Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


Port scanning...

 
Post new topic   Reply to topic    Cheat Engine Forum Index -> Computer Talk
View previous topic :: View next topic  
Author Message
Localhost
I post too much
Reputation: 0

Joined: 28 Apr 2007
Posts: 3402

PostPosted: Wed Apr 23, 2008 9:05 pm    Post subject: Port scanning... Reply with quote

Okay i port scanned this server, and i tried all the ip:port combinations... The last one i tried shocked me. It was sort of like a .htaccess login thing... But the weird thing is, i think it was the servers router!

It sayed WRT54GL (Linksys Router) at http://<ip>:<port>

I gasped in amazement when i saw this.

Can you say exploit?

_________________
Back to top
View user's profile Send private message MSN Messenger
Psy
Grandmaster Cheater Supreme
Reputation: 1

Joined: 27 Mar 2008
Posts: 1366

PostPosted: Thu Apr 24, 2008 2:27 am    Post subject: Reply with quote

Its nothing super special.
Port 80 is open on a hell of a lot of routers nowadays, especially home cable/dsl ones. So you can access the web config pages from the WAN side.
Even more worryingly is that a lot of times, the default passwords are used, so its obvious what you can do from that stage...

Also, on more crappy routers, you will get a port open in the 3xxx range.
This was originally designed to give the router manufacturer a way into your router at any given time, provided they new your IP, so they could troubleshoot for you. It would use a built-in account called tech.
There is no other way to close this port other than to create a port forwarding rule, and make it throw all traffic to a fake LAN IP, therefore dropping the packets. Interesting....
Back to top
View user's profile Send private message
Localhost
I post too much
Reputation: 0

Joined: 28 Apr 2007
Posts: 3402

PostPosted: Thu Apr 24, 2008 4:27 am    Post subject: Reply with quote

Its actually port 8080. I thought it was kind of rare/stupid for that to happen. I cant wait to i find out his password Razz
_________________
Back to top
View user's profile Send private message MSN Messenger
Psy
Grandmaster Cheater Supreme
Reputation: 1

Joined: 27 Mar 2008
Posts: 1366

PostPosted: Thu Apr 24, 2008 4:45 am    Post subject: Reply with quote

Yeah 8080, common proxy port...
Back to top
View user's profile Send private message
Localhost
I post too much
Reputation: 0

Joined: 28 Apr 2007
Posts: 3402

PostPosted: Thu Apr 24, 2008 4:53 am    Post subject: Reply with quote

but its not Apache thats running on that port... Its his router! Like you know how you go in and type 192.168.1.1 and you go to your router? Well i can type <ip>:<port> and i get to his router... Sorry if you already understood that Razz
_________________
Back to top
View user's profile Send private message MSN Messenger
Psy
Grandmaster Cheater Supreme
Reputation: 1

Joined: 27 Mar 2008
Posts: 1366

PostPosted: Thu Apr 24, 2008 5:06 am    Post subject: Reply with quote

Yeah I know what you mean... its not difficult, or new..and I doubt you can do much in the way of getting further into his network. Maybe fk up his settings but that'll be it.
I'm a network engineer by trade, so yeah, I'm well aware..
Back to top
View user's profile Send private message
Localhost
I post too much
Reputation: 0

Joined: 28 Apr 2007
Posts: 3402

PostPosted: Thu Apr 24, 2008 5:08 am    Post subject: Reply with quote

Hmm, What if i find out his computers IP (like 192.168.x.x) and open that to the internet?
_________________
Back to top
View user's profile Send private message MSN Messenger
Psy
Grandmaster Cheater Supreme
Reputation: 1

Joined: 27 Mar 2008
Posts: 1366

PostPosted: Thu Apr 24, 2008 6:32 am    Post subject: Reply with quote

Stick it in a DMZ... Razz

That would allow it to be accessed from the web, but then of course the appropriate ports must be open on the PC itself... if there is a firewall on there then there is still another line of defence.

I'm not gonna discuss this anymore, its hacking... but yeah, from that point an attacker is in a pretty good position.
Back to top
View user's profile Send private message
Cheetah
I post too much
Reputation: 0

Joined: 11 Nov 2007
Posts: 2758

PostPosted: Thu Apr 24, 2008 12:58 pm    Post subject: Reply with quote

Nice find Razz
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> Computer Talk All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites