeing a lot of info 'for free' about my router config and setup, without being logged in in any way, but just by dint of being on the same local network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It still seems very lax from a security point of view.&amp;nbsp; I'm thinking if this was a small office setting or somewhere like a cafe / pub where they allow guest access to their network, or a shared student house. It's surely not good practice to give so much potential 'ammo' to anyone who happens to be on the same network. Guests or non-admin users shouldn't be able to 'peek behind the curtain' at the router's admin controls at all, without logging in.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Dec 2022 10:47:35 GMT</pubDate>
      <guid>https://community.plus.net/t5/My-Router/Hub-2-Lax-Admin-Security/m-p/1903152#M34373</guid>
      <dc:creator>madra</dc:creator>
      <dc:date>2022-12-23T10:47:35Z</dc:date>
    </item>
    <item>
      <title>Re: Hub 2 -- Lax Admin Security?</title>
      <link>https://community.plus.net/t5/My-Router/Hub-2-Lax-Admin-Security/m-p/1903153#M34374</link>
      <description>&lt;P&gt;I'm sure that when I have had cause to contact Plusnet with an issue, they have been able to see in to my Hub2 to check for issues?&lt;/P&gt;
&lt;P&gt;Is there a hidden "Admin" login that they use to do this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Dec 2022 10:48:13 GMT</pubDate>
      <guid>https://community.plus.net/t5/My-Router/Hub-2-Lax-Admin-Security/m-p/1903153#M34374</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2022-12-23T10:48:13Z</dc:date>
    </item>
    <item>
      <title>Re: Hub 2 -- Lax Admin Security?</title>
      <link>https://community.plus.net/t5/My-Router/Hub-2-Lax-Admin-Security/m-p/1903155#M34375</link>
      <description>&lt;P&gt;&lt;EM&gt;&lt;SPAN&gt;&amp;nbsp;Guests or non-admin users shouldn't be able to 'peek behind the curtain' at the router's admin controls at all, without loggi&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;you might be able to look at some basic information but you can't 'do' anything without logging in&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN&gt;Is there a hidden "Admin" login that they use to do this?&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;no, they use TR069 which is a secure protocol which only allows access from the Plusnet server&lt;/P&gt;</description>
      <pubDate>Fri, 23 Dec 2022 10:53:18 GMT</pubDate>
      <guid>https://community.plus.net/t5/My-Router/Hub-2-Lax-Admin-Security/m-p/1903155#M34375</guid>
      <dc:creator>MisterW</dc:creator>
      <dc:date>2022-12-23T10:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: Hub 2 -- Lax Admin Security?</title>
      <link>https://community.plus.net/t5/My-Router/Hub-2-Lax-Admin-Security/m-p/1903171#M34376</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/44959"&gt;@madra&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;....It still seems very lax from a security point of view.&amp;nbsp; &lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Seeing as BT hubs plus I suspect many others the same there are literally millions of devices across the country with your definition of lax security.&lt;/P&gt;
&lt;P&gt;Fortunately if this bothers you there is no restriction to you getting your own third party hub.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Dec 2022 14:15:00 GMT</pubDate>
      <guid>https://community.plus.net/t5/My-Router/Hub-2-Lax-Admin-Security/m-p/1903171#M34376</guid>
      <dc:creator>Baldrick1</dc:creator>
      <dc:date>2022-12-23T14:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: Hub 2 -- Lax Admin Security?</title>
