Can sum1 crack my modem password?

headstrong

Expert Member
Joined
May 10, 2006
Messages
1,099
Reaction score
0
Hi

If I make my modem/router GUI username and password like 20 characters each, can sum1 still crack it? and if so how long?

Thanks
 
Unless there is a known security flaw with the router making it easy to bypass I have to wonder if anyone would bother trying knowing that there are so many easier targets available.
 
Yes, someone can still obtain it if they are able to do an ARP poisoning between your PC and the router. But if you use SSL (see if it says https:\\ instead of http:\\) then it's encrypted and they probably won't be able to get it.
 
everything is always crackable - even ssl won't save you. if its really secure then hackers will most likely give up long before and try another account that is less secure. ssl just gives you an encrypted tunnel - you can still push any attacks through that tunnel. it wont stop something like dictionary/brute force attacks.
 
You'll need quite some time to brute force SSL or SSH ;) The easiest would be to just ARP poison the network and create a fake SSL certificate :D
 
you dont need to crack the ssl key, if your router requires you to logon via SSL I can still run a brute force attack through the SSL tunnel - no SSL keys need to be attacked. All that SSL is doing is preventing any IPS/IDS's in the path from detecting my attack. Similiar with SSH - no need to crack the SSH key, I can just launch a dictionary attack.
 
True, you can still try to brute force SSL but I find it easier to intercept the traffic and fake the certificate. Then you have the key (since you generated it) and all the packets. :)

So, the general consensus is that they might be able to crack your password over time but they probably won't since it's less effort to just attack a network that doesn't use SSL.
 
Top
Sign up to the MyBroadband newsletter
X