Re: multiple vulnerabilities in Alcatel Speed Touch DSL modems

From: Tom Perrine (tepat_private)
Date: Fri Apr 13 2001 - 10:32:10 PDT

  • Next message: Adam Rothschild: "Re: PIX Firewall 5.1 DoS Vulnerability"

    >>>>> On Wed, 11 Apr 2001 19:07:24 -0700, Joey Hess <joeyat_private> said:
    
        Joey> Here's one way to disable the backdoor: I used the EXPERT login to download
        Joey> /active/ip.ini by ftp, removed all the apadd and rdadd lines, turned off
        Joey> forwarding for good measure, and re-uploaded it. After resetting the device,
        Joey> I can't ping it or connect to it on any port, and yet it still functions as
        Joey> a DSL modem. I suppose this closes all the holes except DSLAM access.
    
        Joey> --
        Joey> see shy jo
    
    Additionally you can check http://security.sdsc.edu/self-help/alcatel
    for tools to crack the binary, and infomration to patch the binary to
    remove all the "bad" features.
    
    --tep
    
    --
    Tom E. Perrine (tepat_private) | San Diego Supercomputer Center
    http://www.sdsc.edu/~tep/     | Voice: +1.858.534.5000
    "Libertarianism is what your mom taught you: 'Behave yourself
    and don't hit your sister."' - Kenneth Bisson of Angola, Ind.
    



    This archive was generated by hypermail 2b30 : Mon Apr 16 2001 - 01:31:52 PDT