      <link>https://community.plus.net/t5/My-Router/Hub-2-Lax-Admin-Security/m-p/1903178#M34377</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/1110"&gt;@MisterW&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;you might be able to look at some basic information but you can't 'do' anything without logging in&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Without logging in I can see what model router I'm using and what its firmware version is. I can also see a list of every device connected to my network along with their internal IP number.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both of those are security risks. There are plenty of sites [both well- and ill-intentioned] out there which publish lists of exploits for various software / firmware on various devices. Usually a ne'er-do-well would have to probe the system, looking for open ports and trying to deduce what devices were behind them on which IPs and then try a range of exploits. This hub basically removes one of those obstacles by openly listing everything attached to the network and giving its IP. So now the miscreant has a nice list of devices to check aginast his stash of exploits.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/38823"&gt;@Baldrick1&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Fortunately if this bothers you there is no restriction to you getting your own third party hub.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Oh dear.&amp;nbsp; Someone always has to play the &lt;EM&gt;'If you don't like it. Make your own'&lt;/EM&gt; card. The non-thinker's response to any criticism of anything.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Dec 2022 16:09:57 GMT</pubDate>
      <guid>https://community.plus.net/t5/My-Router/Hub-2-Lax-Admin-Security/m-p/1903178#M34377</guid>
      <dc:creator>madra</dc:creator>
      <dc:date>2022-12-23T16:09:57Z</dc:date>
    </item>
    <item>
      <title>Re: Hub 2 -- Lax Admin Security?</title>
      <link>https://community.plus.net/t5/My-Router/Hub-2-Lax-Admin-Security/m-p/1903181#M34378</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/44959"&gt;@madra&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No, just being realistic.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Dec 2022 16:19:49 GMT</pubDate>
      <guid>https://community.plus.net/t5/My-Router/Hub-2-Lax-Admin-Security/m-p/1903181#M34378</guid>
      <dc:creator>Baldrick1</dc:creator>
      <dc:date>2022-12-23T16:19:49Z</dc:date>
    </item>
    <item>
      <title>Re: Hub 2 -- Lax Admin Security?</title>
      <link>https://community.plus.net/t5/My-Router/Hub-2-Lax-Admin-Security/m-p/1903182#M34379</link>
      <description>&lt;P&gt;&lt;EM&gt;&lt;SPAN&gt;Without logging in I can see what model router I'm using and what its firmware version is. I can also see a list of every device connected to my network along with their internal IP number.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt; ut you have to be connected&amp;nbsp; to the local network to access the router at all . So someone trying to obtain that information&amp;nbsp; must be physically connected&amp;nbsp; to a lan port or have used the wireless password to connect&lt;/P&gt;</description>
      <pubDate>Fri, 23 Dec 2022 16:20:11 GMT</pubDate>
      <guid>https://community.plus.net/t5/My-Router/Hub-2-Lax-Admin-Security/m-p/1903182#M34379</guid>
      <dc:creator>MisterW</dc:creator>
      <dc:date>2022-12-23T16:20:11Z</dc:date>
    </item>
    <item>
      <title>Re: Hub 2 -- Lax Admin Security?</title>
      <link>https://community.plus.net/t5/My-Router/Hub-2-Lax-Admin-Security/m-p/1903193#M34380</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/44959"&gt;@madra&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The thing is there are plenty of free tools available which can display the data you are worried about hiding without the need to have access to the Hubs home page&lt;/P&gt;
&lt;P&gt;Once connected to your LAN I can use:-&lt;/P&gt;
&lt;P&gt;&lt;A href="https://whatismyipaddress.com/" target="_self"&gt;https://whatismyipaddress.com/&lt;/A&gt;&amp;nbsp;- displays your public IP address&lt;/P&gt;
&lt;P&gt;Android app "Network Analyser Pro"&lt;/P&gt;
&lt;P&gt;Using "LAN scan" I can list all the active devices IP Addresses &lt;SPAN&gt;and hostname&amp;nbsp;&lt;/SPAN&gt;connected to your LAN .&lt;/P&gt;
&lt;P&gt;Android "WiFi Analyzer"&lt;/P&gt;
&lt;P&gt;I can list all the local wireless network and list security used and if WPS is enabled without the need to be connected to your LAN.&lt;/P&gt;
&lt;P&gt;The connection speed could be determined using a speed test.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Dec 2022 17:36:17 GMT</pubDate>
      <guid>https://community.plus.net/t5/My-Router/Hub-2-Lax-Admin-Security/m-p/1903193#M34380</guid>
      <dc:creator>Dan_the_Van</dc:creator>
      <dc:date>2022-12-23T17:36:17Z</dc:date>
    </item>
  </channel>
</rss>

