Like every other website on the planet, SmallNetBuilder uses cookies. Our cookies track login status, but we only allow admins to log in anyway, so those don't apply to you. Any other cookies you pick up during your visit come from advertisers, which we don't control.
If you continue to use the site, you agree to tolerate our use of cookies. Thank you!

Router Charts

Click for Router Charts

Router Ranker

Click for Router Ranker

NAS Charts

Click for NAS Charts

NAS Ranker

Click for NAS Ranker

More Tools

Click for More Tools

NAS How To

Finding a back door

A quick port-scan looking for open ports showed nothing of interest. Searching through all of the standard menus was fruitless as well. It was time to get creative.

A standard technique for accessing the internals of device such as these is to look for back doors. Developers of these devices need easy visibility into the running system and often leave a way to get in or to run tests. Sometimes this requires special development hardware, but it is also common for developers to get into the device through the a network connection.

The obvious place to start looking was in the web interface. I had noticed that all of the Administration menus were in a web subdirectory named Management. Since I knew that webservers can provide a listing of the contents of a directory depending on the webserver configuration, I decided to try this simple exploit by typing http://192.168.3.77/Management/ into my web browser. Bingo! I was rewarded with a complete listing of all of the files in the directory.

NOTE!Ed. Note: This directory listing ability has been removed as of the V2.3R25 NSLU2 firmware

Included in the list of jpg and html files was a little gem called telnet.cgi. Step one complete. A potential back door discovered. Execution of the script showed the following screen:

Figure 2: Telnet enable screen

Disregarding the warning, I pushed the "Enable Telnet" button. The web page refreshed and I was greeted with the same screen except the message indicated that Telnet was now enabled! One step closer...

More NAS

Wi-Fi System Tools
Check out our Wi-Fi System Charts, Ranker and Finder!

Support Us!

If you like what we do and want to thank us, just buy something on Amazon. We'll get a small commission on anything you buy. Thanks!

Over In The Forums

I own a home in Colorado and a second home in Utah. I'm considering creating a site to site vpn between the homes. I'm not that concerned about hiding...
Update 2020/12/01(9.0.0.4.386.41157)https://drive.google.com/drive/folders/1D4X3k9GXxkiRQkaO1huQGnCAsQeIvokC?usp=sharingThis version inclouds ZenWiFi:...
Hmmmmmrunning 384.19 on an rt-ac86u in access point mode. And I looked at the wireless logs.the log says the device is offline. But it’s not. WemoBack...
Hi All,I know the stock Asus firmware does not "publish" out the configured client names for DHCP clients. I presume neither does Merlin FW?I am waiti...
I have four Etekcity/VeSync smart wall plugs that I use for various lights in the house, and for the most part they work as intended, but they go offl...

Don't Miss These

  • 1
  • 2
  • 3