<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: BT Home Flub: Pwnin the BT Home Hub (4)</title>
	<atom:link href="http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Mon, 12 Dec 2011 19:56:03 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.2</generator>
	<item>
		<title>By: bobp</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-128841</link>
		<dc:creator>bobp</dc:creator>
		<pubDate>Wed, 01 Sep 2010 09:57:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-128841</guid>
		<description>Is there any way to reset admin password, other than doing factory reset of router?</description>
		<content:encoded><![CDATA[<p>Is there any way to reset admin password, other than doing factory reset of router?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JC</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-128546</link>
		<dc:creator>JC</dc:creator>
		<pubDate>Wed, 09 Jun 2010 18:39:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-128546</guid>
		<description>The first thing I do with any router is to change its ip address and the range of ips that the lan users can use and turn of dhcp. This would mean your script would have in theory to cover the whole range of private ip addresses from the Wan side and make access from the lan side much more difficult</description>
		<content:encoded><![CDATA[<p>The first thing I do with any router is to change its ip address and the range of ips that the lan users can use and turn of dhcp. This would mean your script would have in theory to cover the whole range of private ip addresses from the Wan side and make access from the lan side much more difficult</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Burns</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-126701</link>
		<dc:creator>Richard Burns</dc:creator>
		<pubDate>Wed, 29 Apr 2009 07:00:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-126701</guid>
		<description>This all seems pointless, tell me i&#039;m wrong. How can you run any of this unless your on the network? I am surrounded by at least 10 hubs and need to access one of them??</description>
		<content:encoded><![CDATA[<p>This all seems pointless, tell me i&#8217;m wrong. How can you run any of this unless your on the network? I am surrounded by at least 10 hubs and need to access one of them??</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jonnycorer77</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-125367</link>
		<dc:creator>Jonnycorer77</dc:creator>
		<pubDate>Sat, 17 Jan 2009 20:05:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-125367</guid>
		<description>Noggin, take a look at the post concerning bypassing the admin password, all you need is there</description>
		<content:encoded><![CDATA[<p>Noggin, take a look at the post concerning bypassing the admin password, all you need is there</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Noggin</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-125308</link>
		<dc:creator>Noggin</dc:creator>
		<pubDate>Thu, 15 Jan 2009 09:58:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-125308</guid>
		<description>I am connected to a BT Home Hub with the WPA2 key (it&#039;s a long story how I got that!) and when I browse 192.168.1.254 I get the &quot;Change your admin password for the first time&quot; screen, showing version 8.1.A

I&#039;ve tried entering the serial number (from the BT Home Hub Admin app plus &quot;CP&quot; in front) but it tells me it is invalid. I have another BT Home Hub and once I&#039;ve changed the admin password this screen no longer shows.

