Other nomination
Hacking Millions of Modems (and Investigating Who Hacked My Modem)
An authorization bypass in a major US ISP's business customer portal let any unauthenticated request succeed simply by being replayed, exposing roughly 700 REST endpoints on a reverse-proxied Spring backend. Swagger documentation reachable through a static-file routing quirk, plus a client-side encryption routine that signed device identifiers, allowed customer record lookup and read/write control of any subscriber modem by MAC address.
Record
- Researcher
- Sam Curry and @samwcyo
- Date
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Sam Curry and @samwcyo, first published at the original source. Preserved copies are kept so the citation survives its host.