<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Dumping the admin password of the BT Home Hub (pt 2)</title>
	<atom:link href="http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/</link>
	<description>Information Security Think Tank</description>
	<pubDate>Fri, 29 Aug 2008 18:26:54 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By: Adrian 'pagvac' Pastor</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/#comment-122390</link>
		<dc:creator>Adrian 'pagvac' Pastor</dc:creator>
		<pubDate>Sat, 31 May 2008 08:33:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-122390</guid>
		<description>We got a winner :) I can confirm this works on the BT Home Hub v1, firmware 6.2.6.E. Good catch Aaron!

Any other ideas on how to obtain the Hub's S/N and therefore the default admin password? The more techniques the merrier!

btw, the troubleshooting page - which doesn't require a password to be seen - *used to* include the S/N but BT removed such info in the latest firmware: https://api.home/cgi/b/bttroubleshooting/</description>
		<content:encoded><![CDATA[<p>We got a winner :) I can confirm this works on the BT Home Hub v1, firmware 6.2.6.E. Good catch Aaron!</p>
<p>Any other ideas on how to obtain the Hub&#8217;s S/N and therefore the default admin password? The more techniques the merrier!</p>
<p>btw, the troubleshooting page - which doesn&#8217;t require a password to be seen - *used to* include the S/N but BT removed such info in the latest firmware: <a href="https://api.home/cgi/b/bttroubleshooting/" rel="nofollow">https://api.home/cgi/b/bttroubleshooting/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephen</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/#comment-122380</link>
		<dc:creator>Stephen</dc:creator>
		<pubDate>Fri, 30 May 2008 16:28:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-122380</guid>
		<description>I can verify that the OU of the SSL certificate gives the serial number on 6.2.6.E on my HH v1.5

Just point your browser to https://api.home/ and click examine certificate when prompted ;)</description>
		<content:encoded><![CDATA[<p>I can verify that the OU of the SSL certificate gives the serial number on 6.2.6.E on my HH v1.5</p>
<p>Just point your browser to <a href="https://api.home/" rel="nofollow">https://api.home/</a> and click examine certificate when prompted ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/#comment-122338</link>
		<dc:creator>Aaron</dc:creator>
		<pubDate>Thu, 29 May 2008 18:41:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-122338</guid>
		<description>You can dump the serial number of the HomeHub 6.2.6.E by connecting to the HTTPS port and examining the SSL Certificate... the default OU of the certificate issuer is the serial number of the device...

Hence, the pwndhub I am currently using has just dished out this after I ran a Nessus scan on it...

OU = 0641EHJRR
O = THOMSON
CN = BT Home Hub

Please verify this works for others...</description>
		<content:encoded><![CDATA[<p>You can dump the serial number of the HomeHub 6.2.6.E by connecting to the HTTPS port and examining the SSL Certificate&#8230; the default OU of the certificate issuer is the serial number of the device&#8230;</p>
<p>Hence, the pwndhub I am currently using has just dished out this after I ran a Nessus scan on it&#8230;</p>
<p>OU = 0641EHJRR<br />
O = THOMSON<br />
CN = BT Home Hub</p>
<p>Please verify this works for others&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian 'pagvac' Pastor</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/#comment-122318</link>
		<dc:creator>Adrian 'pagvac' Pastor</dc:creator>
		<pubDate>Wed, 28 May 2008 22:51:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-122318</guid>
		<description>The serial number disclosure reported in this post was originally tested on a BT Home Hub running firmware version 6.2.2.6. However, it appears that BT has replaced such information with the Hub's MAC address in the latest firmware (6.2.6.E at time of writing).

Since only the latest firmware uses the Hub's serial number as the default admin password, the reported serial number disclosure via UPnP XML description files is NOT exploitable. 

