User comments on ISPs
  >> EE (Everything Everywhere) and Orange


Register (or login) on our website and you will not see this ad.


Pages in this thread: 1 | 2 | [3] | 4 | (show all)   Print Thread
Standard User glossywhite
(member) Sun 19-Jan-14 20:47:02
Print Post

Re: Bright Box plain-text security leaks


[re: deleted] [link to this post]
 
In reply to a post by ScottHelme:
I thought you'd be interested in an article I've just written about the EE BrightBox.

It seems the security of the device is worse than it appears, allowing an attacker to bypass the admin login, exploit the device remotely and even take control of your EE account by leaking credentials.

You can see the article on my blog here: http://scotthel.me/eebb

Scott.


Hello Scott smile

That's a nice article; FAR more research than I could be bothered to do over such a poor device. I'm now moving back to electronics as the majority of my work - I'm a hardware guy more - I have been since I was a child - software just frustrates me and confuses me.

LOVE the shotgun - that's the best thing for this piece of hardware - I have SIX spares, all brand new, and do you think EE will listen to me, and send me a BB 2? Nope - they just stonewall me. Poor show.

Great article! laugh

God bless you,

Matt.
Standard User deleted
(deleted) Sun 19-Jan-14 22:24:54
Print Post

Re: Bright Box plain-text security leaks


[re: glossywhite] [link to this post]
 
Hey Matt,

Yeah, it is bad that they're still shipping these things out and considering how long they have been aware of this and not patched it, well, unbelievable.

I've been trying to get a BB 2 also, let me know if you have any joy and how you get one.

Cheers,

Scott.
Standard User deleted
(deleted) Mon 20-Jan-14 12:59:33
Print Post

Re: Bright Box plain-text security leaks


[re: deleted] [link to this post]
 
At last EE taking action:

EE rushes to fix broadband box security risk


Register (or login) on our website and you will not see this ad.

Standard User XRaySpeX
(eat-sleep-adslguide) Mon 20-Jan-14 13:37:52
Print Post

Re: Bright Box plain-text security leaks


[re: deleted] [link to this post]
 
Well done, Scott, and getting it in the news smile !

1999: Freeserve 48K Dial-Up => 2005: Wanadoo 1 Meg BB => 2007: Orange 2 Meg BB => 2008: Orange 8 Meg LLU => 2010: Orange 16 Meg LLU => 2011: Orange 20 Meg WBC
Standard User glossywhite
(member) Mon 20-Jan-14 15:31:35
Print Post

Re: Bright Box plain-text security leaks


[re: XRaySpeX] [link to this post]
 
In reply to a post by XRaySpeX:
Well done, Scott, and getting it in the news smile !


I thought it "wasn't an issue"? wink

How soon people change their minds... LOL.
Standard User XRaySpeX
(eat-sleep-adslguide) Mon 20-Jan-14 16:14:02
Print Post

Re: Bright Box plain-text security leaks


[re: glossywhite] [link to this post]
 
Where did I say that? I just pointed your findings were of low risk, not Scott's.. Here I was just congratulating Scott on his much more in-depth research.

You are most spiteful and defensive!

1999: Freeserve 48K Dial-Up => 2005: Wanadoo 1 Meg BB => 2007: Orange 2 Meg BB => 2008: Orange 8 Meg LLU => 2010: Orange 16 Meg LLU => 2011: Orange 20 Meg WBC
Standard User Oliver341
(eat-sleep-adslguide) Mon 20-Jan-14 18:08:14
Print Post

Re: Bright Box plain-text security leaks


[re: glossywhite] [link to this post]
 
I notice the scotthelme website doesn't credit you for finding the exploited URLs.

Who originally discovered these?

Oliver.
Standard User deleted
(deleted) Mon 20-Jan-14 18:50:31
Print Post

Re: Bright Box plain-text security leaks *DELETED*


[re: Oliver341] [link to this post]
 
Post deleted by Zak_
Standard User deleted
(deleted) Mon 20-Jan-14 20:42:31
Print Post

Re: Bright Box plain-text security leaks


[re: Oliver341] [link to this post]
 
I found the first exploited URLs using packet sniffing software and then went on to find the rest from the device itself. I used to be a firmware tester so hooking up to JTAG/serial headers on an embedded device is something I'm familiar with.

If credit were due, it would have been given!

Scott.
Standard User deleted
(deleted) Mon 20-Jan-14 20:44:47
Print Post

Re: Bright Box plain-text security leaks


[re: deleted] [link to this post]
 
Thanks to Zak and Ray for the comments/links!
Pages in this thread: 1 | 2 | [3] | 4 | (show all)   Print Thread

Jump to