<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Call Jacking: Phreaking the BT Home Hub</title>
	<atom:link href="http://www.gnucitizen.org/blog/call-jacking-phreaking-the-bt-home-hub/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/call-jacking-phreaking-the-bt-home-hub/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Mon, 12 Dec 2011 19:56:03 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.2</generator>
	<item>
		<title>By: Trackback - Free Internation Call &#62;&#62; How to make free international call</title>
		<link>http://www.gnucitizen.org/blog/call-jacking-phreaking-the-bt-home-hub/comment-page-1/#comment-128000</link>
		<dc:creator>Trackback - Free Internation Call &#62;&#62; How to make free international call</dc:creator>
		<pubDate>Thu, 19 Nov 2009 21:55:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/call-jacking#comment-128000</guid>
		<description>,[...] www.gnucitizen.org is other great source on this subject,[...]</description>
		<content:encoded><![CDATA[<p>,[...] <a href="http://www.gnucitizen.org" rel="nofollow">http://www.gnucitizen.org</a> is other great source on this subject,[...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Test-Guru</title>
		<link>http://www.gnucitizen.org/blog/call-jacking-phreaking-the-bt-home-hub/comment-page-1/#comment-127623</link>
		<dc:creator>Test-Guru</dc:creator>
		<pubDate>Mon, 13 Jul 2009 18:57:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/call-jacking#comment-127623</guid>
		<description>I cannot believe this is true!</description>
		<content:encoded><![CDATA[<p>I cannot believe this is true!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Beware the BT home hub &#124; hilpers</title>
		<link>http://www.gnucitizen.org/blog/call-jacking-phreaking-the-bt-home-hub/comment-page-1/#comment-125383</link>
		<dc:creator>Beware the BT home hub &#124; hilpers</dc:creator>
		<pubDate>Sun, 18 Jan 2009 18:37:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/call-jacking#comment-125383</guid>
		<description>[...] Beware the BT home hub     has become of interest to phreakers, if they can tempt you to visit thier naughty wibble it allows them to molish zbarlous VoIP calls at your expense.  http://www.gnucitizen.org/blog/call-jacking [...]</description>
		<content:encoded><![CDATA[<p>[...] Beware the BT home hub     has become of interest to phreakers, if they can tempt you to visit thier naughty wibble it allows them to molish zbarlous VoIP calls at your expense.  <a href="http://www.gnucitizen.org/blog/call-jacking" rel="nofollow">http://www.gnucitizen.org/blog/call-jacking</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Holes in Embedded Devices: Authentication bypass (pt 2) &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/call-jacking-phreaking-the-bt-home-hub/comment-page-1/#comment-114824</link>
		<dc:creator>Holes in Embedded Devices: Authentication bypass (pt 2) &#124; GNUCITIZEN</dc:creator>
		<pubDate>Fri, 15 Feb 2008 17:18:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/call-jacking#comment-114824</guid>
		<description>[...] http://www.gnucitizen.org/blog/call-jacking [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://www.gnucitizen.org/blog/call-jacking" rel="nofollow">http://www.gnucitizen.org/blog/call-jacking</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Call Jacking &#124; VoipBloggen</title>
		<link>http://www.gnucitizen.org/blog/call-jacking-phreaking-the-bt-home-hub/comment-page-1/#comment-114790</link>
		<dc:creator>Call Jacking &#124; VoipBloggen</dc:creator>
		<pubDate>Fri, 15 Feb 2008 06:03:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/call-jacking#comment-114790</guid>
		<description>[...] Gnucitizen er jeg faldet over dette spÃ¦ndende indlÃ¦g om Call Jacking, hvilket svarer til Hi Jacking, altsÃ¥ en erobring af folks [...]</description>
