<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Dumping the admin password of the BT Home Hub (pt 2)</title>
	<atom:link href="http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Sat, 02 Feb 2013 17:50:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: Andy</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/comment-page-1/#comment-128146</link>
		<dc:creator>Andy</dc:creator>
		<pubDate>Mon, 15 Feb 2010 16:59:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-128146</guid>
		<description>You can still get the serial. Go to https://api.home View the cert like said, but it&#039;s simply the OU- organizational unit above serial number. Add CP to that string, and that&#039;s the serial.</description>
		<content:encoded><![CDATA[<p>You can still get the serial. Go to <a href="https://api.home" rel="nofollow">https://api.home</a> View the cert like said, but it&#8217;s simply the OU- organizational unit above serial number. Add CP to that string, and that&#8217;s the serial.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pwn-a-cycle</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/comment-page-1/#comment-127968</link>
		<dc:creator>pwn-a-cycle</dc:creator>
		<pubDate>Fri, 30 Oct 2009 15:59:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-127968</guid>
		<description>the link is http://www.josephn.net/download/dl.php?file=bthh_recovery

@fLaMePr0oF - seems you accidently appended a ).. to the url</description>
		<content:encoded><![CDATA[<p>the link is <a href="http://www.josephn.net/download/dl.php?file=bthh_recovery" rel="nofollow">http://www.josephn.net/downloa.....h_recovery</a></p>
<p>@fLaMePr0oF &#8211; seems you accidently appended a ).. to the url</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fLaMePr0oF</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/comment-page-1/#comment-127668</link>
		<dc:creator>fLaMePr0oF</dc:creator>
		<pubDate>Sun, 02 Aug 2009 03:49:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-127668</guid>
		<description>Another method for getting the serial number of any BTHH is to download and run the latest BT Home Hub Recovery Tool 6.2.2.6 (can get it here: http://www.josephn.net/download/dl.php?file=bthh_recovery)...  When the tool tries to access the HH and asks for authentication, the serial number will be displayed above the user/pass input fields.

(LoL @ BT for changing password to serial to improve security when serial can be accessed SO easily!)</description>
		<content:encoded><![CDATA[<p>Another method for getting the serial number of any BTHH is to download and run the latest BT Home Hub Recovery Tool 6.2.2.6 (can get it here: <a href="http://www.josephn.net/download/dl.php?file=bthh_recovery" rel="nofollow">http://www.josephn.net/downloa.....h_recovery</a>)&#8230;  When the tool tries to access the HH and asks for authentication, the serial number will be displayed above the user/pass input fields.</p>
<p>(LoL @ BT for changing password to serial to improve security when serial can be accessed SO easily!)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Martin</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/comment-page-1/#comment-127489</link>
		<dc:creator>Martin</dc:creator>
		<pubDate>Tue, 16 Jun 2009 10:01:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-127489</guid>
		<description>Gary, that was perfect. I couldn&#039;t get the other methods to work as I didn&#039;t realise you had to add on the CP to the start of what was returned.</description>
		<content:encoded><![CDATA[<p>Gary, that was perfect. I couldn&#8217;t get the other methods to work as I didn&#8217;t realise you had to add on the CP to the start of what was returned.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gary</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/comment-page-1/#comment-124348</link>
		<dc:creator>Gary</dc:creator>
		<pubDate>Sat, 15 Nov 2008 19:13:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-124348</guid>
		<description>You can also get the Serial Number by visiting this page: http://pbteu.bt.motive.com/ElectiveFWUpgradePortal/ and clicking on &quot;Schedule your BT Home Hub upgrade&quot;

or follow the link direct: http://pbteu.bt.motive.com/ElectiveFWUpgradePortal/jsp/Loading.jsp?URL=Schedule.jsp

