just a slight concern...

Onraji

Well-Known Member
Joined
Mar 23, 2005
Messages
183
Reaction score
0
My first concern

I have a friend who knows someone that knows someone who works @ iBurst ( a weak link, i know, but that's half my point ).

My friend asked his friend to ask the person they know @ iBurst wot my , and a mutual friend's passwords are. And guess wot, they gave it to them. :confused:

It isn't necesserily a problem for me because i used a different password to wot i usually use, but some people use the same password for everything.

My problem isn't that someone will use my iBurst account, because apparently, the username and password is tied to the utd. The problem is that, as i said, some people use the same password and the wrong info in the wrong hands ... ???

Does this mean you keep the passwords in text ? :confused:

My second concern

When im online, doing woteva, with full signal, my utd will just lose all signal for about 2-3 seconds and then go back up 2 full again. It doesnt happen often. Maybe once every hour or so. The funny thing is, i dont get disconnected ? mayb there's sumthing wrong with my utd ?

According to the map, i use the Northcliff Tower ... I am in Weltevreden Park

Otherwise... iBurst rocks !!! :D
 
Onraji said:
My problem isn't that someone will use my iBurst account, because apparently, the username and password is tied to the utd. :D

I have wondered about the same thing, I have not seen a user account area on the IBurst website where you can change your own password, also they have confirmed my password verbally with me during a previous call to the Helldesk.

So that means they do know what your password is. And if they know that they can use your 3Gig on your behalf, unless of cours the above is true.

IBurst........ IBurst..... Anybody out there from IBurst?

Or can anyone on this forum confirm this please.
 
unfortnately security is always a problem... and always will be a problem... also if someone does get your password and you do you use the same password on some other sites or whatever they will first need to know that.

Unless ofcourse you have pissed someone off who is willing to go that extra mile to make your life hell I think it isn't a real concern. Kinda of like leaving your home while you go on holiday and wandering if it will be brocken into.

Its one of those things that if it happens... it happens and there is not much you can do except maybe be cautious with your passwords and try not to use the same passwords for lets say banking as you would for lets say iburst.

As for the modem loosing signal I also get that but not as often as you... but then I probably wouldn't notice either... esp since it aint lose a connection.

And yeah. iBurst most certainly rocks!
 
As for the disconnecting problem, they're still working on that problem but it's not effecting alot of folks like it used to.

Re: Security, the passwords appear as text for the call centre agents, the user is linked to a UTD. Because the same problem existed with Sentech (and probably still do) I've tested their agents on numerous occassions.

They ask your username, then ask your ID number (or relevant information till they're satisfied you're the person who's account it is) then give you your password.

You will be able to change the password yourself in future (hopefully at launch) according to sihen, however, if the password will still be able to be viewed by call centre agents after the fact, I'm unable to tell you.

If you want, you can pm sihen (who is the call centre manager) to comment on this thread about this issue. If you don't come right, talk to his boss (think it's Shaun Green) and if he can't help you, talk to his boss (I think it's Sasin Parvin) and if you don't come right there... talk to the CFO (who pays all their salaries! :P )
 
geeks love talking about security because they all think they're hackers, anyways as far as account theft goes, its around with every ISP but it will be way less with iBurst since you need specialised hardware to connect.

If iBurst are anything like other ISPs (and they probably are) then they have a SQL database with account info in, then both the authentication server used when you connect and the mail server and anything requiring your login will use this database to authenticate you, is a password stored in this database in cleartext? Thats highly unlikley, the standard is to use an MD5 hash, which is a one way encryption scheme, so you can encrypt but not decrypt. Was the account holder told his password.. or did he choose it, was is some dictionary word or a proper password?

And your thing goes red because its switching or attempting a switch between towers, with iBurst while driving around I can have a red dot for like 5 minutes and not disconnect sometimes.
 
slimothy, call into helpdesk, tell them you forgot your password... they can tell you your password. if it was MD5 hashed (doubt they even know what it is) the call centre agent would not be able to tell you your current password, but only have an option to reset the password for you.

Usually (this could have changed) an ISP's authentication servers are not synced with their account information (unless a password change is made, and usually this takes a couple of minutes to reflect)

This opens it up for a user to "steal" another user's credentials and use it to log in from a different location. The ISP only investigates when a complaint has been made. I refer you to the bandwidth theft for some ADSL users last year (probably still happening). Unfortunately, telkom forces you to log a complaint with the police first, before they'll release any information as to who actually logged into your account as well.

If it wasn't for the geeks who discussed security, you won't be so safe sitting there downloading everything you do download.

Your recent flurry of posts makes me concerned, because it hardly contains any of your previous helpful posts and if it is somewhat helpful, comes with insulting someone or a group of people.

Please stop that, I was starting to be convinced that you were a decent and nice guy... don't taint that perception
 
I'm kinda wondering why each modem doesn't have it's own unique code that goes along with a username/password ?

Surely something such as this is easy enough to implement - when you get your modem, you have the code in the manual which is also required for connecting ?

