User comments on ISPs
  >> EE (Everything Everywhere) and Orange


Register (or login) on our website and you will not see this ad.


Pages in this thread: 1 | [2] | 3 | 4 | (show all)   Print Thread
Standard User XRaySpeX
(eat-sleep-adslguide) Fri 11-Oct-13 20:58:22
Print Post

Re: Bright Box plain-text security leaks


[re: glossywhite] [link to this post]
 
It's takes 2 to tango!

In this case I contend that it is your issue by not being prepared to answer a simple reasonable Q. I have claimed no 'rights' in this thread; only Qs.

Here ends the lesson grin!

1999: Freeserve 48K Dial-Up => 2005: Wanadoo 1 Meg BB => 2007: Orange 2 Meg BB => 2008: Orange 8 Meg LLU => 2010: Orange 16 Meg LLU => 2011: Orange 20 Meg WBC
Standard User glossywhite
(member) Fri 11-Oct-13 21:23:18
Print Post

Re: Bright Box plain-text security leaks


[re: XRaySpeX] [link to this post]
 
In reply to a post by XRaySpeX:
It's takes 2 to tango!

In this case I contend that it is your issue by not being prepared to answer a simple reasonable Q. I have claimed no 'rights' in this thread; only Qs.

Here ends the lesson grin!


Have a nice night - there's more to life that routers and being right smile
Standard User XRaySpeX
(eat-sleep-adslguide) Fri 11-Oct-13 21:34:16
Print Post

Re: Bright Box plain-text security leaks


[re: glossywhite] [link to this post]
 
In reply to a post by glossywhite:
Just connected to my OPEN virtual WiFi on the Bright Box, and it hands over the info no questions asked.
Not surprising if you leave an unauthenticated SSID (don't see 'virtual' comes into it). You don't even need to inject these special URLs!

1999: Freeserve 48K Dial-Up => 2005: Wanadoo 1 Meg BB => 2007: Orange 2 Meg BB => 2008: Orange 8 Meg LLU => 2010: Orange 16 Meg LLU => 2011: Orange 20 Meg WBC


Register (or login) on our website and you will not see this ad.

Standard User XRaySpeX
(eat-sleep-adslguide) Fri 11-Oct-13 21:38:41
Print Post

Re: Bright Box plain-text security leaks


[re: glossywhite] [link to this post]
 
In reply to a post by glossywhite:
there's more to life thatn routers
Too true! Funny how all your posts have been about them; indeed just the BrightBox.

1999: Freeserve 48K Dial-Up => 2005: Wanadoo 1 Meg BB => 2007: Orange 2 Meg BB => 2008: Orange 8 Meg LLU => 2010: Orange 16 Meg LLU => 2011: Orange 20 Meg WBC
Standard User glossywhite
(member) Fri 11-Oct-13 21:49:35
Print Post

Re: Bright Box plain-text security leaks


[re: XRaySpeX] [link to this post]
 
In reply to a post by XRaySpeX:
In reply to a post by glossywhite:
there's more to life thatn routers
Too true! Funny how all your posts have been about them; indeed just the BrightBox.


You don't let up, do you.

Even a fool appears wise when he says nothing; surely saying nothing is better than causing hard feeling just because you can't NOT say something?

I'm sure you're much too clever than to make "smart" comments, the only purpose of which are to cause annoyance and offence - this is not the first time you have been needlessly pedantic and know-it-all to me - I'd urge you to stop - you don't exactly endear people to you, making them WANT to communicate.

Edited by glossywhite (Fri 11-Oct-13 21:57:51)

Standard User deleted
(deleted) Tue 07-Jan-14 19:58:03
Print Post

Re: Bright Box plain-text security leaks


[re: glossywhite] [link to this post]
 
Hi glossywhite,

I've sent you a PM if you get chance to pick it up and respond that would be great.

Scott.
Standard User Pipexer
(eat-sleep-adslguide) Wed 08-Jan-14 21:09:01
Print Post

Re: Bright Box plain-text security leaks


[re: glossywhite] [link to this post]
 
In reply to a post by glossywhite:
PS: Amazing things, firmware upgrades, because even router designers are human.


I tried to tell you last year how rubbish these routers are, but you insisted it was the most amazing piece of networking equipment ever produced.

Zen 8000 Pro

Edited by Pipexer (Wed 08-Jan-14 21:10:11)

Standard User deleted
(deleted) Thu 09-Jan-14 12:10:50
Print Post

Re: Bright Box plain-text security leaks


[re: glossywhite] [link to this post]
 
In reply to a post by glossywhite:
I put these URLs into a browser on a machine in my network... a machine that has NEVER connected to the router pages... and it gives up PLAIN TEXT security data... try them youselves.

The machine was not even logged in on the router!


Brower: "Give me all your security credentials"

Router: "Oh, okay!"


http://192.168.1.1/cgi/cgi_status.js?t=1381432913046

http://192.168.1.1/cgi/cgi_wifi_wpa.js?t=1381433787099

http://192.168.1.1/cgi/cgi_atmint.js?t=1381434119553

http://192.168.1.1/cgi/cgi_status.js?t=1381434119550

http://192.168.1.1/cgi/cgi_security_log.js?t=1381434403382

http://192.168.1.1/cgi/cgi_wireless_wps.js?t=1381434403382
If I use the router default gateway IP address 192.168.1.1 or my own chosen gateway IP address 192.168.XX.XXX None of those URL addresses work with my Bright Box 1 router, all I get is Microsoft JScript runtime error. wink

Using Windows 7 Pro with Internet Explorer 11

Edited by deleted (Thu 09-Jan-14 12:19:21)

Standard User XRaySpeX
(eat-sleep-adslguide) Thu 09-Jan-14 15:11:44
Print Post

Re: Bright Box plain-text security leaks


[re: deleted] [link to this post]
 
In reply to a post by E7er:
all I get is Microsoft JScript runtime error. wink
As I pointed out ages ago, yes they fail on IE, but they work in FF.

1999: Freeserve 48K Dial-Up => 2005: Wanadoo 1 Meg BB => 2007: Orange 2 Meg BB => 2008: Orange 8 Meg LLU => 2010: Orange 16 Meg LLU => 2011: Orange 20 Meg WBC
Standard User deleted
(deleted) Tue 14-Jan-14 18:50:32
Print Post

Re: Bright Box plain-text security leaks


[re: glossywhite] [link to this post]
 
I thought you'd be interested in an article I've just written about the EE BrightBox.

It seems the security of the device is worse than it appears, allowing an attacker to bypass the admin login, exploit the device remotely and even take control of your EE account by leaking credentials.

You can see the article on my blog here: http://scotthel.me/eebb

Scott.
Pages in this thread: 1 | [2] | 3 | 4 | (show all)   Print Thread

Jump to