Thursday, October 28, 2010

IP POWER IP9258 and the ip address 122.116.138.126

I am very glad to have this ip power 9258. This is Network based power controller - I am able to power on and off all my cisco routers and switches from anywhere in the world. Because this simple unit, I am saving on electricity and cut off my phone calls to my wife and daughter . I used to call them to turn on devices when I am at starbucks studying.

But there is something I discovered with this ip power that very SCARY. It mapped my ip address to a public ip service server located 122.116.138.126 - Anybody in the world could access my network and turn on and off all my devices. Can you imagine if I plug my production servers into this device?


http://122.116.138.129/test/ip_search.asp


I found lot of ip addresses (ip power devices) with default username and password. I could turn off and on if I wanted to scare people specialy on this halloween days.

SO - PLEASE MAKE SURE YOU CHANGED THE PASSWORD AND DENY ANY TRAFFIC TO 122.116.138.129

You can put it to the test. Change the name of your IP 9258 and go to the website and enter the new hostname. You will be scared.

1 comment:

Howard said...

Thanks.

Just ordered myself one of these and first thing out of the box will change admin info and block IP address access.