<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Dumping the admin password of the BT Home Hub</title>
	<atom:link href="http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Sat, 02 Feb 2013 17:50:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: point</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/comment-page-1/#comment-129250</link>
		<dc:creator>point</dc:creator>
		<pubDate>Sat, 30 Oct 2010 05:30:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/#comment-129250</guid>
		<description>Iused three methods so far nothing good I tryed with recovery get serial but then i enter it i got wrong serial number then i use gdi i get 12 numberer and guy dont know what router is so it gonna be long waiting. anu suggestions</description>
		<content:encoded><![CDATA[<p>Iused three methods so far nothing good I tryed with recovery get serial but then i enter it i got wrong serial number then i use gdi i get 12 numberer and guy dont know what router is so it gonna be long waiting. anu suggestions</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ash</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/comment-page-1/#comment-128732</link>
		<dc:creator>Ash</dc:creator>
		<pubDate>Mon, 23 Aug 2010 00:17:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/#comment-128732</guid>
		<description>Jakey haha thats just excelent, how did you figer that out lol</description>
		<content:encoded><![CDATA[<p>Jakey haha thats just excelent, how did you figer that out lol</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Homeseer</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/comment-page-1/#comment-128088</link>
		<dc:creator>Homeseer</dc:creator>
		<pubDate>Fri, 08 Jan 2010 22:09:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/#comment-128088</guid>
		<description>This is security through obscurity at it&#039;s finest.  Gotta love the lottery comment - perhaps if each attempt was the equivalent to purchasing a ticket, but since there&#039;s zero cost to attempt it&#039;s not exactly a robust analogy.</description>
		<content:encoded><![CDATA[<p>This is security through obscurity at it&#8217;s finest.  Gotta love the lottery comment &#8211; perhaps if each attempt was the equivalent to purchasing a ticket, but since there&#8217;s zero cost to attempt it&#8217;s not exactly a robust analogy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ross</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/comment-page-1/#comment-128071</link>
		<dc:creator>Ross</dc:creator>
		<pubDate>Fri, 25 Dec 2009 17:08:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/#comment-128071</guid>
		<description>Please Ignore my previous post. Works perfectly on Winxp and BT3.</description>
		<content:encoded><![CDATA[<p>Please Ignore my previous post. Works perfectly on Winxp and BT3.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ross</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/comment-page-1/#comment-128068</link>
		<dc:creator>Ross</dc:creator>
		<pubDate>Fri, 25 Dec 2009 16:03:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/#comment-128068</guid>
		<description>Using BT 3 I get the following (mdap-dump.py is running)

&lt;pre&gt;&lt;code&gt;python mdap-send-ant-search.py
File &quot;mdap-send-ant-search.py&quot;, line 1&lt;/code&gt;&lt;/pre&gt;</description>
		<content:encoded><![CDATA[<p>Using BT 3 I get the following (mdap-dump.py is running)</p>
<pre><code>python mdap-send-ant-search.py
File "mdap-send-ant-search.py", line 1</code></pre>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nagi</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/comment-page-1/#comment-128063</link>
		<dc:creator>Nagi</dc:creator>
		<pubDate>Sun, 20 Dec 2009 02:35:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/#comment-128063</guid>
		<description>Hi guys, I decided to stop using bthh. So I bought a drytek 2820n router. I was trying to get it to work but failed. At some stage of router installation it asks me for a username and password for WAN1, which, it says, I should had been given by my ISP - BT. Now, I don&#039;t know where to get this details from? Any advice most appreciated.</description>
		<content:encoded><![CDATA[<p>Hi guys, I decided to stop using bthh. So I bought a drytek 2820n router. I was trying to get it to work but failed. At some stage of router installation it asks me for a username and password for WAN1, which, it says, I should had been given by my ISP &#8211; BT. Now, I don&#8217;t know where to get this details from? Any advice most appreciated.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jakey</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/comment-page-1/#comment-126462</link>
		<dc:creator>Jakey</dc:creator>
		<pubDate>Wed, 08 Apr 2009 12:20:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/#comment-126462</guid>
		<description>Just go here and click on &quot;Schedule your BT Home Hub upgrade&quot; and you see your serial: http://pbteu.bt.motive.com/ElectiveFWUpgradePortal/

