Slashdot Mirror


Cable Modem Hackers Release Improved Firmware

FatCat writes "SecurityFocus has a story about a group of hardware and software hobbyists specializing in embeddded systems who've released their own custom firmware for Motorola Surfboard cable modems. The firmware lets you log in to an interactive VxWorks shell, or issue commands from a Web browser through an http interface. You load it by tapping an undocumented console serial port on the circuit board. So far, uncappers are apparently the primary consumers, and they're downloading up to 400 copies a day."

14 of 419 comments (clear)

  1. Great, the bandwidth hogs by Gr8Apes · · Score: 4, Insightful

    will be quickly disconnected! More bandwidth for me!

    --
    The cesspool just got a check and balance.
  2. Hmm... by Pxtl · · Score: 5, Insightful

    IANAA (I am not an admin) but shouldn't bandwidth capping be handled at the ISP's end, through a transparent proxy? Not through the cable modem? At the very least couldn't they just have the system automagically cut off service when the packets start flowing too fast, rather than getting into the legal minefields? Then they could say "I'm sorry, our system does not support uncapping" when someone tries and finds their machine not getting anything. Seems a more elegant solution than simply hoping nobody will try and then hosing lawyer hours at them when they do.

  3. This shouldn't even be possible by huhmz · · Score: 4, Insightful

    Here in Sweden the caps aren't in the modems and quite frankly what kind of idiot ISP would do it this way? We are capped at the router or somesuch. I got 8 Mbit on my ADSL though which is maximum for ADSL so im not complaining.

    1. Re:This shouldn't even be possible by Quill_28 · · Score: 4, Insightful

      Umm.. I believe cable modem use a shared line with other users.
      I am certainly no expert but I think it is more difficult with this setup, than with DSL.

      But I could be wrong

    2. Re:This shouldn't even be possible by Jarnis · · Score: 4, Insightful

      There is a big difference in technology when comparing ADSL and Cable modems. Yes, one could argue that the early cable modem standard sucks and is exploitable, but that's what is in use by millions of customers right now.

      ADSL is single line from you to your local DSLAM. Zero issues with capping at the DSLAM end.

      Cable modem has tons of users sharing the same cable, and the easiest point where you squeeze down what a single user can send/receive to the cable is your cable modem. Yes, there are ways of doing it at the ISP:s end, but they are either expensive or require nasty kludges.

  4. Re:My Opinion by lukewarmfusion · · Score: 4, Insightful

    My Comcast (and my Sprint PCS) TOS states that the TOS is free to change at any time, without needing any notification, additional signature or approval from me, and is enforceable without my prior knowledge. They can add fees and still charge a cancellation fee if I get upset and leave.

    Something ain't right about that.

  5. Harsh lesson for business by Stiletto · · Score: 5, Insightful


    Lesson learned:

    Don't stake your business on being able to place artificial limits on how users use a product they buy.

    DivX learned this. The RIAA are learning this. the MPAA will learn it. And looks like broadband providers will soon learn it too.

  6. It's of no moment by picklepuss · · Score: 5, Insightful

    It's interesting today, but it won't last. I wouldn't really bother with it. If the ISP is capping it at the modem and users find a way around it, the ISP will just figure out a way to cap it in a different place - they'll probably put the cap on the other end of the pipe where they have absolute control of the firmware/hardware.

    I do think it's an interesting attack on the Cable providors who have an undocumented bandwidth limitation that they enforce. One would think that a potential benefit would be an increase in the number of people who are diconnected due to this invisible marker, and some court enforced clarification/disclosure of limitations. Sadly, the activity is obviously illegal, and therefore any potential long term gains from this kind of activity are rendered unachievable.

  7. Re:dropped carrier by ErichTheRed · · Score: 3, Insightful
    Yup, lots of people don't realize that. Especially over the last two years, cable broadband has emerged from the Wild West period. Now providers are actually looking at what's going on in their networks, and going after people who are stealing service. Of course, they don't have time to crack down on everyone, but they can easily collect statistics from the routers.

    The thing that stinks is that our provider is great. They block a few common ports inbound to prevent casual abuse, but that's about it; it's fast and stable! Uncappers may ruin it for the rest of us with this firmware mod.

  8. so the question becomes by The+Tyro · · Score: 5, Insightful

    Why do this on a shared medium, particularly one you have to share with your neighbors? I like my neighbors, and I get almost 3.5 megabits down, which is pretty quick. Plus, my neighbors know I'm the cul-de-sac computer geek, and they'd probably come to me if their connections slowed to a crawl. What am I supposed to do? Play dumb when they ask me if I know what's up with their slow connections? That's pretty weak... and looks even weaker when the cable company tells my neighbors that someone in the neighborhood uncapped their cable modem... Hmmm... wonder who that person could be?

    Sorry, but there's very few things worse than being a weasel.

    Yeah, it's great to have m4d bandwidth, but you're really paying for a shared resource, and I think most people know that. Don't get me wrong... I appreciate the value of a good hardware hack as much as the next geek, but if you're using it to siphon huge amounts of bandwidth from your neighborhood node, that's a problem.

    If you need huge, dedicated bandwidth, I'd say buy a T-1 line, or pay for a business-class account.

    --
    Even if a man chops off your hand with a sword, you still have two nice, sharp bones to stick in his eyes.
    1. Re:so the question becomes by Awptimus+Prime · · Score: 4, Insightful

      Do you actually think they run another line for a business-class account?

      I think that's the point, exactly. There are others paying for the bandwidth, while some kid with a hacked firmware is, in essence, stealing it.

      Just because it's there, does not mean it's there for the taking. If you need the extra bandwidth, don't steal it. Buy it.

      Also, just because the cable modem ring concept is flawed and difficult to control, by design, that does not make it justifyable to steal from them any more than it does to steal from music artists by downloading Mp3's. If you are going to be a criminal, don't play like it's not wrong. Accept that it's wrong, and get your kicks on the idea you stole something. That's less sick than the relentless and asinine justification I see all through this thread.

  9. Re:Cheap VxWorks development system? by Quasar1999 · · Score: 3, Insightful

    Umm, you are aware that VxWorks runs fine on an x86 based PC? Why muck around with a modem and hacking, when you could install VxWorks on a PC and worry about learning the system, not hacking the hardware.

    --

    ---
    Programming is like sex... Make one mistake and support it the rest of your life.
  10. Re:This won't last long by arctan1701 · · Score: 3, Insightful

    hmmmm... i own my cable modem. my contract says nothing about allowing my cable company to access my computer systems and make changes. shouldn't this be a form of hacking/terrorism and be punished by death as it is for the rest of us?

  11. No by The+Tyro · · Score: 3, Insightful

    I know for a fact they don't run another line, because I purchased one of their business-class accounts for my corporation.

    Why? Running servers for one, and I also get priority for bandwidth on the node, as well as better tech support (which I basically never use... calling tech support is a sign of weakness). Yes, it costs more, but I knew my utilization would be a good deal more than average, so I paid for the next level of service.

    I personally suspect the uncappers are after some better upstream pipe... that's where residential accounts are seriously lacking compared to a T-1.

    --
    Even if a man chops off your hand with a sword, you still have two nice, sharp bones to stick in his eyes.