ADSL user account details freely available due to poor security

Speaking of security IS should improve security on their usage stats page - usernames and passwords are sent in cleartext. The saix page is a little better but still uses basic authorisation which is pretty easy to intercept and decode if you know how. This is a major risk if you connect to the net via a proxy.

They should implement https if they're serious about security.
 
a friend of a friend wrote a little java application that connects to each ip in the 165.165.x range. setting it to do 10 simultanious connections, he was able to get 50+ ADSL username/password combinations in less than an hour using default marconi username and password.

this was about two years ago... really thought that people would know to change the passwords by now.
 
No, they still dont. I'm shure at least a third or so of the marconi Telkom supplied routers are still set to their default username and pass.

I was trying to fix a friends ADSL/Lan connection problem but didnt have the password for his Marconi router, instead of asking I just tried out what I thaught the default setting might be and got in first time, and I just made it up from what I knew my Netgears default setting was.
 
MaD said:
It must be understood though that this is nobody else's fault but the person who set up the router. The absolute first thing to do when you get a router/modem is to change the default login username and passwords.
I disagree. I think its the manufacturers fault. My router (Netgear) by default does not allow access to the admin interface from the internet, only from LAN connections. It would be trivial to enable this feature in the marconi routers but by not doing it they leave open a massive security hole. Telkom is also to blame for allowing this situation to continue year after year.
 
fergus said:
I disagree. I think its the manufacturers fault. My router (Netgear) by default does not allow access to the admin interface from the internet, only from LAN connections. It would be trivial to enable this feature in the marconi routers but by not doing it they leave open a massive security hole. Telkom is also to blame for allowing this situation to continue year after year.
Thats like saying a car accident is the fault of the car manufacturer though. It is up to the driver of the car to know what precautions to take, not the car manufacturer.

Are there any stickers or anything that is stuck onto a modem or router to alert the new owner to change the defaults? If not there should be at the very least. Zyxel and assorted other modems have the first admin screen as a 'change password' box.. would be great if other manufacturers started doing that by default as well.

One could probably even get account details of users in the UK/US like this.
 
Actually if the car is faulty the motor manafucturer would recall that model. If you made an accident it would be the manufacturer's fault.

The problem here is a security flaw in the Marconi routers. Telkom should have recalled them all and upgraded the firmware. The problem have been documented here on the forum (it was sticky thread) for a very long time.

A few month after Lexus (the luxury Japaness motor manufacturer) launched their first car in the States they faced the problem that they needed to do a recall. At this early stage it was the early adopters that bought the Lexus and so Lexus phoned each customer to make an appointment for the change in the car. Normally with recalls, a press release and post card is sent out. Lexus cleaned and filled the tank of each recalled car. If you did not stay close to one of their repair centers they would picked up the car from you. The moral here is that Lexus scored major brownie points and people still talk about Lexus' service. They also turned a negative (the recall) in a major positive for a new brand.

Read more: Lexus gives away iPod Nanos for IS250 recall (http://paultan.org/archives/2006/02/13/lexus-gives-away-ipod-nanos-for-is250-recall/)
 
Leaving a router on default user/pass isnt a hardware flaw though.. no need to recall it as it works properly. If the user/pass is changed as early as possible then the connection is safe.. for the most part.
 
The Billion routers' firmware can easily be upgraded. The Billion routers does not suffer from the same security flaw as the Marconi router. Configuration access is limited to only local interface (ethernet) and not the remote interface (ADSL).
 
Last edited:
MaD, the problem is not the default configuration username/password. There will always be defaults. The problem is that the configuration is accessible via the ADSL interface. It should be limited to only the local interface.
 
There is a firmware upgrade for the Marconi routers. It is here: http://www.marconisa.co.za/routeradsl.htm

The firmware is dated 30 April 2003 (so, very old!) and version 1.027.L10-3A. It uses the TFTP program that is included in the archive to upload the firmware.

I'm not sure if the firmware upgrade actually does anything for the security flaw. There is installation instructions but there is no documentation about what the firmware upgrade is suppose to fix.
 
@ic, the USB ADSL modem uses a dialup connection and a Window PPPoE driver. There is no web based configurator with the modem as is the case with the routers. But it is important to ran a personal firewall on the PC.
 
ic said:
One thing I am curious about is why it seems like forumites with specifically TelkodemonopoliesHindernet ISP accounts seem to suffer from username & password theft? - did all these people have ADSL routers [as opposed to ADSL modems], and did they all fail to change their router's password & other security settings...?

Or is it just that Telkodemonopolies employees still have cleartext [on their PC monitors] access to both username & password of TelkodemonopoliesHindernet customers?

Perhaps victims of ADSL username & password & data traffic, could comment here...

I had no problem with theft yet but...I complained with Telkom for not getting the e-mail sending functional. So the clerk on phone would not pass me on to the second tier, as it was my third call already, without checking all details. So he asked my user name and password. I asked him what have he got to do with my password and he commented he can see it on the screen he want to check if it is correct! Now not to repeat what I said; but he was not a happy chappy???

With all the corruption how can you trust common clerks with this info!
 
allyoucaneat said:
MaD, the problem is not the default configuration username/password. There will always be defaults. The problem is that the configuration is accessible via the ADSL interface. It should be limited to only the local interface.
Yes sorry, I was thinking along another line there :)
 
The Firmware Upgrade on my Zyxel Router changed the login window from the usual Admin and Password Pop-up to just a web based password entry.
After entering the first window with the default password a second web based window asks you to change your password with extra confirmation.
This new feature simply puts the password change in the user's face and if he doesn't act at this stage then the person only has them self to blame if they get their ADSL account hacked.

Some of the Planet Routers are also at risk.
Some of the Pop-up windows even reflect the model of the router?
Which leaves it open as then one simply has to go to the Manufacturer's website to see what user name and password is used.
 
Last edited:
Top
Sign up to the MyBroadband newsletter
X