Likes Likes:  0
Resultaten 1 tot 4 van de 4
Geen
  1. #1
    http-equiv@excite.com
    SPRINT ADSL [Zyxel 645 Series Modem]
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    SPRINT ADSL [Zyxel 645 Series Modem]



    Thursday, January 23 2003

    Sprint FastConnect[insert little registration r here]ADSL provides
    the Zyxel series of modem/routers to their customers. The problem is
    all these devices are factory set with default commonly known
    passwords and logins and include a little http, ftp and telnet
    server. This allows for remote configuration of the network settings
    and host of other things. Including uploading and downloading the
    modem configuration file rom-0, rebooting the modem, changing the
    modem's remote management login and password, various other "high-
    tech" fiddling possibilities. Through both telnet and web.

    Certainly not of interest or of need to your generic subscriber.

    Quick pretend examination of:

    Sprint NETBLK-SPRINTBLK (NET-198-67-0-0-1)
    198.67.0.0 - 198.70.255.255
    LTD SPRINT FLA ANS ISP FON-332652953698729 (NET-198-70-208-0-1)
    198.70.208.0 - 198.70.223.255

    shows 800 out of 2000 [of 100,000 or so] affected modems. Closer
    examination confirms:

    Copyright (c) 1994 - 2002 ZyXEL Communications
    Corp.

    P645ME+ Main Menu

    Getting Started Advanced Management
    1. General Setup 21. Filter Set
    Configuration
    3. Ethernet Setup 22. SNMP Configuration
    4. Internet Access Setup 23. System Password
    24. System Maintenance
    25. IP Routing Policy
    Setup
    Advanced Applications 26. Schedule Setup
    11. Remote Node Setup
    12. Static Routing Setup
    15. SUA Server Setup 99. Exit






    Enter Menu Selection Number:

    punching in on our replica modem, number four [4], we get:


    Menu 4 - Internet Access Setup

    ISP's Name= MyISP
    Encapsulation= PPPoE
    Multiplexing= LLC-based
    VPI #= 8
    VCI #= 35
    Service Name=
    My Login= grandpamalware@malware.com
    My Password= ********
    Single User Account= Yes
    IP Address Assignment= Dynamic
    IP Address= N/A
    ENET ENCAP Gateway= N/A




    Press ENTER to Confirm or ESC to Cancel:

    Press ENTER to Confirm or ESC to Cancel:

    Playing with our replica modem a bit more we GET:

    ftp> open malware.com
    Connected to malware.com.
    220 Sprint FTP version 1.0 ready at Wed Jan 5 17:20:47 2000
    User (malware.comnone)):
    331 Enter PASS command
    Password:
    230 Logged in
    ftp> get rom-0
    200 Port command okay
    150 Opening data connection for RETR rom-0
    226 File sent OK
    ftp: 16384 bytes received in 2.03Seconds 8.07Kbytes/sec.
    ftp>

    Due to our modem only being a replica, we are unable to determine
    whether uploading our custom crafted rom-0 file from our second
    replica modem to our first, will (a) register the user data from
    there to there inclusive of user name and password and or (b)
    overwrite the configuration file in such a way our modem then becomes
    useless.

    But without a doubt, we are not happy to see Grandpappy's private
    email address out in the open for the whole world to see.

    Notes:

    1. The provider suggests that slapping up a web page with
    instructions to disable this "feature" will be the solution. We would
    suggest fire-walling off the entire affected user base ftp, http and
    telnet ports, rolling out the trucks, physically reconfiguring each
    and every affected subscriber's modem or replacing them
    2. PRIVACY PRIVACY PRIVACY. In this day and age, it is all we have
    left !
    3. http://www.wired.com/news/infostruct...,57342,00.html
    4. Victims of this contact your provider asa possible and have them
    hand-hold you through disabling this "feature". Better yet, insist
    they send over the installer to do it for you. After all it should
    have been done at time of installation.

