YoVDO

I Hunt TR-069 Admins - Pwning ISPs Like a Boss

Offered By: 44CON Information Security Conference via YouTube

Tags

44CON Courses Cybersecurity Courses Network Security Courses Ethical Hacking Courses

Course Description

Overview

Explore the rising trend of residential gateway exploitation and the vulnerabilities in TR-069/CWMP, the de-facto CPE device management protocol, in this 33-minute conference talk from 44CON Information Security Conference. Delve into the previously under-researched Auto Configuration Server (ACS) software, which controls entire fleets of consumer premises devices for ISPs and Telco providers. Discover how compromising these servers can impact critical numbers of users. Examine several TR-069 ACS platforms, revealing instances of poorly secured deployments that could potentially grant control over hundreds of thousands of devices. Learn about exploits for vulnerabilities discovered in ACS software, including remote code execution on multiple platforms. Gain insights into the security landscape of SOHO routers and the potential risks associated with TR-069 protocol implementation.

Syllabus

I Hunt TR-069 Admins: Pwning ISPs Like a Boss - Presented By Shahar Tal


Taught by

44CON Information Security Conference

Related Courses

Supply Chain Unchained - How To Be A Bad SaaS
44CON Information Security Conference via YouTube
Aviation Security 101
44CON Information Security Conference via YouTube
The Anti-Checklist Manifesto
44CON Information Security Conference via YouTube
Why Are We Still Doing Authentication Wrong?
44CON Information Security Conference via YouTube
What Do Hackers See When They Look at the Clouds
44CON Information Security Conference via YouTube