hero-image

Mataram City Infrastructure Security Assessment


Mataram City Infrastructure Security Assessment is a confidential summary of a gray-box external and internal assessment conducted on 23 March 2026.

This post only includes high-level information that is safe to share publicly. It intentionally leaves out direct links, PoC details, raw appendix data, and other sensitive evidence.

Overview

The assessment covered both external-facing services and the internal network segment.

The environment included:

  • a public web origin behind a protection layer
  • management interfaces for network equipment
  • application servers
  • printers and embedded devices
  • cameras and other IoT-style assets

The overall picture showed a mixed environment with several critical misconfigurations that could widen the impact of a single compromise.

What Stood Out

Seven findings were identified in total:

  • 3 Critical
  • 3 High
  • 1 Medium

The most important themes were:

  • exposed management surfaces
  • default or weak credentials
  • insufficient network segmentation
  • externally reachable services that should have been more restricted
  • internal devices exposing services that were not meant to be broadly accessible

Key Findings

Exposed origin server behind the protection layer

The public web infrastructure exposed the origin server directly, which reduced the value of the front-layer protection.

That created a path where an attacker could potentially reach the backend more directly than intended.

Default credentials on ACS / TR-069 management paths

The assessment found signs of default or assumed-default credentials on management-related interfaces used for CPE provisioning.

Because this type of interface can control many devices at once, the risk was not limited to one router or one subscriber line.

Exposed TR-069 management surface

The ACS/TR-069 surface appeared too open for a system that should have been tightly isolated.

If abused, it could affect device configuration, service stability, and the integrity of managed customer equipment.

Flat internal network design

The internal environment appeared to place many different device types on a single flat subnet.

That included servers, printers, cameras, and other connected devices.

Without segmentation, one compromised host can move laterally much more easily.

Exposed reporting services

An internal Windows server exposed reporting services that should have been more tightly controlled.

Even when authentication is required, exposed management or reporting surfaces still increase the attack surface and deserve extra restrictions.

Anonymous FTP on a network printer

A printer was found offering anonymous FTP access.

That kind of misconfiguration can expose configuration data, cached jobs, or other internal artifacts that were never meant to be public.

Default router admin credentials

A gateway/router management interface was accessible with default administrative credentials.

That is one of the highest-risk issues in the report because it can lead to full control over routing, DNS behavior, firewall rules, and service availability.

Business Impact

The main business risks were:

  • unauthorized access to sensitive systems
  • mass device reconfiguration
  • service disruption
  • broader impact from a single compromise because of the flat network design
  • exposure of internal reports or device configuration data
  • reputational damage if infrastructure weaknesses become public

Remediation Themes

The report recommended a focused response around a few core actions:

  • change all default administrative credentials immediately
  • isolate management services on dedicated trusted networks
  • protect the origin server more strictly
  • restrict reporting and printer services to authorized hosts only
  • segment the internal network into smaller security zones
  • apply access controls and monitoring to reduce lateral movement
  • validate the fixes after implementation

Closing Notes

This post is meant as a safe public summary only.

It reflects the overall security posture, the number of findings, and the kind of misconfigurations that were observed, without exposing the raw evidence trail.