Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | new home existing cables

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Virgin Media Services > Virgin Media Internet Service
Register FAQ Community Calendar

Superhub 7 second exploit
Reply
 
Thread Tools
Old 06-03-2014, 22:18   #1
LemonyBrainAid
Inactive
 
Join Date: Jul 2004
Location: 127.0.0.1
Services: 50MB Virgin w/ TiVo 1TB
Posts: 1,255
LemonyBrainAid has a bronze arrayLemonyBrainAid has a bronze arrayLemonyBrainAid has a bronze array
LemonyBrainAid has a bronze arrayLemonyBrainAid has a bronze arrayLemonyBrainAid has a bronze arrayLemonyBrainAid has a bronze array
Superhub 7 second exploit

Apologies if this has already been posted somewhere (searched and couldn't find anything), but stumbled across this and had to share.

Allegedly it's possible to make use of a 7-second window of unsecured WiFi access during the SuperHub boot process to gain access to the admin panel and retrieve the unmasked WiFi password.

It requires the admin panel password, but as we all know it's very rare for the general user to do change that

Read more (and learn how to protect against it) here:
http://ramblingrant.co.uk/2014/03/06...security-flaw/
LemonyBrainAid is offline   Reply With Quote
Advertisement
Old 06-03-2014, 22:54   #2
Coffeeguy
cf.member
 
Join Date: Aug 2012
Services: Hub 5 VM 200MB Broadband
Posts: 61
Coffeeguy is on a distinguished roadCoffeeguy is on a distinguished road
Re: Superhub 7 second exploit

More reason to put the darned thing into modem mode
Coffeeguy is offline   Reply With Quote
Old 06-03-2014, 23:01   #3
Synthetic
cf.geek
 
Join Date: Jul 2010
Location: Newcastle
Posts: 785
Synthetic is a name known to allSynthetic is a name known to allSynthetic is a name known to allSynthetic is a name known to allSynthetic is a name known to allSynthetic is a name known to allSynthetic is a name known to allSynthetic is a name known to all
Re: Superhub 7 second exploit

Interesting, think i'll give this a try (on my own shub of course)
Synthetic is offline   Reply With Quote
Old 06-03-2014, 23:40   #4
thenry
XIV
 
thenry's Avatar
 
Join Date: Dec 2009
Location: Crawley
Age: 35
Services: Three Unlimited
Posts: 15,772
thenry has a nice shiny starthenry has a nice shiny starthenry has a nice shiny starthenry has a nice shiny star
thenry has a nice shiny starthenry has a nice shiny starthenry has a nice shiny starthenry has a nice shiny starthenry has a nice shiny starthenry has a nice shiny starthenry has a nice shiny starthenry has a nice shiny starthenry has a nice shiny starthenry has a nice shiny starthenry has a nice shiny starthenry has a nice shiny starthenry has a nice shiny starthenry has a nice shiny starthenry has a nice shiny starthenry has a nice shiny starthenry has a nice shiny starthenry has a nice shiny starthenry has a nice shiny star
Re: Superhub 7 second exploit

Quote:
Originally Posted by LemonyBrainAid View Post
Apologies if this has already been posted somewhere (searched and couldn't find anything), but stumbled across this and had to share.

Allegedly it's possible to make use of a 7-second window of unsecured WiFi access during the SuperHub boot process to gain access to the admin panel and retrieve the unmasked WiFi password.

It requires the admin panel password, but as we all know it's very rare for the general user to do change that

Read more (and learn how to protect against it) here:
http://ramblingrant.co.uk/2014/03/06...security-flaw/
I told VM about this from the get go when testing the SH2 and it was taken on board and as far as I know it was fixed. Now when the SH2 boots up wifi 2.4GHz & 5GHz do not load up until a minute or two after the modem/router syncs etc.

Do your SH2 lights match up to whats actually going on? Could you please tell us the lighting sequence from power on to fully loaded up.

Also what is your software version > http://192.168.100.1/cgi-bin/VmRouterStatusInfoCfgCgi
thenry is online now   Reply With Quote
Old 07-03-2014, 00:31   #5
Skie
a giant headend
 
Join Date: Jan 2011
Location: Liverpool
Posts: 1,169
Skie has reached the bronze age
Skie has reached the bronze ageSkie has reached the bronze ageSkie has reached the bronze ageSkie has reached the bronze ageSkie has reached the bronze ageSkie has reached the bronze ageSkie has reached the bronze age
Re: Superhub 7 second exploit

Yeah, the SH2 popping up with unsecured wifi connections during boot was certainly reported by a few people during the trial. I wonder if the 'fix' was to just make them not broadcast their SSID during boot instead of actually fixing the problem properly.

