Welcome Guest ( Log In | Register )

Bump Topic Topic Closed RSS Feed

Outline · [ Standard ] · Linear+

Unifi WARNING TO ALL UNIFI USERS, Threat warning, read inside

views
     
schmeichel7
post Jun 3 2010, 12:05 AM

The JERSEYMAN
Group Icon
Elite
2,475 posts

Joined: Jan 2003
From: Shah Alam


When I got my unifi installed last month.. I tweaked around the router (to change the DHCP addressing etc etc) and I notice the remote management feature is enabled by default.. Luckily I've turned it off ever since.. because I know, there is no need to remotely configure it since I can do so directly... Phewww...

Thanks rizvanrp for the info.
schmeichel7
post Jun 3 2010, 01:37 AM

The JERSEYMAN
Group Icon
Elite
2,475 posts

Joined: Jan 2003
From: Shah Alam


Actually for every user... don't be lazy.. one thing they should do is always change the default admin password for the router and also the default settings for other features (such as the WIFI hotspot WPA key).

Lucky for me because I decided to disable the 'Remote Management' feature earlier after they've installed the unifi equipment at my home after I noticed this:

user posted image

When it says "or set 0.0.0.0 to allow access to any computer on the Internet'... That made me worry and straight away I decided to disable it. Lucky me because I decided to play around with the router and change the WPA Wifi password and the admin password as well.. Funnily though, there is another message in the picture above that reminds us "For security reasons, it is recommended that you change the login password for the admin accounts"

The intentions are noble. TM created an account that can be used to remotely access by the TM staff for troubleshooting purposes. But two big mistakes were made by TM which were:

1. Customer was not told about this up front (existence of another secondary account)
2. Customer was not given the option to change the password for this secondary account (how would they even know it exists since it can't be seen by the default admin userID)

You feel a bit cheated after finding out all this..

schmeichel7
post Jun 3 2010, 01:59 AM

The JERSEYMAN
Group Icon
Elite
2,475 posts

Joined: Jan 2003
From: Shah Alam


It is a shame on how this was not planned properly....

And I'm not surprised that TM quickly released that statement to safeguard their business and potential future customers.. Who wants to subscribe to unifi if they feel insecure and worried due to the risks..

If only they planned things properly in the first place.. Remote support can be done in a proper way..

This post has been edited by schmeichel7: Jun 3 2010, 02:00 AM

Topic ClosedOptions
 

Change to:
| Lo-Fi Version
0.0203sec    0.34    7 queries    GZIP Disabled
Time is now: 2nd December 2025 - 08:50 AM