Home » 

UK ISP News Archives

 » 
Sponsored Links

GNUCitizen Breaks BT Home Hub 6.2.6.E Security

Posted: 28th May, 2008 By: MarkJ
The "ethical" hacking website, GNUCitizen, has found a new way around improvements to the security of BT’s 'Home Hub' broadband ADSL routers (firmware 6.2.6.E). It's understood that the operator had changed the default admin password from 'admin' to the serial number of the router itself, though this too may now be at risk:

As you can see, changing the default admin password to a value which is specific to each Home Hub would make password guessing/cracking attacks much harder. At least, this is usually the case. Well, it turns out that you can get the serial number of the Home Hub by simply sending a Multi Directory Access Protocol (MDAP) multicast request in the network where BT Home Hub is located.

Yes, you must already be part of the LAN where the Home Hub is present, either via Ethernet or via Wi-Fi. However, at GNUCITIZEN, we have demonstrated trivial ways to predict the WEP encryption key of the Home Hub if you know what you are doing. In summary, there are two ways to break into a BT Home Hub Wi-Fi network:

  • arp replays injection plus weak IVs cracking. This attack is typically launched using airodump-ng + aireplay-ng + aircrack-ng (I highly recommend using Backtrack 2 plus the Alfa USB AWUS036S Wi-Fi adaptor for this attack)

  • Predict the Home Hub’s default WEP key by bruteforcing a list of potential candidates which are derived from the SSID (the SSID can be obtained by anyone of course)

Paul Vlissidis, a technical director for I.T. consultancy NCC Group, has already criticised the security of BT's Home Hub in Mondays news (here).
Search ISP News
Search ISP Listings
Search ISP Reviews
Cheap BIG ISPs for 100Mbps+
Community Fibre UK ISP Logo
150Mbps
Gift: None
NOW UK ISP Logo
NOW £24.00
100Mbps
Gift: None
Virgin Media UK ISP Logo
Virgin Media £24.00
132Mbps
Gift: None
Vodafone UK ISP Logo
Vodafone £26.50 - 27.00
150Mbps
Gift: None
Plusnet UK ISP Logo
Plusnet £27.99
145Mbps
Gift: None
Large Availability | View All
Cheapest ISPs for 100Mbps+
Gigaclear UK ISP Logo
Gigaclear £19.00
300Mbps
Gift: None
BeFibre UK ISP Logo
BeFibre £19.00
150Mbps
Gift: None
Community Fibre UK ISP Logo
150Mbps
Gift: None
YouFibre UK ISP Logo
YouFibre £22.99
150Mbps
Gift: None
Hey! Broadband UK ISP Logo
150Mbps
Gift: None
Large Availability | View All
Sponsored Links
The Top 15 Category Tags
  1. FTTP (5849)
  2. BT (3605)
  3. Politics (2656)
  4. Business (2372)
  5. Openreach (2372)
  6. Building Digital UK (2302)
  7. Mobile Broadband (2088)
  8. FTTC (2070)
  9. Statistics (1856)
  10. 4G (1763)
  11. Virgin Media (1710)
  12. Ofcom Regulation (1537)
  13. Fibre Optic (1444)
  14. Wireless Internet (1436)
  15. FTTH (1383)
Sponsored

Copyright © 1999 to Present - ISPreview.co.uk - All Rights Reserved - Terms  ,  Privacy and Cookie Policy  ,  Links  ,  Website Rules