Also interesting to know that you can reboot a superhub remotely.
Skie is offline   Reply With Quote
Old 07-03-2014, 00:55   #6
qasdfdsaq
cf.mega poster
 
Join Date: Aug 2004
Posts: 11,207
qasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronze
qasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronze
Re: Superhub 7 second exploit

Sounds like a pretty standard bootup sequence for a consumer router to be honest.
qasdfdsaq is offline   Reply With Quote
Old 07-03-2014, 00:59   #7
Ignitionnet
Inactive
 
Join Date: Jun 2008
Location: Leeds, West Yorkshire
Age: 47
Posts: 13,995
Ignitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny stars
Ignitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny stars
Re: Superhub 7 second exploit

Quote:
Originally Posted by qasdfdsaq View Post
Sounds like a pretty standard bootup sequence for a consumer router to be honest.
Confirmed. The HH5 boots up in the same way.
Ignitionnet is offline   Reply With Quote
Old 07-03-2014, 13:35   #8
StevenNT
Inactive
 
Join Date: May 2012
Location: Farnborough, Hampshire
Age: 44
Services: 500Mb Hyperoptic, Sky Signature with HD, UHD and Ultimate On Demand
Posts: 225
StevenNT has a spectacular aura about themStevenNT has a spectacular aura about themStevenNT has a spectacular aura about themStevenNT has a spectacular aura about them
Re: Superhub 7 second exploit

Quote:
Originally Posted by Ignitionnet View Post
Confirmed. The HH5 boots up in the same way.
Does the BT HH5 broadcast it's encryption key during boot?
StevenNT is offline   Reply With Quote
Old 07-03-2014, 13:51   #9
Ignitionnet
Inactive
 
Join Date: Jun 2008
Location: Leeds, West Yorkshire
Age: 47
Posts: 13,995
Ignitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny stars
Ignitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny stars
Re: Superhub 7 second exploit

Haven't sniffed it, just noted that the thing broadcasts SSIDs before it applies security policy.
Ignitionnet is offline   Reply With Quote
Old 07-03-2014, 14:44   #10
qasdfdsaq
cf.mega poster
 
Join Date: Aug 2004
Posts: 11,207
qasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronze
qasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronze
Re: Superhub 7 second exploit

Openwrt and DD-Wrt also behave the same way.

That said nobody mentioned the Superhub broadcasting its encryption key... Only that you can log in and manually retrieve the network access password.

Actual encryption keys are randomly generated on the fly and automatically changed every few minutes anyway.
qasdfdsaq is offline   Reply With Quote
Old 07-03-2014, 15:04   #11
Ignitionnet
Inactive
 
Join Date: Jun 2008
Location: Leeds, West Yorkshire
Age: 47
Posts: 13,995
Ignitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny stars
Ignitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny starsIgnitionnet has a pair of shiny stars
Re: Superhub 7 second exploit

I assumed that he meant the network access password, Mr QWERTY. Would be a truly spectacular mess up if an AP broadcast that.
Ignitionnet is offline   Reply With Quote
Old 07-03-2014, 16:03   #12
qasdfdsaq
cf.mega poster
 
Join Date: Aug 2004
Posts: 11,207
qasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronze
qasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronzeqasdfdsaq is cast in bronze
Re: Superhub 7 second exploit

To be honest actually broadcasting the password would be an equally spectacular mess up IMO.
qasdfdsaq is offline   Reply With Quote
Old 07-03-2014, 16:10   #13
Sirius
Grumpy Fecker
 
Sirius's Avatar
 
Join Date: Jul 2007
Location: Warrington
Age: 65
Services: Every Weekend
Posts: 17,032
Sirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver bling
Sirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver blingSirius has a lot of silver bling
Re: Superhub 7 second exploit

Quote:
Originally Posted by Coffeeguy View Post
More reason to put the darned thing into modem mode
__________________
The UK is now the regime of Kim Jong Starmer the UK's dictator
Sirius is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 14:27.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum