• November 01, 2024, 10:28:18 AM
  • Welcome, Guest
Please login or register.

Login with username, password and session length
Advanced search  

News:

This Forum Beta is ONLY for registered owners of D-Link products in the USA for which we have created boards at this time.

Author Topic: How to block internet admin login? Its open to the world!!  (Read 4929 times)

cuban_cigar

  • Level 1 Member
  • *
  • Posts: 1
How to block internet admin login? Its open to the world!!
« on: December 03, 2013, 01:31:04 AM »

I entered the external IP address to my network as assigned by my ISP and was absolutely floored to find that not only was the router login screen visible from the internet, it has the model and firmware version number clearly displayed.

A gaping mile-wide security hole.

Also, there seemed to be no documentation regarding how to disable/ turn off/ kill the wan (internet) login.


I got this router last year, a DIR-651. D-link considers this "end of life", which is odd.

How might I go about turning off WAN admin login?


This security flaw is going to be the ruin of me, and everyone who has a router.



When I comment on Wikipedia, people can LITERALLY get right to my router with just one click on the convenient IP hyperlink. A child could crack through the router like it was nothing this way, the vulnerabilities for any model are cataloged over time for easy exploitation. The internet must be prevented from even seeing that it's a router.


Look, they even published my IP, here... it's open season!

~wondering why
« Last Edit: December 03, 2013, 01:57:25 AM by cuban_cigar »
Logged

RYAT3

  • Level 10 Member
  • *****
  • Posts: 2254
Re: How to block internet admin login? Its open to the world!!
« Reply #1 on: December 03, 2013, 05:02:27 AM »

There should be an option in there to turn it off.

Anyways, only admin can see your posts ip address.

I cannot see it.
Logged

Herschel51

  • Level 1 Member
  • *
  • Posts: 1
Re: How to block internet admin login? Its open to the world!!
« Reply #2 on: January 01, 2014, 08:26:06 PM »

Thanks for sharing.
Logged

gerritv

  • Level 1 Member
  • *
  • Posts: 23
Re: How to block internet admin login? Its open to the world!!
« Reply #3 on: January 04, 2014, 09:36:06 AM »

You could try reading the manual, it will tell you how to disable Remote Admin. That would have taken less time than it took you to type your comments :-)

Logged

FurryNutz

  • Poweruser
  •   ▲
    ▲ ▲
  • *****
  • Posts: 49923
  • D-Link Global Forum Moderator
    • Router Troubleshooting
Re: How to block internet admin login? Its open to the world!!
« Reply #4 on: January 10, 2014, 08:31:22 AM »

FYI, this is not a security flaw as other Mfr routers including D-Link has this feature. It's disabled by default. This is a feature of many networking products out there. It's up to users to decide weather to use it or not.

Many users enjoy using this to help manage there products from remote locations. If you care concerned about this, then disable it if it's enabled. Also ensure that your local LAN side admin account PW is safe and secure and no body else has it.
Logged
Cable: 1Gb/50Mb>NetGear CM1200>DIR-882>HP 24pt Gb Switch. COVR-1202/2202/3902,DIR-2660/80,3xDGL-4500s,DIR-LX1870,857,835,827,815,890L,880L,868L,836L,810L,685,657,3x655s,645,628,601,DNR-202L,DNS-345,DCS-933L,936L,960L and 8000LH.