    End Call



    --
    http://www.malware.com





  2. #2
    Raymond Dijkxhoorn
    SPRINT ADSL [Zyxel 645 Series Modem]
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: SPRINT ADSL [Zyxel 645 Series Modem]

    Hi!

    > shows 800 out of 2000 [of 100,000 or so] affected modems. Closer
    > examination confirms:


    > ftp> open malware.com
    > Connected to malware.com.
    > 220 Sprint FTP version 1.0 ready at Wed Jan 5 17:20:47 2000
    > User (malware.comnone)):
    > 331 Enter PASS command
    > Password:
    > 230 Logged in
    > ftp> get rom-0
    > 200 Port command okay
    > 150 Opening data connection for RETR rom-0
    > 226 File sent OK
    > ftp: 16384 bytes received in 2.03Seconds 8.07Kbytes/sec.
    > ftp>


    Its even worse, if you upload a config file, same size as the rom-0 file,
    but filled with total crap the modem reboots (it does thatautomaticlty
    after uploading a new image) and after that the modem is broken. You ONLY
    have the ability to upload a new image via a serial port then, and most
    customers just have to bring back their unit. The modem is waiting after
    upload of a broken image, with a x-modem session. And there it ends. Even
    if you upload the previous image it wont work. Nice stuff

    There are two files you can toy around with in this case, ras and rom-o
    ras is the image file, rom-0 is 'just' the config.

    Bye,
    Raymond.


  3. #3
    FX
    SPRINT ADSL [Zyxel 645 Series Modem]
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: SPRINT ADSL [Zyxel 645 Series Modem]

    > ftp> open malware.com
    > Connected to malware.com.
    > 220 Sprint FTP version 1.0 ready at Wed Jan 5 17:20:47 2000
    > User (malware.comnone)):
    > 331 Enter PASS command
    > Password:
    > 230 Logged in
    > ftp> get rom-0


    I'm not sure if this applies to the Zyxel boxes you found, but there is another
    file called spt.dat, which contains all password and account information. More
    details can be found here: http://www.DarkLab.org/archive/msg00144.html

    FX

    --
    FX <fx@phenoelit.de>
    Phenoelit (http://www.phenoelit.de)
    672D 64B2 DE42 FCF7 8A5E E43B C0C1 A242 6D63 B564

  4. #4
    http-equiv@excite.com
    SPRINT ADSL [Zyxel 645 Series Modem]
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: SPRINT ADSL [Zyxel 645 Series Modem]



    FX <fx@phenoelit.de> said:

    > > ftp> open malware.com
    > > Connected to malware.com.
    > > 220 Sprint FTP version 1.0 ready at Wed Jan 5 17:20:47 2000
    > > User (malware.comnone)):
    > > 331 Enter PASS command
    > > Password:
    > > 230 Logged in
    > > ftp> get rom-0

    >
    > I'm not sure if this applies to the Zyxel boxes you found, but

    there is another
    > file called spt.dat, which contains all password and account

    information. More
    > details can be found here:

    http://www.DarkLab.org/archive/msg00144.html
    >
    > FX


    Yes FX you are correct. After a good swift kick in the nuts, Sprint
    has done and is still doing an admirable job in fixing this.

    Sufficient time has elapsed to advise this.

    The only additional note is to strongly suggest that the users change
    their master account password as well:

    <!--

    Friday, January 24, 2003

    Ladies and Gentlemen:

    Reference the information provided to you on Monday and Tuesday of
    this week and subsequent announcements on Thursday this week:

    http://www.wired.com/news/infostruct...,57342,00.html

    http://www.securityfocusonline.com/a...03-01-22/2003-
    01-28/0

    This message serves to inform you that your entire user base is open
    to full and complete remote compromise through this modem.

