What's new

Security Issue - Access from wan wont ask credentials

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

rod

Occasional Visitor
I just discovered that when I enable web access to router settings from Wan, using default port 8080 and asus DDNS service, the router does not use the authentication, it allows you enter to the settings directly.

Fron inside my lan, on the other side, it asks for user and password.

I have the rmerlin 374.35_4 version installed
Also have entware installed lighttpd with PHP following this guide guide

I will investigate when I return home if it is related to lighttpd, to entware, to the firmware, to the modifications made on firewall-start or may be in the port forwarding.

If I get some hint, I will post it here. For the moment, I have unticked the option for remote administration on the 8080 port.

---update---
RMerlin is right, it was a cached credentials problem :p
I enabled again web access from WAN and the tryed from another machine and the login prompt was shown.
 
Last edited:
Make sure you close and reopen your web browser before accessing it, otherwise it might simply be your web browser automatically sending the cached login credentials.

I regularly access my (internal) development routers through WAN, and I'm always asked for my login credentials, so it's definitely working properly.
 

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top