		<content:encoded><![CDATA[<p>[...] Gnucitizen er jeg faldet over dette spÃ¦ndende indlÃ¦g om Call Jacking, hvilket svarer til Hi Jacking, altsÃ¥ en erobring af folks [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Total surveillance made easy with VoIP phones &#187; Inking&#8217;s Security Blog</title>
		<link>http://www.gnucitizen.org/blog/call-jacking-phreaking-the-bt-home-hub/comment-page-1/#comment-113396</link>
		<dc:creator>Total surveillance made easy with VoIP phones &#187; Inking&#8217;s Security Blog</dc:creator>
		<pubDate>Tue, 12 Feb 2008 05:29:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/call-jacking#comment-113396</guid>
		<description>[...] the article about call jacking with the BT Home Hub? Here is something comparable but pretty new. Since Ronald and pdp had [...]</description>
		<content:encoded><![CDATA[<p>[...] the article about call jacking with the BT Home Hub? Here is something comparable but pretty new. Since Ronald and pdp had [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Total surveillance made easy with VoIP phones &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/call-jacking-phreaking-the-bt-home-hub/comment-page-1/#comment-113213</link>
		<dc:creator>Total surveillance made easy with VoIP phones &#124; GNUCITIZEN</dc:creator>
		<pubDate>Mon, 11 Feb 2008 22:03:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/call-jacking#comment-113213</guid>
		<description>[...] the article about call jacking with the BT Home Hub? Here is something comparable but pretty new. Since Ronald and pdp had [...]</description>
		<content:encoded><![CDATA[<p>[...] the article about call jacking with the BT Home Hub? Here is something comparable but pretty new. Since Ronald and pdp had [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Voice over IP Calljacking &#171; security matters</title>
		<link>http://www.gnucitizen.org/blog/call-jacking-phreaking-the-bt-home-hub/comment-page-1/#comment-113057</link>
		<dc:creator>Voice over IP Calljacking &#171; security matters</dc:creator>
		<pubDate>Mon, 11 Feb 2008 11:41:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/call-jacking#comment-113057</guid>
		<description>[...] nicht bietet gnucitizen ein Beispiel wie der VOIP-Router von British Telecom (BT) dazu genutzt werden kann, ungewollte [...]</description>
		<content:encoded><![CDATA[<p>[...] nicht bietet gnucitizen ein Beispiel wie der VOIP-Router von British Telecom (BT) dazu genutzt werden kann, ungewollte [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian Pastor</title>
		<link>http://www.gnucitizen.org/blog/call-jacking-phreaking-the-bt-home-hub/comment-page-1/#comment-103465</link>
		<dc:creator>Adrian Pastor</dc:creator>
		<pubDate>Fri, 25 Jan 2008 12:34:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/call-jacking#comment-103465</guid>
		<description>It looks like other home hub users who are also running firmware 6.2.6.B have confirmed our VoIP call jacking hack: http://www.digitalspy.co.uk/forums/showthread.php?t=735655&amp;highlight=6.2.6.B</description>
		<content:encoded><![CDATA[<p>It looks like other home hub users who are also running firmware 6.2.6.B have confirmed our VoIP call jacking hack: <a href="http://www.digitalspy.co.uk/forums/showthread.php?t=735655&#038;highlight=6.2.6.B" rel="nofollow">http://www.digitalspy.co.uk/fo.....ht=6.2.6.B</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian Pastor</title>
		<link>http://www.gnucitizen.org/blog/call-jacking-phreaking-the-bt-home-hub/comment-page-1/#comment-103210</link>
		<dc:creator>Adrian Pastor</dc:creator>
		<pubDate>Fri, 25 Jan 2008 01:20:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/call-jacking#comment-103210</guid>
		<description>@David - I guess there is something contagious about my laugh? hehehe

@hackathology - you&#039;re welcome dude!

@Avee - actually it&#039;d be quite simple to setup a tool that allows you to dial phone numbers from your laptop with a simple HTML.</description>
		<content:encoded><![CDATA[<p>@David &#8211; I guess there is something contagious about my laugh? hehehe</p>
<p>@hackathology &#8211; you&#8217;re welcome dude!</p>
<p>@Avee &#8211; actually it&#8217;d be quite simple to setup a tool that allows you to dial phone numbers from your laptop with a simple HTML.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Avee</title>
		<link>http://www.gnucitizen.org/blog/call-jacking-phreaking-the-bt-home-hub/comment-page-1/#comment-102613</link>
		<dc:creator>Avee</dc:creator>
		<pubDate>Wed, 23 Jan 2008 10:54:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/call-jacking#comment-102613</guid>
		<description>This is pretty useful for autodialing stuff from my laptop. Thanks!</description>
		<content:encoded><![CDATA[<p>This is pretty useful for autodialing stuff from my laptop. Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hackathology</title>
		<link>http://www.gnucitizen.org/blog/call-jacking-phreaking-the-bt-home-hub/comment-page-1/#comment-102532</link>
		<dc:creator>hackathology</dc:creator>
		<pubDate>Wed, 23 Jan 2008 03:26:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/call-jacking#comment-102532</guid>
		<description>thanks Adrian.</description>
		<content:encoded><![CDATA[<p>thanks Adrian.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Kierznowski</title>
		<link>http://www.gnucitizen.org/blog/call-jacking-phreaking-the-bt-home-hub/comment-page-1/#comment-102445</link>
		<dc:creator>David Kierznowski</dc:creator>
		<pubDate>Tue, 22 Jan 2008 20:10:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/call-jacking#comment-102445</guid>
		<description>Adrian&#039;s laugh is always comical :)</description>
		<content:encoded><![CDATA[<p>Adrian&#8217;s laugh is always comical :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#187; Voip flaw in BT router or just an unpatched vulnerability? &#124; IT News Digest &#124; TechRepublic.com</title>
		<link>http://www.gnucitizen.org/blog/call-jacking-phreaking-the-bt-home-hub/comment-page-1/#comment-102407</link>
		<dc:creator>&#187; Voip flaw in BT router or just an unpatched vulnerability? &#124; IT News Digest &#124; TechRepublic.com</dc:creator>
		<pubDate>Tue, 22 Jan 2008 17:31:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/call-jacking#comment-102407</guid>
		<description>[...] video of the voip exploit is available on YouTube and also details on the flaw as mentioned on the blog of the GNUCitizen Blog are: In summary, if the victim visits our evil proof-of-concept webpage, his/her browser sends a [...]</description>
		<content:encoded><![CDATA[<p>[...] video of the voip exploit is available on YouTube and also details on the flaw as mentioned on the blog of the GNUCitizen Blog are: In summary, if the victim visits our evil proof-of-concept webpage, his/her browser sends a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: goundoulf</title>
		<link>http://www.gnucitizen.org/blog/call-jacking-phreaking-the-bt-home-hub/comment-page-1/#comment-102362</link>
		<dc:creator>goundoulf</dc:creator>
		<pubDate>Tue, 22 Jan 2008 14:03:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/call-jacking#comment-102362</guid>
		<description>The only way to prevent this with ISP gateways is...

projects like http://www.neufbox4.org which aims at creating an alternative and entirely open firmware for the gateway

ISPs usually break the GPL by using free software and not redistributing, and their gateways rely on security by obscurity.

The customer is then dependent on the firmware upgrade from the ISP following the discovery of a vulnerability, and some times it can take ages before it is corrected.

When the community is in charge of an alternative firmware, vulnerabilities are spotted earlier and corrected faster.</description>
		<content:encoded><![CDATA[<p>The only way to prevent this with ISP gateways is&#8230;</p>
<p>projects like <a href="http://www.neufbox4.org" rel="nofollow">http://www.neufbox4.org</a> which aims at creating an alternative and entirely open firmware for the gateway</p>
<p>ISPs usually break the GPL by using free software and not redistributing, and their gateways rely on security by obscurity.</p>
<p>The customer is then dependent on the firmware upgrade from the ISP following the discovery of a vulnerability, and some times it can take ages before it is corrected.</p>
<p>When the community is in charge of an alternative firmware, vulnerabilities are spotted earlier and corrected faster.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian Pastor</title>
		<link>http://www.gnucitizen.org/blog/call-jacking-phreaking-the-bt-home-hub/comment-page-1/#comment-102355</link>
		<dc:creator>Adrian Pastor</dc:creator>
		<pubDate>Tue, 22 Jan 2008 13:35:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/call-jacking#comment-102355</guid>
		<description>@hackathology - 00390669893461 is an international phone number located in the country whose code is 39 (vatican city in this case): http://www.countrycallingcodes.com/Reverse-Lookup.php?calling-code=39

@Tim - they prob. fixed it. We tested it on 6.2.6.B, which was the most udpated firmware we could get at time of testing without being part of FON. I believe that signing up for FON makes your Home Hub upgrade to a newer firmware? Correct me if I&#039;m wrong.

