Kitz ADSL Broadband Information
adsl spacer  
Support this site
Home Broadband ISPs Tech Routers Wiki Forum
 
     
   Compare ISP   Rate your ISP
   Glossary   Glossary
 
Please login or register.

Login with username, password and session length
Advanced search  

News:

Author Topic: Be Routers - Important Notice to Be users.  (Read 9321 times)

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33888
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Be Routers - Important Notice to Be users.
« on: September 09, 2009, 11:30:23 PM »

Well Ive just tried to log into my router tonight after noticing that something weird seems to have happened to my MRTG graphs which for some unexplained reason seemed to have stopped logging.

I spent a while looking at my MRTG config wondering what had happened.. and then I then tried to log into my router.
But could I log into my router - could I hellers like!  My router wouldnt let me access it either via http or cli.

So I spent a fruitless half an hour or so messing around..... only to find out that Be had changed my router passy without even notifying me.
Just in case anyone else is with Be..  this is from their website

Quote

We want to let you know that we’ve recently been informed of a security problem that could affect the BE Box, among other routers.

Essentially, the problem could allow somebody to change your router settings, and nobody wants that.

For you tech savvies, we’ve included more details at the bottom of this email.


Email?  What e-mail?  You sure as hell didnt send me one out.

Mad?  Yes I am.   :angry:
Thanks Be for just making me waste a total of about 45 mins in total  :wall: :wall:


--------------------

If like me you are having problems logging into your BeBox, the new Admin password has been reset to the serial number on the bottom of your router.
It doesnt matter if youve already set your own passy...  it will be over-written.

Be tells you how to change it if you have a TG585v7 here.

If you have an older Speedtouch router the setting can be found from

Toolbox >
User Management >
Change my password.


Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

philip_l

  • Member
  • **
  • Posts: 28
Re: Be Routers - Important Notice to Be users.
« Reply #1 on: September 14, 2009, 04:25:56 PM »

Hi

I never received an email either although I don't use the BeBox so maybe they knew that?  Mmm okay I don't believe Be are that organised though to only send emails to those actively using the BeBox, and I think really I should have got one but didn't.

Nice one Be, an ISP that can't reliably arrange an emailshot, not good.

Regards

Phil
Logged

Azzaka

  • Reg Member
  • ***
  • Posts: 572
  • SysAdmin
    • A Designers Work in Progress
Re: Be Routers - Important Notice to Be users.
« Reply #2 on: September 14, 2009, 05:30:35 PM »

http://www.jibble.org/o2-broadband-fail/

This exploit applies to all Speedtouch and possibly BT Home Hubs as well - some people are realising this so some calls may be coming in regarding this.

IMPORTANT STUFF
---------------

This exploit can be limited by setting a username/password on the router. DON'T GO WITH THE DEFAULT!!
Logged
I Sync', I Auth', therefore I am.
Online

chainbeltmadras

  • Just arrived
  • *
  • Posts: 5
Re: Be Routers - Important Notice to Be users.
« Reply #3 on: September 14, 2009, 05:59:54 PM »

What should we do now then just leave it as the serial number or could a hacker have the serial numbers already.

If I have been using ethernet and not wireless was it still vulnerable to attack.
Logged

Azzaka

  • Reg Member
  • ***
  • Posts: 572
  • SysAdmin
    • A Designers Work in Progress
Re: Be Routers - Important Notice to Be users.
« Reply #4 on: September 14, 2009, 07:15:02 PM »

Yes it is still Vulnerable to the Attack. The best advise is to change all the default passwords.
Logged
I Sync', I Auth', therefore I am.
Online

chainbeltmadras

  • Just arrived
  • *
  • Posts: 5
Re: Be Routers - Important Notice to Be users.
« Reply #5 on: September 14, 2009, 08:02:46 PM »

I cannot login to it. How can we know if the box has been updated.
If I reset by paper clip on the box is the serial number always the new default password.
Logged

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33888
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: Be Routers - Important Notice to Be users.
« Reply #6 on: September 14, 2009, 11:41:26 PM »

The vulnerability appeared to be that by default these routers were shipped out with the password not set.
Inputting your own password obviously then makes the router more secure.

In fact I think this would apply to many makes of routers where the user has retained the default password, as its not hard to find out what the defaults are.

You can leave it as the serial number, or you can change it to your own.
Its highly unlikely that a hacker would be able to get your router serial number.
He'd either have to be in there already toget it from the router, or be on the premises to get it from the sticker on the bottom.
Some helpdesks may retain a list of SN to users too.

>> I cannot login to it.

The username should be Administrator with a capital A
and the serial number from the sticker on the bottom of your router
so something like CPxxxxxxxxx.  Ignore the last few figures that are in the brackets.

Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

chainbeltmadras

  • Just arrived
  • *
  • Posts: 5
Re: Be Routers - Important Notice to Be users.
« Reply #7 on: September 15, 2009, 09:05:24 PM »

Still very confused by it,

Azzackas link is very worrying.

o2 email today contradicts what you say again.

We have been notified of a potential security issue with our O2 wireless box routers. We have taken this issue very seriously and have been investigating it with the routers manufacturer, Thomson.

As standard the O2 Wireless Boxes have no password for its "Administrator" login, and generic password for the "SuperUser" login, mainly to make it easy for you to use the router.

The user name has changed to "SuperUser" and you password is now your router serial number which can be found printed underneath your router.

I hope this information has been of help to you.

Best regards
Logged

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33888
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: Be Routers - Important Notice to Be users.
« Reply #8 on: September 16, 2009, 11:27:01 PM »

>> The user name has changed to "SuperUser"

Thanks for pointing that out. :)
O2 have always used SuperUser as the main admin on their boxes.
« Last Edit: September 16, 2009, 11:44:10 PM by kitz »
Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

JohnnyD

  • Member
  • **
  • Posts: 23
Re: Be Routers - Important Notice to Be users.
« Reply #9 on: October 05, 2009, 02:01:23 PM »

Well BE totally messed my router up.......The combination I eventually got in with was SuperUser with a password of Administrator

That only took me 3 weeks to sort out

JD
Logged

Oranged

  • Reg Member
  • ***
  • Posts: 623
    • The Mobile Help Forum
Re: Be Routers - Important Notice to Be users.
« Reply #10 on: October 05, 2009, 06:38:33 PM »

Well BE totally messed my router up.......The combination I eventually got in with was SuperUser with a password of Administrator

That only took me 3 weeks to sort out

JD

I've been with O2 using a TG585v7 for 12 months and as soon as I started using the router, as Azzaka said, I created my own userid and password and applied the SuperUser privileges to that......so I have no need to use any of the default userids.
Logged

Azzaka

  • Reg Member
  • ***
  • Posts: 572
  • SysAdmin
    • A Designers Work in Progress
Re: Be Routers - Important Notice to Be users.
« Reply #11 on: October 13, 2009, 08:20:19 AM »

Something to note, we have found a peice of software that can calculate the wireless key by using the Defualt SSID. In such a case the best practice is to change the SSID at least otherwise change both the Key and the SSID.
Logged
I Sync', I Auth', therefore I am.
Online