This has to be done while connected to a HomeHub.</description>
		<content:encoded><![CDATA[<p>You can also get the Serial Number by visiting this page: <a href="http://pbteu.bt.motive.com/ElectiveFWUpgradePortal/" rel="nofollow">http://pbteu.bt.motive.com/Ele.....adePortal/</a> and clicking on &#8220;Schedule your BT Home Hub upgrade&#8221;</p>
<p>or follow the link direct: <a href="http://pbteu.bt.motive.com/ElectiveFWUpgradePortal/jsp/Loading.jsp?URL=Schedule.jsp" rel="nofollow">http://pbteu.bt.motive.com/Ele.....hedule.jsp</a></p>
<p>This has to be done while connected to a HomeHub.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian 'pagvac' Pastor</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/comment-page-1/#comment-122390</link>
		<dc:creator>Adrian 'pagvac' Pastor</dc:creator>
		<pubDate>Sat, 31 May 2008 08:33:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-122390</guid>
		<description>We got a winner :) I can confirm this works on the BT Home Hub v1, firmware 6.2.6.E. Good catch Aaron! Any other ideas on how to obtain the Hub&#039;s S/N and therefore the default admin password? The more techniques the merrier!

btw, the troubleshooting page - which doesn&#039;t require a password to be seen - *used to* include the S/N but BT removed such info in the latest firmware: https://api.home/cgi/b/bttroubleshooting/</description>
		<content:encoded><![CDATA[<p>We got a winner :) I can confirm this works on the BT Home Hub v1, firmware 6.2.6.E. Good catch Aaron! Any other ideas on how to obtain the Hub&#8217;s S/N and therefore the default admin password? The more techniques the merrier!</p>
<p>btw, the troubleshooting page &#8211; which doesn&#8217;t require a password to be seen &#8211; *used to* include the S/N but BT removed such info in the latest firmware: <a href="https://api.home/cgi/b/bttroubleshooting/" rel="nofollow">https://api.home/cgi/b/bttroubleshooting/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephen</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/comment-page-1/#comment-122380</link>
		<dc:creator>Stephen</dc:creator>
		<pubDate>Fri, 30 May 2008 16:28:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-122380</guid>
		<description>I can verify that the OU of the SSL certificate gives the serial number on 6.2.6.E on my HH v1.5

Just point your browser to https://api.home/ and click examine certificate when prompted ;)</description>
		<content:encoded><![CDATA[<p>I can verify that the OU of the SSL certificate gives the serial number on 6.2.6.E on my HH v1.5</p>
<p>Just point your browser to <a href="https://api.home/" rel="nofollow">https://api.home/</a> and click examine certificate when prompted ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/comment-page-1/#comment-122338</link>
		<dc:creator>Aaron</dc:creator>
		<pubDate>Thu, 29 May 2008 18:41:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-122338</guid>
		<description>You can dump the serial number of the HomeHub 6.2.6.E by connecting to the HTTPS port and examining the SSL Certificate... the default OU of the certificate issuer is the serial number of the device...

Hence, the pwndhub I am currently using has just dished out this after I ran a Nessus scan on it...

&lt;pre&gt;&lt;code&gt;OU = 0641EHJRR
O = THOMSON
CN = BT Home Hub&lt;/code&gt;&lt;/pre&gt;

Please verify this works for others...</description>
		<content:encoded><![CDATA[<p>You can dump the serial number of the HomeHub 6.2.6.E by connecting to the HTTPS port and examining the SSL Certificate&#8230; the default OU of the certificate issuer is the serial number of the device&#8230;</p>
<p>Hence, the pwndhub I am currently using has just dished out this after I ran a Nessus scan on it&#8230;</p>
<pre><code>OU = 0641EHJRR
O = THOMSON
CN = BT Home Hub</code></pre>
<p>Please verify this works for others&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian 'pagvac' Pastor</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/comment-page-1/#comment-122318</link>
		<dc:creator>Adrian 'pagvac' Pastor</dc:creator>
		<pubDate>Wed, 28 May 2008 22:51:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-122318</guid>
		<description>The serial number disclosure reported in this post was originally tested on a BT Home Hub running firmware version 6.2.2.6. However, it appears that BT has replaced such information with the Hub&#039;s MAC address in the latest firmware (6.2.6.E at time of writing).

Since only the latest firmware uses the Hub&#039;s serial number as the default admin password, the reported serial number disclosure via UPnP XML description files is NOT exploitable. 

