<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Time Warner cable modem/router major security hole</title>
	<atom:link href="http://chenosaurus.com/2009/10/20/time-warner-cable-modemrouter-major-security-hole/feed/" rel="self" type="application/rss+xml" />
	<link>http://chenosaurus.com/2009/10/20/time-warner-cable-modemrouter-major-security-hole/</link>
	<description>startups, software, skateboarding</description>
	<lastBuildDate>Thu, 05 Nov 2009 00:37:08 +0100</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: skeptikal</title>
		<link>http://chenosaurus.com/2009/10/20/time-warner-cable-modemrouter-major-security-hole/comment-page-1/#comment-41</link>
		<dc:creator>skeptikal</dc:creator>
		<pubDate>Thu, 05 Nov 2009 00:37:08 +0000</pubDate>
		<guid isPermaLink="false">http://chenosaurus.com/?p=55#comment-41</guid>
		<description>This might actually be a big deal.. except you still have to log in to the GUI before you use the exploit.
As for why TW is even turning on the public-facing login, I have no idea.</description>
		<content:encoded><![CDATA[<p>This might actually be a big deal.. except you still have to log in to the GUI before you use the exploit.<br />
As for why TW is even turning on the public-facing login, I have no idea.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://chenosaurus.com/2009/10/20/time-warner-cable-modemrouter-major-security-hole/comment-page-1/#comment-36</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Tue, 27 Oct 2009 14:30:01 +0000</pubDate>
		<guid isPermaLink="false">http://chenosaurus.com/?p=55#comment-36</guid>
		<description>Does this mean disabling Javascript in Firefox OR Internet Explorer while connecting to the device?</description>
		<content:encoded><![CDATA[<p>Does this mean disabling Javascript in Firefox OR Internet Explorer while connecting to the device?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gaping security hole in Time Warner cable routers &#124; War On You: Breaking Alternative News</title>
		<link>http://chenosaurus.com/2009/10/20/time-warner-cable-modemrouter-major-security-hole/comment-page-1/#comment-33</link>
		<dc:creator>Gaping security hole in Time Warner cable routers &#124; War On You: Breaking Alternative News</dc:creator>
		<pubDate>Tue, 27 Oct 2009 03:38:49 +0000</pubDate>
		<guid isPermaLink="false">http://chenosaurus.com/?p=55#comment-33</guid>
		<description>[...] Chen explains: After poking around using the customer account, I found that access to the admin features of the router has been disabled via Javascript. You heard me correct, the web admin for the router simply uses a script to hide certain menu options when the user does not have admin privileges. By simply disabling Javascript in the browser, I was able to access all the features of the router. With that access, I am now able to change the wifi settings, port-forwarding, etc. [...]</description>
		<content:encoded><![CDATA[<p>[...] Chen explains: After poking around using the customer account, I found that access to the admin features of the router has been disabled via Javascript. You heard me correct, the web admin for the router simply uses a script to hide certain menu options when the user does not have admin privileges. By simply disabling Javascript in the browser, I was able to access all the features of the router. With that access, I am now able to change the wifi settings, port-forwarding, etc. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Some Time Warner Cable modems have major security flaw - The Gadgetress - OCRegister.com</title>
		<link>http://chenosaurus.com/2009/10/20/time-warner-cable-modemrouter-major-security-hole/comment-page-1/#comment-28</link>
		<dc:creator>Some Time Warner Cable modems have major security flaw - The Gadgetress - OCRegister.com</dc:creator>
		<pubDate>Mon, 26 Oct 2009 23:25:02 +0000</pubDate>
		<guid isPermaLink="false">http://chenosaurus.com/?p=55#comment-28</guid>
		<description>[...] The SMC8014WG-SI, used by an untold number of Time Warner Cable customers, has a serious security hole that &#8220;allows anyone to access your private network and possibly capture and manipulate your private data,&#8221; according to David Chen, who blogs about the breach at Chenosaurus.com. [...]</description>
		<content:encoded><![CDATA[<p>[...] The SMC8014WG-SI, used by an untold number of Time Warner Cable customers, has a serious security hole that &#8220;allows anyone to access your private network and possibly capture and manipulate your private data,&#8221; according to David Chen, who blogs about the breach at Chenosaurus.com. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: my california adventures - startups, software, skateboarding</title>
		<link>http://chenosaurus.com/2009/10/20/time-warner-cable-modemrouter-major-security-hole/comment-page-1/#comment-26</link>
		<dc:creator>my california adventures - startups, software, skateboarding</dc:creator>