Makes sense to me.

(oops, but I'm not supposed to be posting in here ... :rolleyes: )
 
If me connection doesn't die again by the time I've written this...:rolleyes:

I have been seriously concerned about the safety of my iBurst account info - especially since WBS' iburst.co.za site went down (what was it - downtime close to 7 days?), and then the site sortof came back up again - only to have lots of complaints about being easily hackable (I didn't bother finding out, please ask me why and I will tell you)...

I am not particularly concerned about bandwidth being stolen if username & password & UTID are mutually inclusive in the authentication stream.

I am however concerned that anyone can get hold of my details from WBS without the authority to receive such info.

Curses, that means that I too disagree with the theory of our esteemed forumite:
"geeks love talking about security because they all think they're hackers...". And talking about MD5 - wasn't it cracked just recently?

Again with the no traffic going through - thank you WBS for a useless always-on disconnection which I pay you to provide me with.

Added: apologies, I remember now, it was SHA-1 that was allegedly cracked just recently.
 
Last edited:
yeah md5 wasn't cracked as such, they used supercomputers and found collisions (2 different words/data that made the same hash) but MD5 is still OK for most things. If iBurst don't encrypt passwords or only allow certain capable/accountable people to access that data then thats thier own fault, seeing as how any idiot knows stuff liek that shouldn't be laying around.
 
Next time someone calls up WBS (or hacks in) & says to HelpdeskPerson:
Please confirm that my bank account is correct on your system...now my ID number...what's my address again...PIN code - sorry I mean password...

A little bit of psychological manipulation can get people to say things they should never say, so I say deny them access to account details they do not need.
 
sorry another thing i wanted to touch on (not to be petty) is that (hypothetically) I can hack the wbs or iburst site right, some lame web sploit or maybe they run somethign stupid on a priveleged port, so lets say I get in I have root... how does that give me access to clients passwords again? I mean seeing as they are an ISP and all i'm pretty sure they have more than one server and i'm sure they dont run this whole thing with some webserver and all the clients details in a little mysql setup. you'd have to go through the whole network or not hack from the www at all, plus i'm sure they would set up the SQl server as an internal server only accessable from inside the network and not be sitting on the internet. and after checkign IPs of www.iburst.co.za and smtp.wbs.co.za and www.wbs.co.za i think its safe to say thats exactly whats they're doing
 
ic said:
Next time someone calls up WBS (or hacks in) & says to HelpdeskPerson:
Please confirm that my bank account is correct on your system...now my ID number...what's my address again...PIN code - sorry I mean password...

A little bit of psychological manipulation can get people to say things they should never say, so I say deny them access to account details they do not need.

once I went to Nedbank to sort out my credit card... get a pin number for it or encode it so I could use it for the ATM... anyways I waltz in... some dude asks what do I need. I explain the prob he takes me to some machine tells me to swipe the card and enter the pin number I desire... I asked him I am not sure if it has a pin number or not. He says no worries it will clear the old one with the new one. Anyways I do this and walk out.

Not once did he ask for ID, look at the card... or proof of owenership... a freaking gold card and they dont even wonder if this long haired freak picked it up or something..

moral of the story... nothing is secure... but I wander if iBurst will give us some kind of panel to see how much bandiwdth my account has used just in case. I think it is in their best interest to do this.
 
slimothy said:
yes.. they will
Please substantiate with facts that spewed forth from the horse's mouth, thank you :).

Now, back to iBurst.co.za, the fact that there was an error message displayed at the bottom of each page (for quite some time - until it was commented out instead of fixed - thereafter I lost track), the thing started off "E:\"... so is that Linux then or is it iBurst.co.za running on a Windoze platform...?

VISP is something that allows you to host a whole bunch of sites on the same physical box - just different IP addresses...

There are also other possibilities, none of which inspire me to trust WBS with keeping my account info safe.
 
the error message was probably a php one because it looks liek they have a shoddy php CMS running things especially compared to the aus site (have you seen how clean the aus site is? they actually do soemthing with the flash and NO FRAMES!!!), but its not hard to see what they're running, after checkign the TCP figerprint and http://uptime.netcraft.com/up/graph?site=http://www.iburst.co.za/ they're definatley running windows, which i gotta say sucks as far as security is concerned, and *gulp* they dont even use apache, they use Microsoft-IIS/5.0. go look at securityfocus.com and look at all the exploits :(

tell any security consultant you wanna run IIS 5 out of the box and they'll slap you
 
Like I said - it's not Linux, which I think we can all agree is bad unless they keep the box continually patched, and even then there are likely to be new exploits that don't yet have M$ hotfixes that get well exploited.

So, the question remains - how safe is your personal info in WBS' hands?
 
Well a second username and password for a adsl connection would be nice about now...anybody have some lying around?

Lollllllllllllllllllllllllllllll
 
not very, you know what these guys are idiots, i'm sick of defending them and always being the guy trying to pull opinion back on thier side and then they go and do this, idiots
 
Top
Sign up to the MyBroadband newsletter
X