Nevertheless, the MDAP attack described in our previous post has been verified on the latest firmware and has been confirmed by several users both, on the BT Home Hub v1, and v1.5.</description>
		<content:encoded><![CDATA[<p>The serial number disclosure reported in this post was originally tested on a BT Home Hub running firmware version 6.2.2.6. However, it appears that BT has replaced such information with the Hub&#8217;s MAC address in the latest firmware (6.2.6.E at time of writing).</p>
<p>Since only the latest firmware uses the Hub&#8217;s serial number as the default admin password, the reported serial number disclosure via UPnP XML description files is NOT exploitable. </p>
<p>Nevertheless, the MDAP attack described in our previous post has been verified on the latest firmware and has been confirmed by several users both, on the BT Home Hub v1, and v1.5.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rishi</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/#comment-122310</link>
		<dc:creator>rishi</dc:creator>
		<pubDate>Wed, 28 May 2008 13:32:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-122310</guid>
		<description>have any flaws been found in the H firmware?

Thanks</description>
		<content:encoded><![CDATA[<p>have any flaws been found in the H firmware?</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephen</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/#comment-122302</link>
		<dc:creator>Stephen</dc:creator>
		<pubDate>Tue, 27 May 2008 16:24:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-122302</guid>
		<description>Ok. Reading it in detail the upnp/IGD.xml file contains the following:

Device not enabled: UPNP-IGD

So at least it seems to be off.

However the dslf/IGD.xml looks like it still offers services - does this mean that even turning off UPnP that one could still utilise the dslf stuff to pwn it?</description>
		<content:encoded><![CDATA[<p>Ok. Reading it in detail the upnp/IGD.xml file contains the following:</p>
<p>Device not enabled: UPNP-IGD</p>
<p>So at least it seems to be off.</p>
<p>However the dslf/IGD.xml looks like it still offers services - does this mean that even turning off UPnP that one could still utilise the dslf stuff to pwn it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/#comment-122301</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Tue, 27 May 2008 16:21:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-122301</guid>
		<description>even when you switch off UPnP the IGD description may still be present.</description>
		<content:encoded><![CDATA[<p>even when you switch off UPnP the IGD description may still be present.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephen</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/#comment-122300</link>
		<dc:creator>Stephen</dc:creator>
		<pubDate>Tue, 27 May 2008 16:19:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-122300</guid>
		<description>Apologies for three posts in a row but I just checked and UPnP is definitely switched off on my HH (I immediately disabled it on reading your initial HH posts some months ago).

Should these files still be available even when UPnP is off? Because they are...</description>
		<content:encoded><![CDATA[<p>Apologies for three posts in a row but I just checked and UPnP is definitely switched off on my HH (I immediately disabled it on reading your initial HH posts some months ago).</p>
<p>Should these files still be available even when UPnP is off? Because they are&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephen</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/#comment-122299</link>
		<dc:creator>Stephen</dc:creator>
		<pubDate>Tue, 27 May 2008 16:15:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-122299</guid>
		<description>Just to add that I'm on 6.2.6.E (forgot to mention that)</description>
		<content:encoded><![CDATA[<p>Just to add that I&#8217;m on 6.2.6.E (forgot to mention that)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephen</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/#comment-122297</link>
		<dc:creator>Stephen</dc:creator>
		<pubDate>Tue, 27 May 2008 16:10:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-122297</guid>
		<description>On my HH v15 the serialnumber field has the MAC address in it</description>
		<content:encoded><![CDATA[<p>On my HH v15 the serialnumber field has the MAC address in it</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MJW</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/#comment-122295</link>
		<dc:creator>MJW</dc:creator>
		<pubDate>Tue, 27 May 2008 13:48:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-122295</guid>
		<description>I'm on 6.2.6.E and I've checked the IGD.xml file, the Serial Number field shows my MAC code not the serial number. Is this a change in 6.2.6.E?</description>
		<content:encoded><![CDATA[<p>I&#8217;m on 6.2.6.E and I&#8217;ve checked the IGD.xml file, the Serial Number field shows my MAC code not the serial number. Is this a change in 6.2.6.E?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
