DrayTek Vigor revovery password

A funny thing happened at the office the other day.

We have a teleworker who works in regional NSW. She connects via VPN to our Sydney office – we have Draytek Vigor 2800 VG's at each end.

For some reason, her line was disconnected (some sort of Telstra clerical error) and once that was sorted, she was given a new ISP password by Telstra.

Problem is, she had forgotten the password for the router. No, worries – just do a factory reset was the initial thought, but with so many settings needed to be re-entered, it would have been a real pain.

Whilst we were rummaging through our records to find the password, she called Draytek and they asked her for the MAC address of the unit and then gave her a password (about 6 characters, I think) which logged her in.

So it would seem that Draytek have a "backdoor" password – probably a hash on the MAC address or something of that ilk.

I've done some googling and can't find any mention of this for the Draytek or any other routers.

Is this common ? I guess it's not too much of a security issue, as firstly you'd need to know the MAC address, and secondly once you had the MAC address, you'd need to either have access to the LAN / wireless to login (unless remote management was enabled!).

Handy to know, regardless.

EDIT : Here's a thought... with a few calls to Draytek I could get the "hash" password for multiple addresses and probably derive the hash algorithm. Probably a question for a cryptography expert to comment on the viability, but it does leave me a little concerned.

http://forums.whirlpool.net.au/archive/1317036

https://github.com/ammonium/draytools

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值