<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: BT Home Flub: Pwnin the BT Home Hub (4)</title>
	<atom:link href="http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Thu, 11 Mar 2010 22:49:16 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Richard Burns</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-126701</link>
		<dc:creator>Richard Burns</dc:creator>
		<pubDate>Wed, 29 Apr 2009 07:00:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-126701</guid>
		<description>This all seems pointless, tell me i&#039;m wrong. How can you run any of this unless your on the network? I am surrounded by at least 10 hubs and need to access one of them??</description>
		<content:encoded><![CDATA[<p>This all seems pointless, tell me i&#8217;m wrong. How can you run any of this unless your on the network? I am surrounded by at least 10 hubs and need to access one of them??</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jonnycorer77</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-125367</link>
		<dc:creator>Jonnycorer77</dc:creator>
		<pubDate>Sat, 17 Jan 2009 20:05:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-125367</guid>
		<description>Noggin, take a look at the post concerning bypassing the admin password, all you need is there</description>
		<content:encoded><![CDATA[<p>Noggin, take a look at the post concerning bypassing the admin password, all you need is there</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Noggin</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-125308</link>
		<dc:creator>Noggin</dc:creator>
		<pubDate>Thu, 15 Jan 2009 09:58:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-125308</guid>
		<description>I am connected to a BT Home Hub with the WPA2 key (it&#039;s a long story how I got that!) and when I browse 192.168.1.254 I get the &quot;Change your admin password for the first time&quot; screen, showing version 8.1.A

I&#039;ve tried entering the serial number (from the BT Home Hub Admin app plus &quot;CP&quot; in front) but it tells me it is invalid. I have another BT Home Hub and once I&#039;ve changed the admin password this screen no longer shows.

Any ideas how I can gain access to the admin pages?</description>
		<content:encoded><![CDATA[<p>I am connected to a BT Home Hub with the WPA2 key (it&#8217;s a long story how I got that!) and when I browse 192.168.1.254 I get the &#8220;Change your admin password for the first time&#8221; screen, showing version 8.1.A</p>
<p>I&#8217;ve tried entering the serial number (from the BT Home Hub Admin app plus &#8220;CP&#8221; in front) but it tells me it is invalid. I have another BT Home Hub and once I&#8217;ve changed the admin password this screen no longer shows.</p>
<p>Any ideas how I can gain access to the admin pages?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pwning Ubuntu via CUPS &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-124365</link>
		<dc:creator>Pwning Ubuntu via CUPS &#124; GNUCITIZEN</dc:creator>
		<pubDate>Tue, 18 Nov 2008 13:43:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-124365</guid>
		<description>[...] similar to our previously-published BT Home Hub vulnerabilities, it&#8217;s possible to use the victim&#8217;s browser as a bridge to talk to a service/daemon [...]</description>
		<content:encoded><![CDATA[<p>[...] similar to our previously-published BT Home Hub vulnerabilities, it&#8217;s possible to use the victim&#8217;s browser as a bridge to talk to a service/daemon [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Arie&#8217;s Blog &#187; Blog Archive &#187; Hacking Online&#8217;s new modem</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-123406</link>
		<dc:creator>Arie&#8217;s Blog &#187; Blog Archive &#187; Hacking Online&#8217;s new modem</dc:creator>
		<pubDate>Thu, 28 Aug 2008 13:45:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-123406</guid>
		<description>[...] some googling I came across a vulnerability in the Speedtouch 780, that allows you to access any page of the webinterface, even the ones you shouldn&#8217;t have [...]</description>
		<content:encoded><![CDATA[<p>[...] some googling I came across a vulnerability in the Speedtouch 780, that allows you to access any page of the webinterface, even the ones you shouldn&#8217;t have [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pwnie Award Nominee &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-123074</link>
		<dc:creator>Pwnie Award Nominee &#124; GNUCITIZEN</dc:creator>
		<pubDate>Thu, 24 Jul 2008 14:53:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-123074</guid>
		<description>[...] a friend of mind let me know that some of my BT Home Hub security research (details here and here) got nominated for the Pwnie [...]</description>
		<content:encoded><![CDATA[<p>[...] a friend of mind let me know that some of my BT Home Hub security research (details here and here) got nominated for the Pwnie [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Holes in Embedded Devices: Authentication bypass (pt 1) &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-114711</link>
		<dc:creator>Holes in Embedded Devices: Authentication bypass (pt 1) &#124; GNUCITIZEN</dc:creator>
		<pubDate>Thu, 14 Feb 2008 12:13:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-114711</guid>
		<description>[...] instance, the BT Home Hub, which is the most popular DSL router in the UK is vulnerable to an authentication bypass bug due to the device accepting multiple representations of the same [...]</description>
		<content:encoded><![CDATA[<p>[...] instance, the BT Home Hub, which is the most popular DSL router in the UK is vulnerable to an authentication bypass bug due to the device accepting multiple representations of the same [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Voice of VOIPSA &#187; Blog Archive &#187; Amusing Vulnerability in the BT Home Hub</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-102698</link>
		<dc:creator>Voice of VOIPSA &#187; Blog Archive &#187; Amusing Vulnerability in the BT Home Hub</dc:creator>
		<pubDate>Wed, 23 Jan 2008 17:51:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-102698</guid>
		<description>[...] upon a previously reported (and still un-patched!) vulnerability in the BT Home Hub which allows HTTP authentication to be bypassed, the folks over at GNUCitizen [...]</description>
		<content:encoded><![CDATA[<p>[...] upon a previously reported (and still un-patched!) vulnerability in the BT Home Hub which allows HTTP authentication to be bypassed, the folks over at GNUCitizen [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: norm</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-102197</link>
		<dc:creator>norm</dc:creator>
		<pubDate>Mon, 21 Jan 2008 22:09:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-102197</guid>
		<description>The new Home Hub firmware (6.2.6E) removes these exploits.

