Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Superhub Telnet


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Virgin Media Services > Virgin Media Internet Service

Superhub Telnet
Reply
 
Thread Tools
Old 29-12-2011, 21:20   #1
ccarmock
cf.addict
 
Join Date: Jun 2008
Posts: 333
ccarmock is a glorious beacon of lightccarmock is a glorious beacon of lightccarmock is a glorious beacon of lightccarmock is a glorious beacon of lightccarmock is a glorious beacon of lightccarmock is a glorious beacon of lightccarmock is a glorious beacon of light
Superhub Telnet

Just spotted an interesting entry in the event log on my Superhub:-

Thu Dec 29 11:43:00 2011 Critical (3) Telnet login failed from 210.61.240.52.


I find that indeed the superhub is running a telnet server, which appears to be accessible via the WAN IP address. the normal admin login doesn't work though. Hopefully there isn't a standard login as this woudl seem to be a security risk.
ccarmock is offline   Reply With Quote
Advertisement
Old 29-12-2011, 21:54   #2
Peter_
Catjack
 
Peter_'s Avatar
 
Join Date: Jan 2009
Location: Liverpool
Services: Samsung V+ XL TV XL Phone 30Mb Superhub Nokia N8
Posts: 19,861
Peter_ is seeing silvered starsPeter_ is seeing silvered starsPeter_ is seeing silvered starsPeter_ is seeing silvered starsPeter_ is seeing silvered stars
Peter_ is seeing silvered starsPeter_ is seeing silvered starsPeter_ is seeing silvered starsPeter_ is seeing silvered starsPeter_ is seeing silvered starsPeter_ is seeing silvered stars
Re: Superhub Telnet

The ip resolves to

CHUNGHWA-TELECOM-TP-TW
__________________
"Religion was invented when the first con man met the first fool." - Mark Twain (1835 - 1910) now that has a ring of truth to it.
Peter_ is online now   Reply With Quote
Old 30-12-2011, 00:30   #3
ccarmock
cf.addict
 
Join Date: Jun 2008
Posts: 333
ccarmock is a glorious beacon of lightccarmock is a glorious beacon of lightccarmock is a glorious beacon of lightccarmock is a glorious beacon of lightccarmock is a glorious beacon of lightccarmock is a glorious beacon of lightccarmock is a glorious beacon of light
Re: Superhub Telnet

Yup I suspect a portscan found it. Is there a way to disable telnet from the WAN port?
ccarmock is offline   Reply With Quote
Old 30-12-2011, 03:36   #4
Chrysalis
VMNG300 FTW!!!!
 
Join Date: Sep 2003
Location: Leics
Age: 33
Services: M TV 30mbit BB (new uplifted bottom tier) - VMNG300 Basic Phone
Posts: 10,364
Chrysalis has a bronze arrayChrysalis has a bronze arrayChrysalis has a bronze array
Chrysalis has a bronze arrayChrysalis has a bronze arrayChrysalis has a bronze arrayChrysalis has a bronze arrayChrysalis has a bronze arrayChrysalis has a bronze arrayChrysalis has a bronze arrayChrysalis has a bronze array
Re: Superhub Telnet

it should already be off so looks like a bug, VM went to great effort to lockout ssh/telnet access.
__________________
TBB Graph Live
FTTC due sept 2012
Chrysalis is offline   Reply With Quote
Old 30-12-2011, 09:17   #5
kwikbreaks
Grumpy old man
 
kwikbreaks's Avatar
 
Join Date: May 2010
Services: 10Mbps VMNG300, Buffalo WHR-G54S Tomato FW, Vodafone mobile BB, FoxSat HDR for TV, Vonage VOIP
Posts: 1,313
kwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful one
Re: Superhub Telnet

From what I remember of it you could access it from the standard port 23 on the LAN side - I don't recall ever trying or seeing it mentioned that WAN access was possible at all. IMO any WAN access using any protocol is a potential security breach - didn't O2 suffer some stick for an open port on their Thomson router?
__________________
Dear God in Heaven please send some clothes for the poor ladies in daddies computer.
Adios Virgin Media - To Infinity and Beyond
kwikbreaks is offline   Reply With Quote
Old 30-12-2011, 09:29   #6
ccarmock
cf.addict
 