as pdp pointed out, firmware version 6.2.6.E can take several weeks to upgrade and it appears that many users are having problems receiving the new firmware.</description>
		<content:encoded><![CDATA[<p>@hackathology &#8211; 00390669893461 is an international phone number located in the country whose code is 39 (vatican city in this case): <a href="http://www.countrycallingcodes.com/Reverse-Lookup.php?calling-code=39" rel="nofollow">http://www.countrycallingcodes.....ng-code=39</a></p>
<p>@Tim &#8211; they prob. fixed it. We tested it on 6.2.6.B, which was the most udpated firmware we could get at time of testing without being part of FON. I believe that signing up for FON makes your Home Hub upgrade to a newer firmware? Correct me if I&#8217;m wrong.</p>
<p>as pdp pointed out, firmware version 6.2.6.E can take several weeks to upgrade and it appears that many users are having problems receiving the new firmware.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/call-jacking-phreaking-the-bt-home-hub/comment-page-1/#comment-102342</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Tue, 22 Jan 2008 12:42:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/call-jacking#comment-102342</guid>
		<description>&lt;blockquote&gt;The rollout of the BT Home Hub firmware version 6.2.6.E started on 12 December 2007. It can take several weeks before all BT Home Hubs are upgraded to a new version of the firmware, so please be patient. &lt;a href=&quot;http://bt.custhelp.com/cgi-bin/bt.cfg/php/enduser/cci/bt_adp.php?cat_lvl1=346&amp;cat_lvl2=401&amp;cat_lvl3=407&amp;cat_lvl4=751&amp;p_cv=4.751&amp;p_cats=346,401,407,751&amp;p_faqid=9381&quot; rel=&quot;nofollow&quot;&gt;BT Support &amp; Advice&lt;/a&gt;&lt;/blockquote&gt;</description>
		<content:encoded><![CDATA[<blockquote><p>The rollout of the BT Home Hub firmware version 6.2.6.E started on 12 December 2007. It can take several weeks before all BT Home Hubs are upgraded to a new version of the firmware, so please be patient. <a href="http://bt.custhelp.com/cgi-bin/bt.cfg/php/enduser/cci/bt_adp.php?cat_lvl1=346&#038;cat_lvl2=401&#038;cat_lvl3=407&#038;cat_lvl4=751&#038;p_cv=4.751&#038;p_cats=346,401,407,751&#038;p_faqid=9381" rel="nofollow">BT Support &#038; Advice</a></p></blockquote>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ben Tasker</title>
		<link>http://www.gnucitizen.org/blog/call-jacking-phreaking-the-bt-home-hub/comment-page-1/#comment-102340</link>
		<dc:creator>Ben Tasker</dc:creator>
		<pubDate>Tue, 22 Jan 2008 12:33:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/call-jacking#comment-102340</guid>
		<description>Either BT have now fixed it, or not all BT Home Hubs are vulnerable. Mine simply asks for the username and password, and then asks again when I hit cancel.

The phone never rings afterwards, I do have BT BroadBand Talk and a BT Home Hub running Version 6.2.6.E</description>
		<content:encoded><![CDATA[<p>Either BT have now fixed it, or not all BT Home Hubs are vulnerable. Mine simply asks for the username and password, and then asks again when I hit cancel.</p>
<p>The phone never rings afterwards, I do have BT BroadBand Talk and a BT Home Hub running Version 6.2.6.E</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim</title>
		<link>http://www.gnucitizen.org/blog/call-jacking-phreaking-the-bt-home-hub/comment-page-1/#comment-102335</link>
		<dc:creator>Tim</dc:creator>
		<pubDate>Tue, 22 Jan 2008 12:16:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/call-jacking#comment-102335</guid>
		<description>BT have claimed this attack doesn&#039;t work with the firmware they have rolled out at the moment.</description>
		<content:encoded><![CDATA[<p>BT have claimed this attack doesn&#8217;t work with the firmware they have rolled out at the moment.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: phil_mcracken</title>
		<link>http://www.gnucitizen.org/blog/call-jacking-phreaking-the-bt-home-hub/comment-page-1/#comment-102309</link>
		<dc:creator>phil_mcracken</dc:creator>
		<pubDate>Tue, 22 Jan 2008 09:34:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/call-jacking#comment-102309</guid>
		<description>If I blackholed the DNS for api.home on my local machine (and others on the network) in the HOSTS file, surely that would render this attack useless?</description>
		<content:encoded><![CDATA[<p>If I blackholed the DNS for api.home on my local machine (and others on the network) in the HOSTS file, surely that would render this attack useless?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

