Vodafone Femtocells Rooted, Secret Keys Exposed
AmiMoJo writes "Hackers have discovered the root password for Vodafone femtocells, devices that provide the user with a mobile phone signal piggybacked onto their home broadband. The root password was 'newsys.' Once root access is obtained, phones can be forced to connect to the cell and private keys captured, allowing the user to spoof the victim's phone and potentially make calls or send texts on their account, not to mention eavesdrop."
Streisand Launch in 4, 3, 2, 1 ...
Wait, we're still explaining to people on Slashdot what the function of one is?
I once took an excursion to Reddit, and later HN. Unlimited up/down voting sucks when dealing with a hive-mind.
this was fixed in 2010... http://www.theregister.co.uk/2011/07/14/voda_dismisses_femtocell_base_station_hack/
still a good movie.
Don't you think that the marketing guys are overdoing it with all these S.I. preffix's
You couldn't even see a femtocell (10 to the minus 15) in an electron microscope
I can't say I am surprised.
Vodafone are a terrible company. They are one of the most expensive in the UK. They gouge me. I am changing as soon as I can. They claim to offer unlimited texts but if you send a text that is bigger than 160 characters, they charge you. They also don't pay taxes in the UK, they owe 4.8 billion in taxes but our government decided 'to let it go'.
Now in the UK we're facing cuts to public services, education, electricity rises. I'm not bitter. Vodafone is a bad business. You should change from them and warn people of the same. Didn't they have something to do with Egypt censorship too?
Their website is also littered with Java exceptions.
Vodafone = Incompetent
Slashdot needs Geekcode | Can anyone recommend any good SCIFI? My tastes: Foundation, Startide Rising, CITY, Ringworld,
You couldn't even see a femtocell (10 to the minus 15) in an electron microscope
Just like your wang?
Isn't that kind of insecure? As in, the sort of thing that you would slap people for setting a root password as?
Our culture doesn't get smarter, it just finds new ways of being retarded.
... if you read Harald Welte's blog: http://laforge.gnumonks.org/weblog/2011/07/14/#20110714-vodafone_femtocell_thc
My spirit takes a journey through my mind...
Why dose having root on any cell, let alone a femtocell give you the ability to impersonate and eavesdrop? They should be simply forwarding the encrypted streams to/from Vodaphone they have no need to interpret or modify them. In fact it would have been trivial to design a phone system where even the operators can't eavesdrop, encrypting each call with the receiver's public key. The first time you rang a new number you would have to trust you were getting the correct public-key, but any abuse would be easy to detect and prove. This would mean that voice-mail etc. was only accessible with the original SIM, but that may not be too much of a compromise! You could still require that any phone connecting to the network submits its private keys to law enforcement.
A 6 digit, all alpha, all lowercase password, made from real words.
While it's entirely possible the password would have been hacked if the password was 16 alpha-numeric-punc chars, it's hard to by sympathetic to Vodaphone when they're this sloppy.
------ The best brain training is now totally free : )
In embedded devices like these, there is no reason to use a root password. The devices should be locked down completely with a process to update them with signed firmware.
If they need some form of remote access, they should at the very least use SSH PKI.
This is old news... Yet Slashdot mysteriously won't cover the story about the unredacted Manning/Lamo chat logs that just came out.
In fact, Google has completely censored it from their news/rss aggregators.
heard about this yet?
'Can everyone hear me now?'
Their blog archive goes all the way back to July 2011!
I'm sure "SlashdotMedia" will improve on all the wonders that Dice Holdings blessed us all with
GOD
Now everything has come full circle and hackers can finally return to their roots.
I worked for a company that made a security device with a default password for updates. The password was changed, post build, using the asset (serial) number of the device, a label added to the bottom of the device after install, with the default password added to the end of the string. This ensured that every device had a semi-unique password that required physical access to the device for anyone to figure out the first part of the manufacturer password. Not being a dumb ass company, that was not sufficient for them. Why? Despite the fact that the asset number was alpha numeric, all one needed to do is look at two devices to see the sequence (nn-cc-nnnn-cc-nnnnn). From there, generating nn-cc-nnnn-cc-nnnnn sequences in front of a properly guessed default password would allow brute force attacks. Anyway, the simple answer to the problem is to have a good enough UNIQUE default password then force the buyer to enter a password before the device would work.
Having to work for a living is the root of all evil.
How could a major project at a major public company start without addressing security?
1st of all: Your CD you didn't write the tools for yourself wasn't needed vs. the "indestructible rootkit"!
