Ads skipped

US Government to BanTP-Link Devices - Live Hacking of a Chinese WiFi Router

2M views · Dec 20, 2024 · Science & Technology

Comments · 4K

  • @mattbrwn · 1 year ago · pinned

    What do you guys think? Is this ban targeting one company when others have the same issue? Let me know!

    684

  • @JonitoFischer · 1 year ago

    The solution is simple, instead of banning tp-link, you should enforce an open source driver policy, so their SoCs can be mainlined in Linux kernel or BSDs kernels,  so anybody can build an alternative open source firmware like OpenWRT. If you don't trust the device maker, then you install the OS of your choice and manage your device the way you want.

    4.5K

  • @davenone8516 · 1 year ago

    The real question is do the politicians demanding a ban have a financial stake in a competitor.

    1.4K

  • @birdetta · 1 year ago

    I've found significant 0day vulnerabilities in SOHO routers from every vendor. Almost always it's classic 101 stuff, like unprotected password reset pages or firmware flashing MITM attacks. I don't see how TP Link is special. Don't trust any vendor's home router.

    1.2K

  • @3_Dogs_In_A_Trench_Coat · 1 year ago

    Pro-tip: before taking  the thing apart look at the manual. Admin name and password are usually printed there. TBF the manual also recommends you to change them both ASAP.

    43

  • @KaiNoMood · 1 year ago (edited)

    This video doesn&apos;t actually expose a vulnerability in the TP-Link device. Instead, it highlights how improper router configurations—likely due to user error—can lead to security issues.<br><br>Exposing the router&apos;s telnet or HTTP services to the WAN interface isn&apos;t even enabled by default on these devices. The fact that it can be done isn&apos;t a vulnerability; it&apos;s a configurable feature that can be useful in specific cases, as long as it&apos;s not exposed to a public network.

    993

  • @dmtsza · 1 year ago (edited)

    This video did NOT show any exploit. What it shows is that some users are not changing the default password and exposing the router web admin interface to the WAN interface (which can then be accessed remotely with the default user/password). For this you do not need UART nor flash dump.

    735

  • @everytoolashammer9427 · 1 year ago

    Bro made a YouTube video that taught what took me years of interweb learning. I wish stuff like this was around when I was learning. Great stuff.

    186

  • @azrios · 1 year ago

    Thanks for the video. &nbsp;Matt, what routers would you suggest using?

    4

  • @FrançoisVictor-w3n · 1 year ago

    To find the default password of any device my prefered method is reading the manual and not desoldering the flash ROM, extracting the embedded filesystem and then cracking the password hash.

    227

  • @barry3602 · 1 year ago

    It&apos;s not about just the &apos;security vulnerabilities&apos;, it&apos;s because of security vulnerabilities that doesn&apos;t benefit the US National Security Agency to be exploited.

    241

  • @redroc24x7 · 1 year ago

    Great vid, have you looked into the TP link smart plugs for a similar issue?

Up next

LIVE

Affordable, Simple Compute. Built for Everyone!

Vicharak · 78K views

LIVE

Extracting Firmware from a Chinese Security Camera - Hacking the Anran IP Camera

Matt Brown · 42K views

LIVE

Hacking an AT&T 4G Router For Fun and User Freedom

Matt Brown · 776K views

LIVE

It's Over: Bonds COLLAPSE to WORST Levels Since 2002 - Netherlands BANS Microsoft

House of El · 229K views

LIVE

He Built a Privacy Tool. Now He’s Going to Prison.

Naomi Brockwell TV · 1M views

LIVE

My Dream Power Hammer Restoration! Part 10

Alec Steele · 1M views

LIVE

Have you been hacked? Hacker explains how to find out!

David Bombal · 393K views

LIVE

Is TP-Link Spying on You? The REAL Story Behind the US Ban Investigation

Crosstalk Solutions · 132K views

LIVE

Every Level of Reverse Engineering Explained

Low Level · 582K views

LIVE

The Current State of Siri AI

SAMTIME · 87K views

LIVE

DEF CON 32 - Inside the FBI’s Secret Encrypted Phone Company ‘Anom’ - Joseph Cox

DEFCONConference · 1.7M views

LIVE

In-Circuit eMMC Firmware Extraction - Hacking a Car Diagnostic Scanner

Matt Brown · 68K views

LIVE

Border Officials Asks For My Phone. These 4 Setups Decide What They Get

Rob Braxman Tech · 210K views

LIVE

Something BIG Just Happened Over Lithuania… NATO Takes EMERGENCY ACTION

The Frontline Show · 131K views

LIVE

Hacking a Motorola Automatic License Plate Reader - Firmware Extraction and Password Cracking

Matt Brown · 274K views

LIVE

OpenAI's AI Agents Secretly Organized. Then They Attacked.

Chief Agent Officer · 363 views

LIVE

The Insane Real Engineering of the Nazi Enigma Machine

Veritasium · 13M views

LIVE

American Mind Blown by European Bus Driver Skill & Maneuvers

IWrocker · 34K views

LIVE

Complete DARK WEB Explained: Crime, Cybersecurity & the Hidden Internet

Ismail · 464K views

LIVE

Why a Magnet Doesn't Actually Run Out of Energy

Sleep On Physics · 124K views

LIVE

Every Confusing Thing About How Antennas Work Explained Slowly (For Sleep)

Cosmo Explains · 38K views

LIVE

The US Government Just Banned this Chinese Security Camera - Let's Hack It

Matt Brown · 277K views

LIVE

DEF CON 32 - From getting JTAG on the iPhone 15 to hacking Apple's USB-C Controller - Stacksmashing

DEFCONConference · 584K views

LIVE

How Passwords Work and How to Hack Them: From DES to ZIP

Dave's Garage · 240K views

LIVE

The Ridiculous Engineering Of Jet Engines

Veritasium · 15M views

LIVE

I HACKED my Internet Service Provider's router. So I could get rid of it.

Tomaž Zaman · 2.3M views

YouTube, with the door locked.

Aegis plays a clean stream instead of YouTube's player, so pre-roll ads, trackers, and fingerprinting never ride along. Drop Shields any time if you want the official player back.