Simple!</description>
		<content:encoded><![CDATA[<p>Just go here and click on &#8220;Schedule your BT Home Hub upgrade&#8221; and you see your serial: <a href="http://pbteu.bt.motive.com/ElectiveFWUpgradePortal/" rel="nofollow">http://pbteu.bt.motive.com/Ele.....adePortal/</a></p>
<p>Simple!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: thomas smith</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/comment-page-1/#comment-126366</link>
		<dc:creator>thomas smith</dc:creator>
		<pubDate>Tue, 24 Mar 2009 17:14:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/#comment-126366</guid>
		<description>I can still confirm that bt homehubs are very insecure. I went to the router page and noticed that it shows you everyone who has logged on to your network going by computer name and mac address. My computer name kind of gives me away, so i looked at this for getting the admin password.

I can confirm the python scripts do work on windows using the method john smith said, but also confirm Robbies method works as well, and is a lot easier to do. You now have to go here to download the scripts: http://lab.gnucitizen.org/projects/bt-home-hub-s-n-dumper

the software version is now 6.2.6H and even though i got the unique ID, I cant log on using it (with CP in front) someone said it prompts you to change it straight away now? I think im stuck or is there anything i can do to get it now?</description>
		<content:encoded><![CDATA[<p>I can still confirm that bt homehubs are very insecure. I went to the router page and noticed that it shows you everyone who has logged on to your network going by computer name and mac address. My computer name kind of gives me away, so i looked at this for getting the admin password.</p>
<p>I can confirm the python scripts do work on windows using the method john smith said, but also confirm Robbies method works as well, and is a lot easier to do. You now have to go here to download the scripts: <a href="http://lab.gnucitizen.org/projects/bt-home-hub-s-n-dumper" rel="nofollow">http://lab.gnucitizen.org/proj.....s-n-dumper</a></p>
<p>the software version is now 6.2.6H and even though i got the unique ID, I cant log on using it (with CP in front) someone said it prompts you to change it straight away now? I think im stuck or is there anything i can do to get it now?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Protect Your Wireless LAN&#8230; - Black-Delta.com</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/comment-page-1/#comment-124771</link>
		<dc:creator>Protect Your Wireless LAN&#8230; - Black-Delta.com</dc:creator>
		<pubDate>Tue, 16 Dec 2008 22:05:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/#comment-124771</guid>
		<description>[...] for your specific router (such as a script to challenge the router and spit a password out as seen here) they would know exactly what they are dealing [...]</description>
		<content:encoded><![CDATA[<p>[...] for your specific router (such as a script to challenge the router and spit a password out as seen here) they would know exactly what they are dealing [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian 'pagvac' Pastor</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/comment-page-1/#comment-124270</link>
		<dc:creator>Adrian 'pagvac' Pastor</dc:creator>
		<pubDate>Wed, 05 Nov 2008 22:03:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/#comment-124270</guid>
		<description>@john smith: cool, nice to see it worked on Win for u. :)</description>
		<content:encoded><![CDATA[<p>@john smith: cool, nice to see it worked on Win for u. :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: john smith</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/comment-page-1/#comment-124259</link>
		<dc:creator>john smith</dc:creator>
		<pubDate>Mon, 03 Nov 2008 14:33:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/#comment-124259</guid>
		<description>It worked on python for windows for me. The standard 2.6 installer. I just ran the dump script by double-clicking. Then ran the fetch script by double-clicking. It took a couple of tries for the fetch but worked in the end. Of course, that password is only the admin password until the owner visits the hub&#039;s homepage, whereupon they are required to set a new one immediately.</description>
		<content:encoded><![CDATA[<p>It worked on python for windows for me. The standard 2.6 installer. I just ran the dump script by double-clicking. Then ran the fetch script by double-clicking. It took a couple of tries for the fetch but worked in the end. Of course, that password is only the admin password until the owner visits the hub&#8217;s homepage, whereupon they are required to set a new one immediately.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Craig</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/comment-page-1/#comment-123753</link>
		<dc:creator>Craig</dc:creator>
		<pubDate>Wed, 17 Sep 2008 20:24:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/#comment-123753</guid>
		<description>No matter, I have used aaron&#039;s way of finding the SN by viewing the SSL certificate.</description>
		<content:encoded><![CDATA[<p>No matter, I have used aaron&#8217;s way of finding the SN by viewing the SSL certificate.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Craig</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/comment-page-1/#comment-123752</link>
		<dc:creator>Craig</dc:creator>
		<pubDate>Wed, 17 Sep 2008 20:13:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/#comment-123752</guid>
		<description>I&#039;m attempting to run this on backtrack 3. I&#039;ve run the scripts as you have said yet I get no feedback in Konsole.

