User comments on ISPs
  >> EE (Everything Everywhere) and Orange


Register (or login) on our website and you will not see this ad.


Pages in this thread: 1 | 2 | 3 | >> (show all)   Print Thread
Standard User deleted
(deleted) Fri 31-Jan-14 22:24:05
Print Post

Brightbox Security Update


[link to this post]
 
Well 4 hours on the phone to EE and I have now got them to push the firmware update to my Brightbox 1 router. It has updated as follows

Runtime Code Version: v0.09.94.0006-OT (Fri Sep 21 03:00:26 2012)
to
Runtime Code Version: v0.10.06.0001-OT (Wed Jan 22 22:50:41 2014)


I have also asked them to update my Brightbox 2, but they say that it is up to date
v0.01.42.0001-OT (Mon Aug 26 13:10:37 2013)

Is this correct? Did the security issue not affect both BB1 and BB2, as suggested in the BBC article.

Any help would be great

Steve
Standard User deleted
(deleted) Sat 01-Feb-14 12:47:55
Print Post

Re: Brightbox Security Update


[re: deleted] [link to this post]
 
There is no official release of the latest security firmware upgrade for the EE Bright Box 1 router that I have seen. confused

My Bright Box 1 router still has�
Runtime Code Version: v0.09.94.0006-OT (Fri Sep 21 03:00:26 2012)
Boot Code Version: v1.00.10.0001-OT (Wed Dec 14 09:30:42 2011)
ADSL Modem Code Version: A2pD035b.d23i
Hardware Version: 01

http://help.ee.co.uk/system/selfservice.controller?C...
Standard User deleted
(deleted) Sat 01-Feb-14 13:56:17
Print Post

Re: Brightbox Security Update


[re: deleted] [link to this post]
 
Hi Steve,

The version you have is the same version that EE provided me with so I think this is the patch they are going to start rolling out in their phased deployment.

I too was under the impression that the BrightBox 2 was affected after my conversation with the BBC. I will contact EE and see if I can get some further clarification direct from them.

You can check all of the links in my article against your BrightBox 2 to see if it is vulnerable. Some confirmation either way would actually be helpful.

Scott.


Register (or login) on our website and you will not see this ad.

Standard User deleted
(deleted) Sat 01-Feb-14 14:08:34
Print Post

Re: Brightbox Security Update


[re: deleted] [link to this post]
 
Here are the before and after details from my BB1

Before
Runtime Code Version: v0.09.94.0006-OT (Fri Sep 21 03:00:26 2012)
Boot Code Version: v1.00.10.0001-OT (Wed Dec 14 09:30:42 2011)
ADSL Modem Code Version: A2pD035b.d23i
Hardware Version: 01


After
Runtime Code Version: v0.10.06.0001-OT (Wed Jan 22 22:50:41 2014)
Boot Code Version: v1.00.10.0001-OT (Wed Dec 14 09:30:42 2011)
ADSL Modem Code Version: A2pD035b.d23i
Hardware Version: 01

Edited by deleted (Sat 01-Feb-14 14:12:27)

Standard User deleted
(deleted) Sat 01-Feb-14 14:11:33
Print Post

Re: Brightbox Security Update


[re: deleted] [link to this post]
 
Hi Scott,

Thanks for your reply and all the hard work you have put into the matter.

A manager from EE Tech support India is going to call me tonight to let me know if he was able to find out if there would be an update for the BB2. I did point out the BBC article to him.

BB2
Runtime Code Version v0.01.42.0001-OT (Mon Aug 26 13:10:37 2013)
Boot Code Version 0.0.9-OT (Thu Aug 8 18:14:37 2013)
DSL Modem Code Version A2pv6F039c.d24j-AnnexA
Hardware Version 01


Cheers

Steve

Edited by deleted (Sat 01-Feb-14 14:14:28)

Standard User deleted
(deleted) Sat 01-Feb-14 14:17:48
Print Post

Re: Brightbox Security Update


[re: deleted] [link to this post]
 
Good stuff. Keep me updated, I'm interested to know.

Scott.
Standard User deleted
(deleted) Sat 01-Feb-14 14:30:04
Print Post

Re: Brightbox Security Update


[re: deleted] [link to this post]
 
Will do Scott.

Just hope he sticks to his word and actually calls back, as I can not face calling them again!