Any ideas how I can gain access to the admin pages?</description>
		<content:encoded><![CDATA[<p>I am connected to a BT Home Hub with the WPA2 key (it&#8217;s a long story how I got that!) and when I browse 192.168.1.254 I get the &#8220;Change your admin password for the first time&#8221; screen, showing version 8.1.A</p>
<p>I&#8217;ve tried entering the serial number (from the BT Home Hub Admin app plus &#8220;CP&#8221; in front) but it tells me it is invalid. I have another BT Home Hub and once I&#8217;ve changed the admin password this screen no longer shows.</p>
<p>Any ideas how I can gain access to the admin pages?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pwning Ubuntu via CUPS &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-124365</link>
		<dc:creator>Pwning Ubuntu via CUPS &#124; GNUCITIZEN</dc:creator>
		<pubDate>Tue, 18 Nov 2008 13:43:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-124365</guid>
		<description>[...] similar to our previously-published BT Home Hub vulnerabilities, it&#8217;s possible to use the victim&#8217;s browser as a bridge to talk to a service/daemon [...]</description>
		<content:encoded><![CDATA[<p>[...] similar to our previously-published BT Home Hub vulnerabilities, it&#8217;s possible to use the victim&#8217;s browser as a bridge to talk to a service/daemon [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Arie&#8217;s Blog &#187; Blog Archive &#187; Hacking Online&#8217;s new modem</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-123406</link>
		<dc:creator>Arie&#8217;s Blog &#187; Blog Archive &#187; Hacking Online&#8217;s new modem</dc:creator>
		<pubDate>Thu, 28 Aug 2008 13:45:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-123406</guid>
		<description>[...] some googling I came across a vulnerability in the Speedtouch 780, that allows you to access any page of the webinterface, even the ones you shouldn&#8217;t have [...]</description>
		<content:encoded><![CDATA[<p>[...] some googling I came across a vulnerability in the Speedtouch 780, that allows you to access any page of the webinterface, even the ones you shouldn&#8217;t have [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pwnie Award Nominee &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-123074</link>
		<dc:creator>Pwnie Award Nominee &#124; GNUCITIZEN</dc:creator>
		<pubDate>Thu, 24 Jul 2008 14:53:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-123074</guid>
		<description>[...] a friend of mind let me know that some of my BT Home Hub security research (details here and here) got nominated for the Pwnie [...]</description>
		<content:encoded><![CDATA[<p>[...] a friend of mind let me know that some of my BT Home Hub security research (details here and here) got nominated for the Pwnie [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Holes in Embedded Devices: Authentication bypass (pt 1) &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-114711</link>
		<dc:creator>Holes in Embedded Devices: Authentication bypass (pt 1) &#124; GNUCITIZEN</dc:creator>
		<pubDate>Thu, 14 Feb 2008 12:13:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-114711</guid>
		<description>[...] instance, the BT Home Hub, which is the most popular DSL router in the UK is vulnerable to an authentication bypass bug due to the device accepting multiple representations of the same [...]</description>
		<content:encoded><![CDATA[<p>[...] instance, the BT Home Hub, which is the most popular DSL router in the UK is vulnerable to an authentication bypass bug due to the device accepting multiple representations of the same [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Voice of VOIPSA &#187; Blog Archive &#187; Amusing Vulnerability in the BT Home Hub</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-102698</link>
		<dc:creator>Voice of VOIPSA &#187; Blog Archive &#187; Amusing Vulnerability in the BT Home Hub</dc:creator>
		<pubDate>Wed, 23 Jan 2008 17:51:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-102698</guid>
		<description>[...] upon a previously reported (and still un-patched!) vulnerability in the BT Home Hub which allows HTTP authentication to be bypassed, the folks over at GNUCitizen [...]</description>
		<content:encoded><![CDATA[<p>[...] upon a previously reported (and still un-patched!) vulnerability in the BT Home Hub which allows HTTP authentication to be bypassed, the folks over at GNUCitizen [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: norm</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-102197</link>
		<dc:creator>norm</dc:creator>
		<pubDate>Mon, 21 Jan 2008 22:09:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-102197</guid>
		<description>The new Home Hub firmware (6.2.6E) removes these exploits.

However if you gain wireless access to the device (which isn&#039;t difficult if it&#039;s on WEP) you will find the default password has been changed to the serial number of the device (unless the owner changed it since).

Now you might think getting the serial number would be impossible without physical access, but using the firmware recovery tool provided by BT it will tell you the serial number on finding it. Then all you do is add the two characters &#039;CP&#039; infront of it to make it valid e.g. CP01234ABCD.

From there I guess the possibility lies with downgrading the firmware to a more vulnerable version.</description>
		<content:encoded><![CDATA[<p>The new Home Hub firmware (6.2.6E) removes these exploits.</p>
<p>However if you gain wireless access to the device (which isn&#8217;t difficult if it&#8217;s on WEP) you will find the default password has been changed to the serial number of the device (unless the owner changed it since).</p>
<p>Now you might think getting the serial number would be impossible without physical access, but using the firmware recovery tool provided by BT it will tell you the serial number on finding it. Then all you do is add the two characters &#8216;CP&#8217; infront of it to make it valid e.g. CP01234ABCD.</p>
<p>From there I guess the possibility lies with downgrading the firmware to a more vulnerable version.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Call Jacking: Phreaking the BT Home Hub &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-101931</link>
		<dc:creator>Call Jacking: Phreaking the BT Home Hub &#124; GNUCITIZEN</dc:creator>
		<pubDate>Mon, 21 Jan 2008 02:47:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-101931</guid>
		<description>[...] Reason for this is that the exploit relies on an authentication bypass vulnerability that we have reported a while ago and hasn&#8217;t still been fixed by BT! In our original report, we mentioned that the [...]</description>
		<content:encoded><![CDATA[<p>[...] Reason for this is that the exploit relies on an authentication bypass vulnerability that we have reported a while ago and hasn&#8217;t still been fixed by BT! In our original report, we mentioned that the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BT Home Flub: Pwnin the BT Home Hub (5) - exploiting IGDs remotely via UPnP &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-98006</link>
		<dc:creator>BT Home Flub: Pwnin the BT Home Hub (5) - exploiting IGDs remotely via UPnP &#124; GNUCITIZEN</dc:creator>
		<pubDate>Thu, 10 Jan 2008 11:46:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-98006</guid>
		<description>[...] if you find a pre-auth XSS vulnerability on the target device you can bypass such restriction. For instance, many devices such as the BT [...]</description>
		<content:encoded><![CDATA[<p>[...] if you find a pre-auth XSS vulnerability on the target device you can bypass such restriction. For instance, many devices such as the BT [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: t3h 1337</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-90087</link>
		<dc:creator>t3h 1337</dc:creator>
		<pubDate>Sat, 22 Dec 2007 07:16:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-90087</guid>
		<description>Any 0day for 626c?</description>
		<content:encoded><![CDATA[<p>Any 0day for 626c?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-76430</link>
		<dc:creator>Rob</dc:creator>
		<pubDate>Sat, 24 Nov 2007 17:08:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-76430</guid>
		<description>I don&#039;t suppose there is an exploit in 6.2.6.B that allows telnet access?</description>
		<content:encoded><![CDATA[<p>I don&#8217;t suppose there is an exploit in 6.2.6.B that allows telnet access?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: \-=[WHK]=-// &#187; Archive &#187; Hackeando un HUB &#8220;BT Home Hub&#8221;</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-71541</link>
		<dc:creator>\-=[WHK]=-// &#187; Archive &#187; Hackeando un HUB &#8220;BT Home Hub&#8221;</dc:creator>
		<pubDate>Thu, 15 Nov 2007 19:38:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-71541</guid>
		<description>[...] Fuentes: http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub  http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-2 http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-3 http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4 [...]</description>
		<content:encoded><![CDATA[<p>[...] Fuentes: <a href="http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub" rel="nofollow">http://www.gnucitizen.org/blog.....t-home-hub</a>  <a href="http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-2" rel="nofollow">http://www.gnucitizen.org/blog.....home-hub-2</a> <a href="http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-3" rel="nofollow">http://www.gnucitizen.org/blog.....home-hub-3</a> <a href="http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4" rel="nofollow">http://www.gnucitizen.org/blog.....home-hub-4</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: - TERIS - &#187; Blog Archive &#187; Acceso a routers vulnerables de uso domÃ©stico</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-71023</link>
		<dc:creator>- TERIS - &#187; Blog Archive &#187; Acceso a routers vulnerables de uso domÃ©stico</dc:creator>
		<pubDate>Thu, 15 Nov 2007 05:00:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-71023</guid>
		<description>[...] Exploits: http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4 [...]</description>
		<content:encoded><![CDATA[<p>[...] Exploits: <a href="http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4" rel="nofollow">http://www.gnucitizen.org/blog.....home-hub-4</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Acceso a routers vulnerables de uso domÃ©stico &#171; blog NeTTinG</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-70273</link>
		<dc:creator>Acceso a routers vulnerables de uso domÃ©stico &#171; blog NeTTinG</dc:creator>
		<pubDate>Tue, 13 Nov 2007 22:52:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-70273</guid>
		<description>[...] Exploits: http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4 [...]</description>
		<content:encoded><![CDATA[<p>[...] Exploits: <a href="http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4" rel="nofollow">http://www.gnucitizen.org/blog.....home-hub-4</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CBM Security Blog &#187; Blog Archive &#187; BT Home Hub still vulnerable</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-69705</link>
		<dc:creator>CBM Security Blog &#187; Blog Archive &#187; BT Home Hub still vulnerable</dc:creator>
		<pubDate>Mon, 12 Nov 2007 14:16:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-69705</guid>
		<description>[...] The details about the ongoing and very real problems about the BT Home Hub can be found here. http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4 [...]</description>
		<content:encoded><![CDATA[<p>[...] The details about the ongoing and very real problems about the BT Home Hub can be found here. <a href="http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4" rel="nofollow">http://www.gnucitizen.org/blog.....home-hub-4</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian Pastor</title>
		<link>http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4/comment-page-1/#comment-69115</link>
		<dc:creator>Adrian Pastor</dc:creator>
		<pubDate>Sun, 11 Nov 2007 12:03:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/bt-home-flub-pwnin-the-bt-home-hub-4#comment-69115</guid>
		<description>Here is the demo video for Exploit #3 : http://www.youtube.com/watch?v=QiFQPKcAtNI</description>
		<content:encoded><![CDATA[<p>Here is the demo video for Exploit #3 : <a href="http://www.youtube.com/watch?v=QiFQPKcAtNI" rel="nofollow">http://www.youtube.com/watch?v=QiFQPKcAtNI</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>