You also admitted my technique using the Windows Recovery Console PROVEN TOOLS from a read-only media in listsvc, disable, & fixmbr (if not DEL & more for your off topic "theoretical attacks" in desperation) would work to NON-DESTRUCTIVELY REMOVE THE "ALLEGEDLY INDESTRUCTIBLE ROOTKIT" too, lol, which is hilarious!
(AND, that is what setoff your numerous adhominem attacks on myself since you could not get the last word there, and your talking behind my back in your posts now trying to goad me on HOSTS files... this is going right back in your face, now... enjoy!)
Here, I will list your NUMEROUS other fails vs. tech points I show below, quoting yourself, & myself in rebuttal disprovals of your "so-called" easily overturned or disproven "points" (trying to put words in my mouth I never said even, those are in my p.s. below no less as your "2 biggest fails" you ran from in the end... lol!):
Read on folks. this is hilarious, & point-by-point with backing proofs thereof as to my statements now above!
"BTW, my CD will let a tech run the recovery console on a machine remotely, over the Internet" - by cbiltcliffe (186293) on Thursday July 14, @10:10PM (#36771200) Homepage Journal
(Once I was pointed out your CD wasn't needed & obsolete against that rootkit, YOU got pissed off! Too bad, truth is truth... & YOU CAN'T HANDLE THE TRUTH!)
In fact, you admitted it yourself that my technique worked without your CD (thus "your" cd? Unneeded, & obsolete):
"Will it get rid of an MBR rootkit? Yes. Will it get rid of a driver-based rootkit with a discrete .sys file for the driver? Yes." - by cbiltcliffe (186293) on Tuesday July 12, @03:12PM (#36738656) Homepage Journal
And, there you are (literally admitting my technique for removing "the indestructable rootkit" works, non-destructively, from a read-only media using proven tools from Windows RECOVERY CONSOLE).
---
"Whether you want to admit it or not, my statements regarding you implying TCPview could show connections from rootkits are true. You did imply it." - by cbiltcliffe (186293) on Wednesday July 13, @02:27PM (#36752240) Homepage
No, your reading comprehension obviously sucks... or you skimmed, or are just trying to cover your behind trolling & burying my points all shown here and in the exchange they took place in, out of your "geek angst" due to your own numerous failures vs. myself!
Simply because I can show, here, EXACTLY what I said EXPLICITY on this account also where you tried to put words into my mouth I NEVER SAID or even IMPLIED (quoting myself yet again to disprove you):
PERTINENT QUOTE, VERBATIM FROM MYSELF:
"I can watch who/what/when/where/how my system "talks" to other systems online, & if I see one I am NOT talking to? It gets added to my firewall list (by IP address), and the offending unknown interloper malware/botnet gets "BLOWN AWAY" by ProcessExplorer.exe, as I noted in my last post/other post in reply to YOUR last post." - by Anonymous Coward (Myself, APK) on Saturday July 02, @11:35PM (#36644860)
FROM -> http://it.slashdot.org/comments.pl?sid=2282088&cid=36644860
AND, that's ALL I use TcpView for... vs. ring3/rpl3/usermode malwares (botnets running there, virus, spyware, trojans, keyloggers, etc. BUT NOT ROOTKITS!)
---
I also pointed out, after you went off topic & proposed "theoretical rootkits", some layered security methods against it via:
Group Policies (where you can BLOCK unsigned driver installs that rootkits like this use in hello_tt.sys)
Are all you need to be 100% secure - show me explicitly stating that please.
You can't & you know it. Tomhudson, & gmhowell tried that, they both RAN because they could not do that... no, all you have is trying to put words in my mouth I never said...
"No, no, no...all you need to do is add a HOSTS file, and everything will be 100% secure until the end of the universe!! hehehe." - by cbiltcliffe (186293) on Friday July 15, @09:11AM (#36774056) Homepage
* U FAIL, as usual!
Just like your consolidated FAIL list vs. myself here today shows clearly:
http://slashdot.org/comments.pl?sid=2324592&cid=36776760
APK
P.S.=> That's where I let you trash yourself... especially by using your own mistakes, & technical inadequacy/impotency, even when you went off topic & tried putting words in my mouth I never once said!
Also?
Please - Don't tell me you're not trying to get my goat on HOSTS either, because the other repliers to you (probably your pals or sockpuppets) are mentioning my name:
http://slashdot.org/comments.pl?sid=2324592&cid=36774834
and here:
http://slashdot.org/comments.pl?sid=2324770&cid=36774146
(Doubtless more of your sock puppet alternate registered accounts you have, or those of others I have trashed before (cowards like yourself ALWAYS do that in rather "effete retaliation")).