: )

Steve
Standard User deleted
(deleted) Sat 01-Feb-14 19:29:39
Print Post

Re: Brightbox Security Update


[re: deleted] [link to this post]
 
No call back. Here we go again

: (
Standard User deleted
(deleted) Sat 01-Feb-14 19:43:46
Print Post

Re: Brightbox Security Update


[re: deleted] [link to this post]
 
Just spoke to a "manager" who said he has read an internal article from 22/01/2014 to say that a new firmware will be released to BB2 soon.

Judging by the reps I have spoken to they are just making it go as they go along!
Standard User deleted
(deleted) Sat 01-Feb-14 19:51:57
Print Post

Re: Brightbox Security Update


[re: deleted] [link to this post]
 
My BB1 has not had the firmware update as yet. Also EE appear to be very quiet on this matter. I would have thought that they would have posted something on their website as they did when firmware update was issued last yesr to change from Orange to EE.

Just an observation.
Standard User deleted
(deleted) Sat 01-Feb-14 19:54:35
Print Post

Re: Brightbox Security Update


[re: deleted] [link to this post]
 
Yep, too true

Last published upgrade for BB1 (Orange to EE branding) was 2012)

http://help.ee.co.uk/system/selfservice.controller?C...
Standard User deleted
(deleted) Sun 02-Feb-14 17:41:02
Print Post

Re: Brightbox Security Update


[re: deleted] [link to this post]
 
EE did tell me they were going to release something about this but as yet, I can't see anything. Perhaps they are going to wait until the roll out has been completed?
Standard User deleted
(deleted) Wed 05-Feb-14 18:00:49
Print Post

Re: Brightbox Security Update


[re: deleted] [link to this post]
 
I have spoken to a reliable rep and he said EE are hoping to have this rolled out by the end of February 2014.

Steve
Standard User deleted
(deleted) Thu 06-Feb-14 20:15:59
Print Post

Re: Brightbox Security Update


[re: deleted] [link to this post]
 
Is that the firmware patch or the statement about what's happened? Just for clarification.

Scott.
Standard User deleted
(deleted) Thu 06-Feb-14 21:32:37
Print Post

Re: Brightbox Security Update


[re: deleted] [link to this post]
 
Hi Scott,

The firmware patch for BB2 should be rolled out by end of Feb.

Cheers

Steve
Standard User deleted
(deleted) Mon 10-Feb-14 20:56:59
Print Post

Re: Brightbox Security Update


[re: deleted] [link to this post]
 
Here is my latest blog on the firmware update that EE have released:

http://scotthel.me/eebb2

EE have patched 2 out of the 3 major issues and they are currently working towards resolving the 3rd. More details in the blog.

Scott.
Standard User deleted
(deleted) Wed 12-Feb-14 19:07:13
Print Post

Re: Brightbox Security Update


[re: deleted] [link to this post]
 
Firmware update done on my BrightBox 1 last night - midnight:

SYSTEM

Runtime Code Version: v0.10.06.0001-OT (Wed Jan 22 22:50:41 2014)
Boot Code Version: v1.00.10.0006-OT (Fri Sep 21 03:00:26 2012)
ADSL Modem Code Version: A2pD035b.d23i
Hardware Version: 01
Standard User XRaySpeX
(eat-sleep-adslguide) Wed 12-Feb-14 23:45:58
Print Post

Re: Brightbox Security Update


[re: deleted] [link to this post]
 
Do you think that when EE send you a replacement BB1 (to try allegedly to fix a fault) that they 'deregister' your original BB1 so it won't get the update?

I ran the new BB1 for about 2 weeks, the last 7 days of which the line has been faultless. So I have reverted to my original BB1 to prove to myself that the original fault had nowt to do with the router. It has now run 3.5 days faultlessly.

So i'm wondering whether the original BB1, now online, will ever get the update?

1999: Freeserve 48K Dial-Up => 2005: Wanadoo 1 Meg BB => 2007: Orange 2 Meg BB => 2008: Orange 8 Meg LLU => 2010: Orange 16 Meg LLU => 2011: Orange 20 Meg WBC
Standard User glossywhite
(member) Thu 13-Feb-14 00:39:48
Print Post

Re: Brightbox Security Update


[re: XRaySpeX] [link to this post]
 
Ripping the firmware, packing and uploading it is trivial for someone with the skill to do so. If someone with a Bright Box which is updated, you can send me it, I'll rip the firmware and share it. Then, all you have to do is flash your Bright Box using the recovery page. Easy peasy, lemon squeezy tongue

Edited by glossywhite (Thu 13-Feb-14 00:40:25)

Standard User XRaySpeX
(eat-sleep-adslguide) Thu 13-Feb-14 00:49:01
Print Post

Re: Brightbox Security Update


[re: glossywhite] [link to this post]
 
Irrelevant to my Q. I'm not interested in unofficial bodges by someone who is unable to test his mods thoroughly and fully w/out any quality assurance.

1999: Freeserve 48K Dial-Up => 2005: Wanadoo 1 Meg BB => 2007: Orange 2 Meg BB => 2008: Orange 8 Meg LLU => 2010: Orange 16 Meg LLU => 2011: Orange 20 Meg WBC
Standard User deleted
(deleted) Thu 13-Feb-14 07:28:09
Print Post

Re: Brightbox Security Update


[re: deleted] [link to this post]
 
Zak, good to hear that you have the update!

Ray, this is precisely why I keep pressing EE to make the update available to download. This, and other situations, where a router doesn't receive an update. Customers should have access to critical security updates without depending on some automated system. If you want to go and download the latest firmware to flash your router, you should be able to. It's as simple as that.

Glossy, I have already ripped the firmware as I wanted the ability to flash between the new and old version whilst testing various issues. I haven't made it available simply because EE already don't like me and I didn't want to give them grounds to kick up a fuss (me distributing their firmware). I'm not sure if there are legal issues to consider so I thought I'd just play it safe.
Standard User deleted
(deleted) Thu 13-Feb-14 17:35:07
Print Post

Re: Brightbox Security Update


[re: deleted] [link to this post]
 
BB2 update should be rolling from now and over the next week or so.


I received my update today

BB2
Runtime Code Version
v0.01.47.0001-OT (Thu Jan 16 12:53:50 2014)

Boot Code Version
0.0.9-OT (Thu Aug 8 18:14:37 2013)

DSL Modem Code Version
A2pv6F039c.d24j-AnnexA

Hardware Version
01


Steve

Edited by deleted (Thu 13-Feb-14 17:42:10)

Standard User glossywhite
(member) Thu 13-Feb-14 20:14:46
Print Post

Re: Brightbox Security Update


[re: XRaySpeX] [link to this post]
 
In reply to a post by XRaySpeX:
Irrelevant to my Q. I'm not interested in unofficial bodges by someone who is unable to test his mods thoroughly and fully w/out any quality assurance.


You're rather rude and discourteous; it's not the first time you've been this way. If there's nothing nice to say to me, it's going to be less stressful for you to opt out of responding to my posts, therefore eliminating the anxiety or annoyance I seem to cause you; it's quite simply really, just refrain from talking to me if you have a hang up - I won't be offended or hurt, I am kind to everyone as much as is humanly possible.

Thanks smile

Edited by glossywhite (Thu 13-Feb-14 20:17:30)

Standard User XRaySpeX
(eat-sleep-adslguide) Wed 19-Mar-14 17:18:28
Print Post

Re: Brightbox Security Update


[re: deleted] [link to this post]
 
Finally got my BB1 Security Update today after I had left it online for weeks on end as instructed, having been told by EE that the update would be downloaded automatically, but it never was frown.

However early this AM the BB1 would not connect to the Net altho' it was synced OK and had passed CHAP authentication. At 1st I imagined that EE had blocked my BB1s from the Net prematurely as they were in the process of sending me a new ready-updated BB. However I factory reset the BB and let it do a TR-069 (ACS) auto-configuration. In doing so it finally did the update and I could now get on the Net smile.

My Runtime Code Version is now the same as yours:
Runtime Code Version: v0.10.06.0001-OT (Wed Jan 22 22:50:41 2014)
Boot Code Version: v1.00.10.0006-OT (Fri Sep 21 03:00:26 2012)
ADSL Modem Code Version: A2pD035b.d23i
Hardware Version: 01
Serial Num: J331165307
Only nearly 2 months late!

1999: Freeserve 48K Dial-Up => 2005: Wanadoo 1 Meg BB => 2007: Orange 2 Meg BB => 2008: Orange 8 Meg LLU => 2010: Orange 16 Meg LLU => 2011: Orange 20 Meg WBC
Pages in this thread: 1 | 2 | 3 | >> (show all)   Print Thread

Jump to