    This includes full access to:

    1. the internet via adsl and dialup connection
    2. pop3 email retrieval
    3. webmail
    4. web based user account management including user name and address
    and billing details

    The problem lies in the fact that the modem you have provided to your
    user base is installed with a commonly known default login and
    password. Once access has been gained to this modem, it is trivially
    possible to retrieve a storage file contained within the modem which
    includes the user's name and password.

    With this information it is possible to access all aspects of the
    user account as described above.

    Example:

    00000020: 1234
    00000042: malst
    00000060: Sprint
    00000082: mal Ware
    000000AC: public
    000000CC: public
    000000EC: public
    00001086: dhcppc
    00001C54: MyISP
    00001DDE: grandpamalware
    00001DEB: malware.
    00001DFE: ware
    00002112: mal

    0x20 the root password in clear
    0x40 SNMP Location
    0x60 Device name
    0x80 SNMP Sys Contact
    0xac SNMP read community
    0xcc SNMP read community
    0xec SNMP read community
    0x188 SUA Server IP address
    0x1c54 First PPPoE Account config name (Default: ChangeMe)
    0x1dde First PPPoe Username
    0x1dfe First PPPoe Password
    0x21dc Second PPPeE Account config name

    Where username: grandpamalware@malware.com and pass: ware inputted
    into a dialup connection with specific access number, will function,
    where inputted into a pop3 mail client with corresponding pop3
    server, will retrieve mail accordingly, where inputted into a web
    based mail access, will allow for access and where access to
    myaccount information is required, will allow for authentication and
    login.

    In other words, the single user id and email address along with the
    single pass all contained within the file on the modem will allow
    access to everything!

    The file on the modem is a small dat file called spt.dat therein, in
    clear text, lies all this information.

    This information is already in the public domain and you need to
    urgently fire-wall your user base ports http, telnet, and ftp while
    you solve this problem. You must assume that malicious parties are
    well-aware
    of and are probably exploiting it right now.

    Today is Friday. Nothing has been done about this to date. Your
    entire user base is at risk.

    We expect some sort of substantial action by Tuesday latest. Failing
    that, we will discuss this in technical depth on all relevant
    security lists.

    End Call

    cc:

    Wired
    @pc-radio.com
    Symantec
    @securityfocus.com
    CERT
    @cert.org
    Earthlink
    @corp.earthlink.net
    abuse@earthlink.net
    security@corp.earthlink
    Sprint
    @mail.sprint.com
    noc@sprint.net
    abuse@sprint.net
    security@sprint.net


    --
    http://www.malware.com

    -->

    Date: Tue, 28 Jan 2003 17:01:25 -0500

    <!--

    Sprint is working closely with its DSL modem manufacturer to ensure
    the
    security and integrity of its Sprint-provided DSL equipment. Sprint is
    dedicated to providing its customers a secure broadband Internet
    network, and to that end, recently identified an additional layer of
    security that can help protect customers' DSL modems.<?xml:namespace
    prefix = o ns = "urn:schemas-microsoft-comfficeffice" />

    The company began notifying its customers - one-by-one - in a very
    targeted initiative to provide guidance on ensuring their DSL service
    is
    reliable and secure. We are consulting with our customers and walking
    them through the relatively simple steps to ensure an additional layer
    of security on their modem.

    Proactively, we are reaching out to our customers in three different
    ways - outbound telephone calls, e-mail messages and a customer letter
    mailed today (Jan. 28). These communications are directed at helping
    ensure the safety and security of customers' DSL modems.

    Additionally, we are informing all DSL customers who call our
    technical
    assistance group of the procedures for securing their modem.

    Sprint is committed to providing safe, reliable and secure voice and
    data services to all its customers. When an event occurs that
    threatens
    that safety, reliability and security, we take it very seriously and
    we
    will continue to do everything we can to contact our customers.



    Director-Customer Operations

    -->

    Notes: users can address the issue here:

    http://csb.sprint.com/home/local/dsl...lease645m.html


    --
    http://www.malware.com




Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics