A Progammer explores the IT Security field; offering packets of useful information he picks up along the way.
Subscribe

Archive for the ‘Wireless Security’

“WarWalking”

April 06, 2009 By: Ron Category: Wireless Security No Comments →

I was outside yesterday enjoying the weather with my IPOD touch and decided to see what wireless networks were available to me.  I found an SSID with the name “Linksys” and connected to the network.  I then opened up the Safari mobile browser and went to http://192.168.1.1 which is how one configures a router. I was prompted for a Username and Password. The SSID of “Linksys” is the default SSID that is pre-programmed on all Linksys routers. This tells me that the person who hooked up this Linksys router most likely just took it out of the box and connected it to the Internet without changing the default settings.  One way to confirm that … back at the username/password screen I tried a username of “admin” and password of “secret” and I was in.  See screenshot below.

router_safari

Ohhh man, the headaches I could have inflicted by changing some simple settings, not to mention the potentially dangerous security breaches I could have caused to anyone accessing the Internet connected to this router either wired or wirelessly.  It’s good for them that I’m a WhiteHat. Some people just have no clue!!!