However if you gain wireless access to the device (which isn&#039;t difficult if it&#039;s on WEP) you will find the default password has been changed to the serial number of the device (unless the owner changed it since).

Now you might think getting the serial number would be impossible without physical access, but using the firmware recovery tool provided by BT it will tell you the serial number on finding it. Then all you do is add the two characters &#039;CP&#039; infront of it to make it valid e.g. CP01234ABCD.

From there I guess the possibility lies with downgrading the firmware to a more vulnerable version.</description>
		<content:encoded><![CDATA[<p>The new Home Hub firmware (6.2.6E) removes these exploits.</p>
<p>However if you gain wireless access to the device (which isn&#8217;t difficult if it&#8217;s on WEP) you will find the default password has been changed to the serial number of the device (unless the owner changed it since).</p>
<p>Now you might think getting the serial number would be impossible without physical access, but using the firmware recovery tool provided by BT it will tell you the serial number on finding it. Then all you do is add the two characters &#8216;CP&#8217; infront of it to make it valid e.g. CP01234ABCD.</p>
<p>From there I guess the possibility lies with downgrading the firmware to a more vulnerable version.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Call Jacking: Phreaking the BT Home Hub &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-101931</link>
		<dc:creator>Call Jacking: Phreaking the BT Home Hub &#124; GNUCITIZEN</dc:creator>
		<pubDate>Mon, 21 Jan 2008 02:47:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-101931</guid>
		<description>[...] Reason for this is that the exploit relies on an authentication bypass vulnerability that we have reported a while ago and hasn&#8217;t still been fixed by BT! In our original report, we mentioned that the [...]</description>
		<content:encoded><![CDATA[<p>[...] Reason for this is that the exploit relies on an authentication bypass vulnerability that we have reported a while ago and hasn&#8217;t still been fixed by BT! In our original report, we mentioned that the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BT Home Flub: Pwnin the BT Home Hub (5) - exploiting IGDs remotely via UPnP &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-98006</link>
		<dc:creator>BT Home Flub: Pwnin the BT Home Hub (5) - exploiting IGDs remotely via UPnP &#124; GNUCITIZEN</dc:creator>
		<pubDate>Thu, 10 Jan 2008 11:46:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-98006</guid>
		<description>[...] if you find a pre-auth XSS vulnerability on the target device you can bypass such restriction. For instance, many devices such as the BT [...]</description>
		<content:encoded><![CDATA[<p>[...] if you find a pre-auth XSS vulnerability on the target device you can bypass such restriction. For instance, many devices such as the BT [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: t3h 1337</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-90087</link>
		<dc:creator>t3h 1337</dc:creator>
		<pubDate>Sat, 22 Dec 2007 07:16:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-90087</guid>
		<description>Any 0day for 626c?</description>
		<content:encoded><![CDATA[<p>Any 0day for 626c?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-76430</link>
		<dc:creator>Rob</dc:creator>
		<pubDate>Sat, 24 Nov 2007 17:08:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-76430</guid>
		<description>I don&#039;t suppose there is an exploit in 6.2.6.B that allows telnet access?</description>
		<content:encoded><![CDATA[<p>I don&#8217;t suppose there is an exploit in 6.2.6.B that allows telnet access?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: \-=[WHK]=-// &#187; Archive &#187; Hackeando un HUB &#8220;BT Home Hub&#8221;</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-71541</link>
		<dc:creator>\-=[WHK]=-// &#187; Archive &#187; Hackeando un HUB &#8220;BT Home Hub&#8221;</dc:creator>
		<pubDate>Thu, 15 Nov 2007 19:38:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-71541</guid>
		<description>[...] Fuentes: http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub  http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-2 http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-3 http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4 [...]</description>
