Author Topic: Avast Pro states google wifi router has a weak default password  (Read 2140 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Avast Pro states google wifi router has a weak default password
« on: December 06, 2017, 08:58:25 PM »
I use the google wifi device OnHub AC1900.  When I run Avast Pro, it claims that my router has a weak default password of admin/admin.

However, one cannot even access settings via a web browser on that router.  It requires a phone app and a user defined username/pass to configure it.  From a browser the homepage of the router simply gives links to download the phone app.

My guess is that Avast Pro is simply calling it with a POST and passing admin/admin.  Since it returns a page (the one with download links) Avast assumes that it logged in.

I want to make sure I am not wrong though and there isn't something I am missing with this router.  Like whether or not Avast is using a different protocol or hitting a specific page directly.  The google wifi routers leave much in a black box, so I want to be sure there is no glaring security hole I missed.

REDACTED

  • Guest
Re: Avast Pro states google wifi router has a weak default password
« Reply #1 on: December 07, 2017, 01:25:52 AM »
I believe this to be a bug.  See this post:  https://forum.avast.com/index.php?topic=209402.msg1423925#msg1423925

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48524
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Avast Pro states google wifi router has a weak default password
« Reply #2 on: December 07, 2017, 01:47:49 PM »
Both topics have been reported on the developers channel.
As soon as I get an answer, I'll post it here.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Alikhan

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2220
Re: Avast Pro states google wifi router has a weak default password
« Reply #3 on: December 07, 2017, 02:04:49 PM »
When Wi-Fi inspector finds a weak service password, it doesn't explicitly state which password that is.  It could be the wi-fi password, router password or the FTP server.

Have you checked all three? Many times users don't change FTP server default password.
Windows 10 Home 64-bit • Avast Free (latest stable version) •  Malwarebytes 4 Premium (On-Demand) • Windows Firewall Control • Google Chrome • LastPass • CCleaner • O&O ShutUp10 •

REDACTED

  • Guest
Re: Avast Pro states google wifi router has a weak default password
« Reply #4 on: December 07, 2017, 02:43:47 PM »
When Wi-Fi inspector finds a weak service password, it doesn't explicitly state which password that is.  It could be the wi-fi password, router password or the FTP server.
Doesn't it!

Offline Alikhan

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2220
Re: Avast Pro states google wifi router has a weak default password
« Reply #5 on: December 07, 2017, 02:56:13 PM »
Where does that tell you that the weak password is the wi-fi password, router password or the FTP server?

HNS-Weak-Pass just states it's a weak password but doesn't state each one explicitly.
« Last Edit: December 07, 2017, 02:57:48 PM by Alikhan »
Windows 10 Home 64-bit • Avast Free (latest stable version) •  Malwarebytes 4 Premium (On-Demand) • Windows Firewall Control • Google Chrome • LastPass • CCleaner • O&O ShutUp10 •

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37509
  • Not a avast user
Re: Avast Pro states google wifi router has a weak default password
« Reply #6 on: December 07, 2017, 03:13:33 PM »
To me this seems to be the router log in passwords (not WiFi) .... admin/admin




Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48524
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Avast Pro states google wifi router has a weak default password
« Reply #7 on: December 07, 2017, 03:17:18 PM »

To me this seems to be the router log in passwords (not WiFi) .... admin/admin




That's what I also think. :)
http://www.tp-link.com/us/faq-426.html


(Sorry, I quoted the wrong user. )
« Last Edit: December 07, 2017, 05:25:02 PM by bob3160 »
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

REDACTED

  • Guest
Re: Avast Pro states google wifi router has a weak default password
« Reply #8 on: December 07, 2017, 04:36:37 PM »
Where does that tell you that the weak password is the wi-fi password, router password or the FTP server?

HNS-Weak-Pass just states it's a weak password but doesn't state each one explicitly.
That's what I also think. :)
http://www.tp-link.com/us/faq-426.html
But the only usernames/passwords that the router has set to admin/admin, as default are the router passwords.  FTP has to be explicitly enabled and has no defaults. Default WiFi SSID's are conglomerates of text and part MAC addresses and the passwords are pseudo-random numeric, and besides, my PC doesn't have WiFi so Avast can't test for that.  So for Avast to report that it has found admin/admin can only mean that it was checking the routers web interface.