@ archonixm/billytong
No offense but I don't want to address this issue anymore. I refuse to believe that by writing that wget comment as a joke (in response to the idiotic comment made in that news article) I've somehow compromised the security of routers on the network more than when I disclosed the vulnerability back in May. Infact, I posted a command that would not even work in an actual shell. If you believe that by only posting the current 'operator' passwords you've somehow prevented skiddies from doing what I described, you're absolutely wrong.
That's just how computer security works. It's fair game for both the vendors and the attackers when an exploit is published. The fact remains that TM/DLINK have had months to patch this/change their policy and they have not.
I'm not taking the blame for anything especially after the person who started all this shit basically revealed his butthurt 'I is get no credits for something I didnt do' mentality in his following posts. I'm not saying he didn't have a point, I'm just saying he screwed up his chance to have a mature discussion with me when he revealed that side of himself. I removed my initial post because I knew this is what it would come to but he decided to basically draft a MS Word document using a cached copy just to spite me.
If you have used any of my guides on the athena site, do not expect me to believe that it has never occurred to you an attacker could use that information to break into routers which are not secure. You can link an incomplete 'wget' command to a whole series of possible attacks but stuff like this did not occur to you when you were reading my earlier guides? Let me reiterate here : I posted a
full technical guide back in May which contains the
master password for all DIR-615 G1 routers so that you can secure your own router (you agreed that this is what I should do).. and you don't think people will use that information to attack other users? Do you now realize why I'm like "OH GOD MY HEAD ASPLODE" over here?
That's honestly why I'm questioning your logic and intentions here. I mentioned this back in May that it was a difficult decision.. but as Moogle put it, I felt the benefits of revealing such information far outweighed the bad (especially in a system where you are forced to use the buggy software/hardware). So I ask, where was all your paranoia then? There wasn't any; some troll just decided to vent his anger at me for not crediting him and you took the bait.
I have never written and published a tool to automate attacks on the Unifi network. I have never even described how to perform the attacks I said were possible on compromised routers (turning them into zombies/open proxies/whatever). Doing that would indeed be unnecessary and not beneficial to anyone. I'm a Unifi user myself and I understand your concerns. However from the security analyst point of view, many of you can't put yourselves in my shoes.
I cannot teach people how to protect themselves if I do not tell them what they're going up against. Do you know how many users ignored my advice to disable the remote management option because TM sent out an SMS 'encouraging' people to re-enable it? They assumed that they were safe simply because they changed the operator password however because I didn't make it a point to tell them that the remote management option was also an attack vector, they left it open as per TM's advice.
But at the end of the day, the sheer hypocrisy of using my knowledge to protect yourself then attacking me for distributing that information in the first place.. frankly just astounds me. Start asking TM why they're allowing such a terrible policy to continue instead of blaming me for exposing all of their problems (
to your benefit). You're asking me to do the impossible here for the most trivial of reasons, it's starting to become annoying and I hope you understand that.
I apologize if I offended anyone but that's basically what I'm feeling myself after reading these posts. It feels like I'm shouting at the world because they fail to notice something that is right in front of their eyes.
---
So using the logic some of you are condemning me with, with this single post alone, rexio has basically :
1) Made it known that Unifi is capped by the account type and there is no physical cap
2) That you will need to disconnect another user in order to use his account as your own
3) Made it clear that the attacker will use the typical Malaysian slang to express his delight in breaking into your router
4) Described in detail that TM will reset the session if you dual log as only one session is allowed at a time
In an attempt to prove a point to me, he has literally written a bloody blueprint here on port scanning the Unifi IP range, breaking into routers, extracting passwords, destroying the victims router and using his details to re-enter the Unifi network. I never described anything about breaking into the routers to increase your speed nor the effects of that in my post. I touched on how an IP address can be re-linked to its original account. I wonder how does rexio know this anyway because his 'layman' sounds pretty experienced *hint hint*.
Most of you who have read every post here from v1-v7 know that
nobody has ever posted such an in depth guide like this on 'increasing' your speed. We should TOTALLY add this on the frontpage as rexio's guide to illegally 'upgrading' your Unifi package speed. /s
Seriously, this is why I think all of this is a bloody joke.. and you want to support this moron's cause?
FYI, I've edited this post like 10 times and I'm actually laughing my ass off at 6.30am on a Sunday morning because I just noticed this.
@ Acrisius
TM is constantly adding new IP ranges for Unifi and not all of them have their reverse DNS pointer set yet .. so that's not really a sure fire way to figure out if someone is on Unifi

Hi Bro. Riz,
Thanks for sharing and guide me all the way to set up VLAN bridge, without your guide, my TM DIR-615 will not survive until now (2 months).
Also, I learnt how the internet security works. It's like martial arts, one learn how to protect him/herself (self defense). Only when ppl attack you then use your martial art to defend and counter attack to protect yourself.
I definitely support your guide and keep up your good work.