Full Disclosure mailing list archives

Re: EE BrightBox router hacked - bares all if you ask nicely


From: Jeffrey Walton <noloader () gmail com>
Date: Thu, 16 Jan 2014 13:26:24 -0500

On Wed, Jan 15, 2014 at 3:28 PM, Scott Helme <scotthelme () hotmail com> wrote:
The BrightBox router is the standard equipment issued by UK ISP Everything
Everywhere (EE) to its subscribers.

The device not only leaks sensitive data but is remotely exploitable too. An
attacker even has the ability to take control of your account as the router
leaks your ISP account credentials.

You can read the full article here:
https://scotthelme.co.uk/ee-brightbox-router-hacked/
To add insult to injury, they are probably using a hard code public
key pair, and its probably in the littleblackbox
(http://code.google.com/p/littleblackbox/).

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: