I Hunt TR-069 Admins - Pwning ISPs Like a Boss
Offered By: 44CON Information Security Conference via YouTube
Course Description
Overview
Explore the rising trend of residential gateway exploitation and the vulnerabilities in TR-069/CWMP, the de-facto CPE device management protocol, in this 33-minute conference talk from 44CON Information Security Conference. Delve into the previously under-researched Auto Configuration Server (ACS) software, which controls entire fleets of consumer premises devices for ISPs and Telco providers. Discover how compromising these servers can impact critical numbers of users. Examine several TR-069 ACS platforms, revealing instances of poorly secured deployments that could potentially grant control over hundreds of thousands of devices. Learn about exploits for vulnerabilities discovered in ACS software, including remote code execution on multiple platforms. Gain insights into the security landscape of SOHO routers and the potential risks associated with TR-069 protocol implementation.
Syllabus
I Hunt TR-069 Admins: Pwning ISPs Like a Boss - Presented By Shahar Tal
Taught by
44CON Information Security Conference
Related Courses
Computer SecurityStanford University via Coursera Cryptography II
Stanford University via Coursera Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera Building an Information Risk Management Toolkit
University of Washington via Coursera Introduction to Cybersecurity
National Cybersecurity Institute at Excelsior College via Canvas Network