Nevertheless, the MDAP attack described in our previous post has been verified on the latest firmware and has been confirmed by several users both, on the BT Home Hub v1, and v1.5.</description>
		<content:encoded><![CDATA[<p>The serial number disclosure reported in this post was originally tested on a BT Home Hub running firmware version 6.2.2.6. However, it appears that BT has replaced such information with the Hub&#8217;s MAC address in the latest firmware (6.2.6.E at time of writing).</p>
<p>Since only the latest firmware uses the Hub&#8217;s serial number as the default admin password, the reported serial number disclosure via UPnP XML description files is NOT exploitable. </p>
<p>Nevertheless, the MDAP attack described in our previous post has been verified on the latest firmware and has been confirmed by several users both, on the BT Home Hub v1, and v1.5.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rishi</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/comment-page-1/#comment-122310</link>
		<dc:creator>rishi</dc:creator>
		<pubDate>Wed, 28 May 2008 13:32:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-122310</guid>
		<description>Have any flaws been found in the H firmware? Thanks!</description>
		<content:encoded><![CDATA[<p>Have any flaws been found in the H firmware? Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephen</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/comment-page-1/#comment-122302</link>
		<dc:creator>Stephen</dc:creator>
		<pubDate>Tue, 27 May 2008 16:24:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-122302</guid>
		<description>Ok. Reading it in detail the upnp/IGD.xml file contains the following:

&lt;pre&gt;&lt;code&gt;Device not enabled: UPNP-IGD&lt;/code&gt;&lt;/pre&gt;

So at least it seems to be off. However the dslf/IGD.xml looks like it still offers services - does this mean that even turning off UPnP that one could still utilise the dslf stuff to pwn it?</description>
		<content:encoded><![CDATA[<p>Ok. Reading it in detail the upnp/IGD.xml file contains the following:</p>
<pre><code>Device not enabled: UPNP-IGD</code></pre>
<p>So at least it seems to be off. However the dslf/IGD.xml looks like it still offers services &#8211; does this mean that even turning off UPnP that one could still utilise the dslf stuff to pwn it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/comment-page-1/#comment-122301</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Tue, 27 May 2008 16:21:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-122301</guid>
		<description>even when you switch off UPnP the IGD description may still be present.</description>
		<content:encoded><![CDATA[<p>even when you switch off UPnP the IGD description may still be present.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephen</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/comment-page-1/#comment-122300</link>
		<dc:creator>Stephen</dc:creator>
		<pubDate>Tue, 27 May 2008 16:19:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-122300</guid>
		<description>Apologies for three posts in a row but I just checked and UPnP is definitely switched off on my HH (I immediately disabled it on reading your initial HH posts some months ago).

Should these files still be available even when UPnP is off? Because they are...</description>
		<content:encoded><![CDATA[<p>Apologies for three posts in a row but I just checked and UPnP is definitely switched off on my HH (I immediately disabled it on reading your initial HH posts some months ago).</p>
<p>Should these files still be available even when UPnP is off? Because they are&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephen</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/comment-page-1/#comment-122299</link>
		<dc:creator>Stephen</dc:creator>
		<pubDate>Tue, 27 May 2008 16:15:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-122299</guid>
		<description>Just to add that I&#039;m on 6.2.6.E (forgot to mention that)</description>
		<content:encoded><![CDATA[<p>Just to add that I&#8217;m on 6.2.6.E (forgot to mention that)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephen</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/comment-page-1/#comment-122297</link>
		<dc:creator>Stephen</dc:creator>
		<pubDate>Tue, 27 May 2008 16:10:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-122297</guid>
		<description>On my HH v15 the serialnumber field has the MAC address in it</description>
		<content:encoded><![CDATA[<p>On my HH v15 the serialnumber field has the MAC address in it</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MJW</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/comment-page-1/#comment-122295</link>
		<dc:creator>MJW</dc:creator>
		<pubDate>Tue, 27 May 2008 13:48:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/?p=859#comment-122295</guid>
		<description>I&#039;m on 6.2.6.E and I&#039;ve checked the IGD.xml file, the Serial Number field shows my MAC code not the serial number. Is this a change in 6.2.6.E?</description>
		<content:encoded><![CDATA[<p>I&#8217;m on 6.2.6.E and I&#8217;ve checked the IGD.xml file, the Serial Number field shows my MAC code not the serial number. Is this a change in 6.2.6.E?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