		<pubDate>Mon, 26 Oct 2009 05:43:28 +0000</pubDate>
		<guid isPermaLink="false">http://chenosaurus.com/?p=55#comment-26</guid>
		<description>[...] received incredible response from the  Time Warner modem/router security issue I wrote about last week.  It was immediately picked up by Wired, Cnet, PC World, Consumerist, and [...]</description>
		<content:encoded><![CDATA[<p>[...] received incredible response from the  Time Warner modem/router security issue I wrote about last week.  It was immediately picked up by Wired, Cnet, PC World, Consumerist, and [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tasunke&#8217;s Random Ramblings / Major Time-Warner Modem/Router security flaw</title>
		<link>http://chenosaurus.com/2009/10/20/time-warner-cable-modemrouter-major-security-hole/comment-page-1/#comment-25</link>
		<dc:creator>Tasunke&#8217;s Random Ramblings / Major Time-Warner Modem/Router security flaw</dc:creator>
		<pubDate>Sat, 24 Oct 2009 08:28:43 +0000</pubDate>
		<guid isPermaLink="false">http://chenosaurus.com/?p=55#comment-25</guid>
		<description>[...] above. Words fail me at this point, so let me just quote the guy who found this, Dave, from his blog.   After poking around using the customer account, I found that access to the admin features of the [...]</description>
		<content:encoded><![CDATA[<p>[...] above. Words fail me at this point, so let me just quote the guy who found this, Dave, from his blog.   After poking around using the customer account, I found that access to the admin features of the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul</title>
		<link>http://chenosaurus.com/2009/10/20/time-warner-cable-modemrouter-major-security-hole/comment-page-1/#comment-24</link>
		<dc:creator>Paul</dc:creator>
		<pubDate>Fri, 23 Oct 2009 16:59:20 +0000</pubDate>
		<guid isPermaLink="false">http://chenosaurus.com/?p=55#comment-24</guid>
		<description>Sounds even worse than this problem! http://www.jibble.org/o2-broadband-fail/</description>
		<content:encoded><![CDATA[<p>Sounds even worse than this problem! <a href="http://www.jibble.org/o2-broadband-fail/" rel="nofollow">http://www.jibble.org/o2-broadband-fail/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gaping security hole in Time Warner cable routers &#171; The Daily Blahg</title>
		<link>http://chenosaurus.com/2009/10/20/time-warner-cable-modemrouter-major-security-hole/comment-page-1/#comment-23</link>
		<dc:creator>Gaping security hole in Time Warner cable routers &#171; The Daily Blahg</dc:creator>
		<pubDate>Fri, 23 Oct 2009 15:15:36 +0000</pubDate>
		<guid isPermaLink="false">http://chenosaurus.com/?p=55#comment-23</guid>
		<description>[...] disabling JavaScript in the browser to access hidden features in the router’s admin interface.  Chen explains: After poking around using the customer account, I found that access to the admin features of the [...]</description>
		<content:encoded><![CDATA[<p>[...] disabling JavaScript in the browser to access hidden features in the router’s admin interface.  Chen explains: After poking around using the customer account, I found that access to the admin features of the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: noted &#187; Blog Archive &#187; Only half the threat - and most of the answer.</title>
		<link>http://chenosaurus.com/2009/10/20/time-warner-cable-modemrouter-major-security-hole/comment-page-1/#comment-22</link>
		<dc:creator>noted &#187; Blog Archive &#187; Only half the threat - and most of the answer.</dc:creator>
		<pubDate>Fri, 23 Oct 2009 02:36:55 +0000</pubDate>
		<guid isPermaLink="false">http://chenosaurus.com/?p=55#comment-22</guid>
		<description>[...] be slashdotted. (Edit: no longer. I also indulged myself with a comment on the slashdot story and the blog post, both came late in the game. No, I&#8217;m not selling anything nor do I get ad revenue.)  In any [...]</description>
		<content:encoded><![CDATA[<p>[...] be slashdotted. (Edit: no longer. I also indulged myself with a comment on the slashdot story and the blog post, both came late in the game. No, I&#8217;m not selling anything nor do I get ad revenue.)  In any [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam Lipstadt</title>
		<link>http://chenosaurus.com/2009/10/20/time-warner-cable-modemrouter-major-security-hole/comment-page-1/#comment-21</link>
		<dc:creator>Adam Lipstadt</dc:creator>
		<pubDate>Fri, 23 Oct 2009 02:31:45 +0000</pubDate>
		<guid isPermaLink="false">http://chenosaurus.com/?p=55#comment-21</guid>
		<description>The way these things are deployed, you don&#039;t need to even bother cracking WEP.

http://www.lipstadt.com/noted/archives/120</description>
		<content:encoded><![CDATA[<p>The way these things are deployed, you don&#8217;t need to even bother cracking WEP.</p>
<p><a href="http://www.lipstadt.com/noted/archives/120" rel="nofollow">http://www.lipstadt.com/noted/archives/120</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