And you did these posts today on HOSTS files here:
MANY times already today... WELL, back it up, prove I say HOSTS are "all you need" for perfect security then!
I'll be waiting... lol, until the "12th of never" & when the clock hand strikes 13, because I never once ever said that OR implied it even! I preach layered security:
http://www.bing.com/search?q=%22HOW+TO+SECURE+Windows+2000%2FXP%22&go=&form=QBRE
That does far more than just HOSTS files, but they are an excellent layered security measure.
NOW - Just because you ran from where that took place too in the topmost link above? Talking behind my back's the "best you've got" along with adhominem attacks?? LMAO... & on each point noted in the link above, OR you failed vs. trying to disprove them!
(Where you also tried to put words in my mouth about TcpView &/or ProcessExplorer in regards to detecting rookits or removing them using those tools & I never said that once, either you have reading troubles, OR as I suspect, a troll that tries putting words in others' mouths they never said & later behind their backs too, in "effete geek angst" (that's what women do, not men))
... apk
Or what?? Is that comment of yours supposed to upset me? If so, what's your problem with HOSTS files then??
APK
P.S.=> I'd like to hear about it then, go for it... & then, I'll just tear it apart with facts!
(Just like I tore the "wannabe computer security guru" cbiltcliffe apart, step by methodical destroying step this week -> http://slashdot.org/comments.pl?sid=2324770&cid=36776728 and here again now in regards to HOSTS file here -> http://slashdot.org/comments.pl?sid=2324770&cid=36777198 )
In the 1st link, lol, & in the end he HAD to agree my method for killing the "unkillable rootkit" worked, & his CD was unnecessary... lol!
(Which is WHY he's doing these trolling goadings of myself in "effete retaliation", like pussy's do in real life, instead of owning their screwups like a man instead... he can't handle his own "geek angst" @ being SPANKED by his technical superior in the art & science of computing in myself!)
... apk
why does anyone ship anything with a six-character password? why does any website allow them? eight is barely sufficient given recent gpu-based attacks, and i seriously doubt people who have trouble remembering eight characters have any less trouble with six.
Media that can be recorded and distributed can be recorded and distributed.
-kfg
Umm, is there a way to modify my HOSTS file so I don't ever have to see your ramblings again? 'Cuz that would be a good reason to modify my HOSTS file.
Wow! Watch the spittle fly!!!
"City hall" in German is "Rathaus" Kinda explains a few things......
".elif STSOH ym yfidom ot nosaer doog a eb dluow taht zuC' ?niaga sgnilbmar ruoy ees ot evah reve t'nod I os elif STSOH ym yfidom ot yaw a ereht si ,mmU" - by WrongSizeGlass ANOTHER "ne'er-do-well" /. OFF-TOPIC TROLL on Friday July 15, @04:50PM (#36779976)
"???"
Uhm... Could we get a translation of that off-topic "troll-speak/trolllanguage" of yours, please?
* And, you're an off-topic troll - no questions asked...SEE MY SUBJECT LINE ABOVE!
APK
P.S.=> Yes, it must have just have been another off-topic done nothing of significance with his life troll spewing his off-topic b.s. again & not contributing to the ongoing conversations. Oh well - No biggie!
("ReVeRsE-PsYcHoLoGy", for trolls - Courtesy of this code by "yours truly" in less than 1 second flat):
---
#TrollTalkComReversePsychologyKiller.py (Ver #2 by APK)
def reverse(s):
try:
trollstring = ""
for apksays in s:
trollstring = apksays + trollstring
except:
print("error/abend in reverse function")
return trollstring
s = ""
print reverse(s)
try:
s = "Insert whatever 'trollspeak/trolllanguage' gibberish occurs here..."
s = reverse(s)
print(s)
except Exception as e:
print(e)
---
... apk
Because you did terribly here, lol -> http://slashdot.org/comments.pl?sid=2324592&cid=36776760
And here too -> http://slashdot.org/comments.pl?sid=2324592&cid=36776972
APK
P.S.=> "Run, Forrest... RUN!"
... apk
I've gotten to the boot loader and rooted the Verizon 1x, 3g, and Sprint units. The bootloader password is stored in plain text...in their GPL release. From there, if you can figure out MonteVista linux, the ipsec keys are easily found. Also the web management passwords are easy to find. http://rsaxvc.net/cgi-bin/mt/mt-search.cgi?search=scs&IncludeBlogs=3&limit=20