4 ms·
Not nearly as large as ATT U-Verse but I found a similar vulnerability in the modem I was provided from a rural DSL provider a few years ago. It all started w
by sp00ls 9y ago
Not nearly as large as ATT U-Verse but I found a similar vulnerability in the modem I was provided from a rural DSL provider a few years ago.
It all started when I called to get the admin credentials so that I could open a port. They refused, stating that they use the same PW on all of them so they couldn't provide it to me.
After a day or 2 I found a vulnerability in the WebUI that dumped the password to my browser. Did a shodan scan and found hundreds of these modems connected to the internet. What they said was true, that password worked on the 2-3 I tried just out of curiosity.
I tried reporting my findings to them but they didn't seem to care. So I just changed the password on the one provided to me and let it be.
Now I live elsewhere and use my own purchased modem/firewall/wap. Can't trust ISPs to care about your security.
- samstave 9y ago>Can't trust ISPs to care about your security. This is the kicker here: You SHOULDN'T trust an ISP to care about your security - just like you shouldn't trust a the water company to select which Faucet/Shower head you install in your bathrooms. Raw pipes to info == raw pipes to water (interesting aside, the Mayans always equated thought as being symbolized by water) I am paying the water company for pipes to my house, I choose which faucets/shower-heads and use the water is consumed for. Imagine if the water company charged me a different rate for Kohler Faucets used in the kitchen for washing my dishes, vs a Home Depot Hose used in the garden to water my plants? I pay the water company for the volume of water consumed. I pay the ISP for the bandwidth (volume of data) consumed. Further, if the ISP is ostensibly providing my security to literally anything, then, by contract, they are assuming some of the risk? If "what we do is for your protection" -- then they assume full/some liability. The water company provides zero such assurances. A broken pipe/leak/flooding/damage has no affect on the water company, my agreement/bill with them. Further, the water company isn't injecting "paid supplements" (aside from fluoride, which we can equate to NSA backdoors in this example) into my water supply without my will (ads) -- they don't feed me a % of Gatorade in my water supply because Gatorade has a deal with the main faucet - or fertilizers into the garden hose because of a deal with Monsanto. Source: My family owns an actual water company.
- astrodust 9y agoWe're talking about the water equivalent of having the feed to your house that first goes through an open rain barrel at the front of your house, something anyone passing by could lob cigarette butts or other garbage into. You'd ask the water company "can't I provide my own connection to the water" and they'd say "No". Then you'd want another water company, but no such company exists because they're a monopoly. At that point you'd be better off collecting water from your roof and filtering it yourself. The water company is not helping.
- samstave 9y agouh... no we are not. Please explain yourself further, if I am missing your point. Thanks
- CrendKing 9y agoIf the water company is the only water provider and they require you to use the specific faucet or they don't give you water, good luck arguing them with the fancy words and ideals. In reality, water is considered utility but internet is not. Therefore water company can do much less than ISP.
- madez 9y agoHow is internet not a utility?! Some day people will look back at today and shake their head.
- samstave 9y agoIf the INTERNET company is the only INTERNET provider and they require you to use the specific MODEM or they don't give you INTERNET, good luck arguing them with the fancy words and ideals. -- WTF state do you live in?
- jlgaddis 9y agoUnfortunately, on Uverse you are required to use the ATT-provided CPE (due to 802.1X authentication).
- krallja 9y agoYou can put a firewall behind it, which will at least protect you from the inexplicable open proxy.
- Spivak 9y agoNah, all you have to do is redirect 802.1X traffic to their device and you can use whatever device you want. I have my EdgeRouter performing this function currently.
- wil421 9y agoHow much bandwidth do you lose? I have AT&T fiber and I want as close to 1Gb as I can. Someone else else I saw online did something similar with an EdgeRouter and he lost a ton of speed.
- Spivak 9y agoSo there are two ways to add your own equipment. I don't know what method the person you're talking about used. The first you can put the modem in 'DMZ Plus' mode which is the closest you'll get to a bridge mode. This is where you'll lose bandwidth but it's easier to set up. The second, which I recommend, is to connect your router to the ONT directly, and use their modem as a client on your network. You have to set up some rules to hook up the 802.1X traffic but otherwise the att modem is no longer in the picture. I haven't lost any bandwidth and I can't imagine that att's provided cheapo box would be faster than an EdgeRouter.
- chrissnell 9y agoThe DMZ Plus mode doesn't really kill much bandwidth. I get pretty close to 1 Gbit through it. Maybe 960-980 Mbit. Good enough for me. The real problem with the DMZ Plus mode is that it basically sets up a NAT to your router and the state table of the modem is somewhat limited. I've never had any problems but supposedly it might choke if you have tons of open connections.