		<content:encoded><![CDATA[<p>[...] Fuentes: <a href="http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub" rel="nofollow">http://www.gnucitizen.org/blog.....t-home-hub</a>  <a href="http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-2" rel="nofollow">http://www.gnucitizen.org/blog.....home-hub-2</a> <a href="http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-3" rel="nofollow">http://www.gnucitizen.org/blog.....home-hub-3</a> <a href="http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4" rel="nofollow">http://www.gnucitizen.org/blog.....home-hub-4</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: - TERIS - &#187; Blog Archive &#187; Acceso a routers vulnerables de uso doméstico</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-71023</link>
		<dc:creator>- TERIS - &#187; Blog Archive &#187; Acceso a routers vulnerables de uso doméstico</dc:creator>
		<pubDate>Thu, 15 Nov 2007 05:00:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-71023</guid>
		<description>[...] Exploits: http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4 [...]</description>
		<content:encoded><![CDATA[<p>[...] Exploits: <a href="http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4" rel="nofollow">http://www.gnucitizen.org/blog.....home-hub-4</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Acceso a routers vulnerables de uso doméstico &#171; blog NeTTinG</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-70273</link>
		<dc:creator>Acceso a routers vulnerables de uso doméstico &#171; blog NeTTinG</dc:creator>
		<pubDate>Tue, 13 Nov 2007 22:52:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-70273</guid>
		<description>[...] Exploits: http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4 [...]</description>
		<content:encoded><![CDATA[<p>[...] Exploits: <a href="http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4" rel="nofollow">http://www.gnucitizen.org/blog.....home-hub-4</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CBM Security Blog &#187; Blog Archive &#187; BT Home Hub still vulnerable</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-69705</link>
		<dc:creator>CBM Security Blog &#187; Blog Archive &#187; BT Home Hub still vulnerable</dc:creator>
		<pubDate>Mon, 12 Nov 2007 14:16:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-69705</guid>
		<description>[...] The details about the ongoing and very real problems about the BT Home Hub can be found here. http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4 [...]</description>
		<content:encoded><![CDATA[<p>[...] The details about the ongoing and very real problems about the BT Home Hub can be found here. <a href="http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4" rel="nofollow">http://www.gnucitizen.org/blog.....home-hub-4</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian Pastor</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-69115</link>
		<dc:creator>Adrian Pastor</dc:creator>
		<pubDate>Sun, 11 Nov 2007 12:03:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-69115</guid>
		<description>Here is the demo video for Exploit #3 : http://www.youtube.com/watch?v=QiFQPKcAtNI</description>
		<content:encoded><![CDATA[<p>Here is the demo video for Exploit #3 : <a href="http://www.youtube.com/watch?v=QiFQPKcAtNI" rel="nofollow">http://www.youtube.com/watch?v=QiFQPKcAtNI</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian Pastor</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-67990</link>
		<dc:creator>Adrian Pastor</dc:creator>
		<pubDate>Fri, 09 Nov 2007 09:45:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-67990</guid>
		<description>@G-Brain - fair enough! I see what you mean, I guess I wasted a few CPU cycles in the script. 

You&#039;re right though, if you want to be perfectionist, the definitions on &#039;steal.php&#039; should be under the IF statement.</description>
		<content:encoded><![CDATA[<p>@G-Brain &#8211; fair enough! I see what you mean, I guess I wasted a few CPU cycles in the script. </p>
<p>You&#8217;re right though, if you want to be perfectionist, the definitions on &#8217;steal.php&#8217; should be under the IF statement.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: G-Brain</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-67831</link>
		<dc:creator>G-Brain</dc:creator>
		<pubDate>Thu, 08 Nov 2007 23:00:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-67831</guid>
		<description>I see, thanks for the explanation. I don&#039;t see why  those definitions of RCPT_EMAIL and EMAIL_SUBJECT are made even when there is no $_REQUEST[&#039;data&#039;] though... ;)</description>
		<content:encoded><![CDATA[<p>I see, thanks for the explanation. I don&#8217;t see why  those definitions of RCPT_EMAIL and EMAIL_SUBJECT are made even when there is no $_REQUEST['data'] though&#8230; ;)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
