South Africa’s biggest forum. Discuss, discover, and connect with thousands of members.
LOL.Maybe we'll find another way yet. I'm perplexed why they removed it from the firmware.
I think this is a time to give up. This router is completely unbalanced package, beefing up remote access security and forgetting about basic functionality. It is shipped with hidden master SSH password which is not accessible nor changeable by the user. Now, if SSH is also accessible from the WAN interface, it raise various concerns of security and purpose of such design.Tried the FTP exploit quickly.
I can create user accounts (with arbitrary names + passwords) for use on the B593's FTP server.
Either I don't understand what you wrote here, or you don't understand how important is this issue. I personaly don't feel comfortable if someoe knows secret password to access my device remotely.The B593 can go behind other security devices so it shouldn't be an issue ito. security.
Now I am sure you don't understand the issue. Person who knows secret SSH password can do everything with your Internet data. Such a person can do phishing (forging DNS server setting and redirecting your traffic in order upload malware to computers on your LAN), monitor your traffic, even reprogram device with special spyig firmware, etc. Disabling Internet/device temporary or permanent - of course - not really security concern.What will they do? Disable your internet? From there they can go no further into my* network.
*Said generally, since I don't make use of security appliances.
Then don't take a stand. Surely you can do something, but you are trying in reverse - to promote such products.I'm no networking expert but surely something can be done to take care of that?
I think this is a time to give up. This router is completely unbalanced package, beefing up remote access security and forgetting about basic functionality. It is shipped with hidden master SSH password which is not accessible nor changeable by the user. Now, if SSH is also accessible from the WAN interface, it raise various concerns of security and purpose of such design.
I don't talk about exploits. I am about purpose of hidden master SSH password. If it is in purpose (which I don't doubt for a moment), then obviously router's internal firewall is also prepared to pass remote requests.Both exploits have been shown to exist on some of the other/earlier B593 firmware versions.
Then don't take a stand. Surely you can do something, but you are trying in reverse - to promote such products.
... I am about purpose of hidden master SSH password. If it is in purpose (which I don't doubt for a moment), then obviously router's internal firewall is also prepared to pass remote requests.
It is about you. Not personal, but obvious conclusion based on your post.What are you talking about comrade?
I agree on #1 to #3, but can't argue who 'bad' guys are, I don't know. Many things are designed on the event of future war, some other affect our lives now. It is not about vulnerability or 'weakness', it is about design. They take preference on hidden access to your device and have no space for Cell_ID indicator. This is what I am talking about.Huawei have often been accused of having such nefarious intentions - read this for example.
But as in that article, the "bad guys" are not actually Huawei themselves, but more the NSA.
We have a thread. It is about extraordinary expensive device with limited functionality (in addition to hidden master password for remote access). Limitations are so serious, that to properly allign roof antenna people are adviced to borrow less expensive LTE device."The B593 conspiracy thread" - can someone create this?