IWETHEY v. 0.3.0 | TODO
1,095 registered users | 0 active users | 0 LpH | Statistics
Login | Create New User
IWETHEY Banner

Welcome to IWETHEY!

New Cayman 3220-H router may be insecure.
If you happen to have one of these, look out!

[link|http://www.theregister.co.uk/content/55/22353.html|Register link.]
Hackers have developed a trick for pilfering DSL account names and passwords right from subscriber's routers
...


Alex

Men never do evil so completely and cheerfully as when they do it from religious conviction. -- Blaise Pascal (1623-1662)
New couldnt get the reg but is true of all routers
snoop the line from the router to the authentication server, name and passwd are in clear text. The modem connection is secure, but the router routes that stuff in the clear.
thanx,
bill
tshirt front "born to die before I get old"
thshirt back "fscked another one didnja?"
New Yes, but it's worse than that.
Like other DSL routers, the Cayman 3220-H allows users to easily configure their settings through a Web browser interface. But the router makes that interface accessible, not just from the user's local area network, but also from the 'WAN port' that connects to the Internet.

The device is protected from unauthorized reprogramming by an administrative password set by the owner. But unless the subscriber also sets a separate 'user password', the router's configuration settings can be viewed, though not changed, through the browser interface. There, the 'PPPoE' password used to log onto the DSL service is masked as a series of asterisks, but it is plainly visible in the HTML source code of the page.

Hackers can use the purloined password to download the subscriber's email from SBC servers, or view and edit portions of their account information.

But sources say the vulnerability has found its greatest utility in the computer underground as a wellspring of free, anonymous Internet access. Because the same password works on SBC's dial-ups, without interfering with the subscriber's DSL use, the purloined passwords help hackers cover their tracks by borrowing other people's ISP accounts, according to 20-year-old Internet hacker Adrian Lamo.
Alex

Men never do evil so completely and cheerfully as when they do it from religious conviction. -- Blaise Pascal (1623-1662)
New thats bad need to buy a siemens router :)
tshirt front "born to die before I get old"
thshirt back "fscked another one didnja?"
     Cayman 3220-H router may be insecure. - (a6l6e6x) - (3)
         couldnt get the reg but is true of all routers - (boxley) - (2)
             Yes, but it's worse than that. - (a6l6e6x) - (1)
                 thats bad need to buy a siemens router :) -NT - (boxley)

Powered by zeptotechnology!
68 ms