&lt;pre&gt;&lt;code&gt;bt ~# cd /tmp
bt tmp # python mdap-dump.py &amp;
[1] 6763
bt tmp # python mdap-send-ant-search.py
ANT-SEARCH MDAP/1.1
46
bt tmp #&lt;/code&gt;&lt;/pre&gt;

That is all I get. I&#039;m connect as follows: Windows XP machine (192.168.1.164) &gt; VMWare Bridge &gt; backtrack 3 (192.168.1.78). Does this mean the network is secure?</description>
		<content:encoded><![CDATA[<p>I&#8217;m attempting to run this on backtrack 3. I&#8217;ve run the scripts as you have said yet I get no feedback in Konsole.</p>
<pre><code>bt ~# cd /tmp
bt tmp # python mdap-dump.py &amp;
[1] 6763
bt tmp # python mdap-send-ant-search.py
ANT-SEARCH MDAP/1.1
46
bt tmp #</code></pre>
<p>That is all I get. I&#8217;m connect as follows: Windows XP machine (192.168.1.164) &gt; VMWare Bridge &gt; backtrack 3 (192.168.1.78). Does this mean the network is secure?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian 'pagvac' Pastor</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/comment-page-1/#comment-122492</link>
		<dc:creator>Adrian 'pagvac' Pastor</dc:creator>
		<pubDate>Sun, 08 Jun 2008 09:36:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/#comment-122492</guid>
		<description>@joe: the Python scripts we provided only seem to work in Linux (we tested them on backtrack 2 but should also work on bt3).

If you just want to get the Hub&#039;s serial number prior to authenticating without using the MDAP protocol, then simply check &#039;OU&#039; field of the SSL certificate as mentioned by Aaron on http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/

You should be able to examine the Hub&#039;s SSL certificate by accessing: https://api.home/ or https://192.168.1.254</description>
		<content:encoded><![CDATA[<p>@joe: the Python scripts we provided only seem to work in Linux (we tested them on backtrack 2 but should also work on bt3).</p>
<p>If you just want to get the Hub&#8217;s serial number prior to authenticating without using the MDAP protocol, then simply check &#8216;OU&#8217; field of the SSL certificate as mentioned by Aaron on <a href="http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub-pt-2/" rel="nofollow">http://www.gnucitizen.org/blog.....-hub-pt-2/</a></p>
<p>You should be able to examine the Hub&#8217;s SSL certificate by accessing: <a href="https://api.home/" rel="nofollow">https://api.home/</a> or <a href="https://192.168.1.254" rel="nofollow">https://192.168.1.254</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robbie</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/comment-page-1/#comment-122462</link>
		<dc:creator>Robbie</dc:creator>
		<pubDate>Fri, 06 Jun 2008 11:28:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/#comment-122462</guid>
		<description>just looking for some reason the home hub im testing has 6.2.6H  firmware . It&#039;s a new hub so i presume it must be 1.5 and its had fon opted in. any one else messed with this firmware?</description>
		<content:encoded><![CDATA[<p>just looking for some reason the home hub im testing has 6.2.6H  firmware . It&#8217;s a new hub so i presume it must be 1.5 and its had fon opted in. any one else messed with this firmware?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robbie</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/comment-page-1/#comment-122461</link>
		<dc:creator>Robbie</dc:creator>
		<pubDate>Fri, 06 Jun 2008 10:25:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/#comment-122461</guid>
		<description>for those on windows an easy way id say is to download http://static.btopenworld.com/broadband/adhoc_pages/drivers/Windows_recovery_626E.zip when it asks you for a username and password you can see next to the box with the serial number next to it http://i30.tinypic.com/35l82a9.jpg and voila you have the password for the hub</description>
		<content:encoded><![CDATA[<p>for those on windows an easy way id say is to download <a href="http://static.btopenworld.com/broadband/adhoc_pages/drivers/Windows_recovery_626E.zip" rel="nofollow">http://static.btopenworld.com/.....y_626E.zip</a> when it asks you for a username and password you can see next to the box with the serial number next to it <a href="http://i30.tinypic.com/35l82a9.jpg" rel="nofollow">http://i30.tinypic.com/35l82a9.jpg</a> and voila you have the password for the hub</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: joe</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/comment-page-1/#comment-122385</link>
		<dc:creator>joe</dc:creator>
		<pubDate>Fri, 30 May 2008 20:39:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/#comment-122385</guid>
		<description>I&#039;m running bthomehub-bb59 firmware version 6.2.6.E. where do i get the programs from to get it to work. will this work on windows xp or backtrack 3</description>
		<content:encoded><![CDATA[<p>I&#8217;m running bthomehub-bb59 firmware version 6.2.6.E. where do i get the programs from to get it to work. will this work on windows xp or backtrack 3</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephen</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/comment-page-1/#comment-122298</link>
		<dc:creator>Stephen</dc:creator>
		<pubDate>Tue, 27 May 2008 16:14:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/#comment-122298</guid>
		<description>To confirm from my post near the top - yes I&#039;m on 6.2.6.E on a v1.5</description>
		<content:encoded><![CDATA[<p>To confirm from my post near the top &#8211; yes I&#8217;m on 6.2.6.E on a v1.5</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian 'pagvac' Pastor</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/comment-page-1/#comment-122293</link>
		<dc:creator>Adrian 'pagvac' Pastor</dc:creator>
		<pubDate>Tue, 27 May 2008 12:22:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/#comment-122293</guid>
		<description>After having observed BT&#039;s reaction to several Home Hub vulnerabilities published in the past, it&#039;s easy to notice BT&#039;s PR template. It kind of goes like this:

&lt;blockquote&gt;
&lt;p&gt;&lt;q&gt;We do not believe any of our customers have been affected by this attack.&lt;/q&gt;&lt;/p&gt;
&lt;p&gt;&lt;q&gt;Such security research describes a theoretical attack.&lt;/q&gt;&lt;/p&gt;
&lt;/blockquote&gt;

In reality this translates to: 

&lt;blockquote&gt;
&lt;p&gt;&lt;q&gt;We are not aware of any attack performed in a _mass fashion_ which uses such vulnerabilities. Of course this doesn&#039;t mean such vulnerabilities have not been exploited in the wild. We know that most likely they *have* been exploited as they are practical. However, we don&#039;t want mainstream users (i.e: non-technical) to know this.&lt;/q&gt;&lt;/p&gt;
&lt;p&gt;&lt;q&gt;We want the public to think that such attack is not possible in real life, so they do not realize how bad the current state of the security of the Home Hub really is.&lt;/q&gt;&lt;/p&gt;
&lt;/blockquote&gt;</description>
		<content:encoded><![CDATA[<p>After having observed BT&#8217;s reaction to several Home Hub vulnerabilities published in the past, it&#8217;s easy to notice BT&#8217;s PR template. It kind of goes like this:</p>
<blockquote>
<p><q>We do not believe any of our customers have been affected by this attack.</q></p>
<p><q>Such security research describes a theoretical attack.</q></p>
</blockquote>
<p>In reality this translates to: </p>
<blockquote>
<p><q>We are not aware of any attack performed in a _mass fashion_ which uses such vulnerabilities. Of course this doesn&#8217;t mean such vulnerabilities have not been exploited in the wild. We know that most likely they *have* been exploited as they are practical. However, we don&#8217;t want mainstream users (i.e: non-technical) to know this.</q></p>
<p><q>We want the public to think that such attack is not possible in real life, so they do not realize how bad the current state of the security of the Home Hub really is.</q></p>
</blockquote>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dumping the admin password of the BT Home Hub (pt 2) &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/comment-page-1/#comment-122287</link>
		<dc:creator>Dumping the admin password of the BT Home Hub (pt 2) &#124; GNUCITIZEN</dc:creator>
		<pubDate>Tue, 27 May 2008 09:12:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/dumping-the-admin-password-of-the-bt-home-hub/#comment-122287</guid>
		<description>[...] of the BT Home Hub (pt 2) published: May 27th, 2008 This is just a quick update regarding our previous post which details how to extract the default admin password for the latest firmware of the BT Home Hub [...]</description>
		<content:encoded><![CDATA[<p>[...] of the BT Home Hub (pt 2) published: May 27th, 2008 This is just a quick update regarding our previous post which details how to extract the default admin password for the latest firmware of the BT Home Hub [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
