<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: ZyXEL Gateways Vulnerability Research (Part 2)</title>
	<atom:link href="http://www.gnucitizen.org/blog/zyxel-gateways-vulnerability-research-part-2/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/zyxel-gateways-vulnerability-research-part-2/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Sat, 02 Feb 2013 17:50:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: Adrian 'pagvac' Pastor</title>
		<link>http://www.gnucitizen.org/blog/zyxel-gateways-vulnerability-research-part-2/comment-page-1/#comment-117867</link>
		<dc:creator>Adrian 'pagvac' Pastor</dc:creator>
		<pubDate>Fri, 04 Apr 2008 08:30:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/zyxel-gateways-vulnerability-research-part-2/#comment-117867</guid>
		<description>@lx: We&#039;re always more than happy to answer any questions you guys might have regarding our research. Thanks a lot for your interest (I mean it)! You can find the 1st part of the paper here:

http://www.procheckup.com/Hacking_ZyXEL_Gateways.pdf

@Kender: have you considered adding more details to your reverse-engineering tutorial? I think the community would benefit a lot from it if you made it more complete:

http://www.mindmasters.nl/kender/zyxel/</description>
		<content:encoded><![CDATA[<p>@lx: We&#8217;re always more than happy to answer any questions you guys might have regarding our research. Thanks a lot for your interest (I mean it)! You can find the 1st part of the paper here:</p>
<p><a href="http://www.procheckup.com/Hacking_ZyXEL_Gateways.pdf" rel="nofollow">http://www.procheckup.com/Hack.....teways.pdf</a></p>
<p>@Kender: have you considered adding more details to your reverse-engineering tutorial? I think the community would benefit a lot from it if you made it more complete:</p>
<p><a href="http://www.mindmasters.nl/kender/zyxel/" rel="nofollow">http://www.mindmasters.nl/kender/zyxel/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ix</title>
		<link>http://www.gnucitizen.org/blog/zyxel-gateways-vulnerability-research-part-2/comment-page-1/#comment-117828</link>
		<dc:creator>Ix</dc:creator>
		<pubDate>Thu, 03 Apr 2008 17:41:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/zyxel-gateways-vulnerability-research-part-2/#comment-117828</guid>
		<description>Ahh, well that explains how and why I missed the first one, was wondering how I missed it and couldn&#039;t find it in the archive (I did stay up too late watching some movies with friends last night so I was thinking it might have been sleep dep messing with me). Thanks for the response.

Off to google next time I have time to search and read.</description>
		<content:encoded><![CDATA[<p>Ahh, well that explains how and why I missed the first one, was wondering how I missed it and couldn&#8217;t find it in the archive (I did stay up too late watching some movies with friends last night so I was thinking it might have been sleep dep messing with me). Thanks for the response.</p>
<p>Off to google next time I have time to search and read.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian 'pagvac' Pastor</title>
		<link>http://www.gnucitizen.org/blog/zyxel-gateways-vulnerability-research-part-2/comment-page-1/#comment-117825</link>
		<dc:creator>Adrian 'pagvac' Pastor</dc:creator>
		<pubDate>Thu, 03 Apr 2008 16:22:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/zyxel-gateways-vulnerability-research-part-2/#comment-117825</guid>
		<description>@Kender - as I said, the tool is more than enough to get the admin password which is what I was interested in anyway. 

Regarding protections, well, the first protection is NOT to use ZyXEL routers. If this is not an option for you, then you can check out the first part of the paper which talks about how to defend against these attacks.

@lx - no reason. Just found some serious issues during a pentest, and then decided to purchase a few more to test them more in depth. btw, the first part of the paper was published on the 3rd party-site. Google is your friend ;)</description>
		<content:encoded><![CDATA[<p>@Kender &#8211; as I said, the tool is more than enough to get the admin password which is what I was interested in anyway. </p>
<p>Regarding protections, well, the first protection is NOT to use ZyXEL routers. If this is not an option for you, then you can check out the first part of the paper which talks about how to defend against these attacks.</p>
<p>@lx &#8211; no reason. Just found some serious issues during a pentest, and then decided to purchase a few more to test them more in depth. btw, the first part of the paper was published on the 3rd party-site. Google is your friend ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ix</title>
		<link>http://www.gnucitizen.org/blog/zyxel-gateways-vulnerability-research-part-2/comment-page-1/#comment-117821</link>
		<dc:creator>Ix</dc:creator>
		<pubDate>Thu, 03 Apr 2008 15:23:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/zyxel-gateways-vulnerability-research-part-2/#comment-117821</guid>
		<description>After reading this I have to ask, is there any particular reason why you used ZyXEL devices? Was it what was on hand or donated for testing? or are they  much easier to break into than other routers and firewalls from other companies, therefore giving better coverage of all the possible vulnerabilities that could be found? I haven&#039;t had time to read the report yet and I somehow missed seeing the first one, so if the why is in either of them just ignore this question.

Off to the archives to hunt down the first report now.</description>
		<content:encoded><![CDATA[<p>After reading this I have to ask, is there any particular reason why you used ZyXEL devices? Was it what was on hand or donated for testing? or are they  much easier to break into than other routers and firewalls from other companies, therefore giving better coverage of all the possible vulnerabilities that could be found? I haven&#8217;t had time to read the report yet and I somehow missed seeing the first one, so if the why is in either of them just ignore this question.</p>
<p>Off to the archives to hunt down the first report now.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kender</title>
		<link>http://www.gnucitizen.org/blog/zyxel-gateways-vulnerability-research-part-2/comment-page-1/#comment-117811</link>
		<dc:creator>Kender</dc:creator>
		<pubDate>Thu, 03 Apr 2008 13:36:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/zyxel-gateways-vulnerability-research-part-2/#comment-117811</guid>
		<description>&lt;blockquote&gt;Although such tool is a half-baked project and is a bit buggy&lt;/blockquote&gt;

Heheh, you&#039;re right. I never seem to properly finish anything before something else comes along to catch my interest :) Nice paper though. Perhaps you could include a few simple points on how to prevent attacks on your device.</description>
		<content:encoded><![CDATA[<blockquote><p>Although such tool is a half-baked project and is a bit buggy</p></blockquote>
<p>Heheh, you&#8217;re right. I never seem to properly finish anything before something else comes along to catch my interest :) Nice paper though. Perhaps you could include a few simple points on how to prevent attacks on your device.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