Join Date: Jun 2008
Posts: 333
ccarmock is a glorious beacon of lightccarmock is a glorious beacon of lightccarmock is a glorious beacon of lightccarmock is a glorious beacon of lightccarmock is a glorious beacon of lightccarmock is a glorious beacon of lightccarmock is a glorious beacon of light
Re: Superhub Telnet

It is definitely accessible from both the LAN and WAN side of the Superhub. This is running the business service firmware though. Version 5.5.2R04-BU

I am not sure if this is based on te R04 build of the residential firmware or is a totally new build stream. It does not have modem mode, but does have oter features like L2TP tunnel config options under Basic Settings. SSH is disabled which implies it is more aligned to a later version, however does respond to a port 23 connection with:-

Netgear Embedded Telnet Server (c) 2000-2007

WARNING: Access allowed by authorized users only.

Login:
ccarmock is offline   Reply With Quote
Old 30-12-2011, 09:37   #7
kwikbreaks
Grumpy old man
 
kwikbreaks's Avatar
 
Join Date: May 2010
Services: 10Mbps VMNG300, Buffalo WHR-G54S Tomato FW, Vodafone mobile BB, FoxSat HDR for TV, Vonage VOIP
Posts: 1,313
kwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful one
Re: Superhub Telnet

If it uses the standard port then simply running Gibson's "Shields up" will expose it. I've even got a smartphone app that scans ports on the LAN but don't have a Superhub to check what the current firmware does.
__________________
Dear God in Heaven please send some clothes for the poor ladies in daddies computer.
Adios Virgin Media - To Infinity and Beyond
kwikbreaks is offline   Reply With Quote
Old 30-12-2011, 09:42   #8
ccarmock
cf.addict
 
Join Date: Jun 2008
Posts: 333
ccarmock is a glorious beacon of lightccarmock is a glorious beacon of lightccarmock is a glorious beacon of lightccarmock is a glorious beacon of lightccarmock is a glorious beacon of lightccarmock is a glorious beacon of lightccarmock is a glorious beacon of light
Re: Superhub Telnet

Well it exposes itself with that login banner....
ccarmock is offline   Reply With Quote
Old 30-12-2011, 09:55   #9
Kymmy
Cable Forum Team
 
Kymmy's Avatar
 
Join Date: Dec 2007
Age: 43
Posts: 16,274
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: Superhub Telnet

If you wish to PM the IP address of the hub I'll check to see if the port is open
Kymmy is offline   Reply With Quote
Old 30-12-2011, 10:28   #10
Milambar
cf.geek
 
Join Date: Jan 2008
Posts: 742
Milambar has much to be proud ofMilambar has much to be proud ofMilambar has much to be proud ofMilambar has much to be proud ofMilambar has much to be proud ofMilambar has much to be proud ofMilambar has much to be proud ofMilambar has much to be proud ofMilambar has much to be proud ofMilambar has much to be proud of
Re: Superhub Telnet

Technically, I've broken VM's ToS with this, which specifically prohibits portscanning, but..

Code:
username@fileserver:~$ sudo nmap -sS -P0 -p -1024 <myownip>

Starting Nmap 5.00 ( http://nmap.org ) at 2011-12-30 10:26 GMT
Interesting ports on <myhost> (<myip>):
Not shown: 1023 filtered ports
PORT   STATE SERVICE
22/tcp open  ssh

Nmap done: 1 IP address (1 host up) scanned in 6.71 seconds
No telnet port open here, and Im on a superhub, firmware V5.5.2R30.

Yes, I know port 22 is open, I specifically opened it.
__________________
Algebra is great.

For a food-dish, of radius Z, and thickness A, you can say it is PI*Z*Z*A
Milambar is offline   Reply With Quote
Old 30-12-2011, 10:29   #11
Kymmy
Cable Forum Team
 
Kymmy's Avatar
 
Join Date: Dec 2007
Age: 43
Posts: 16,274
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: Superhub Telnet

Quote:
Originally Posted by Milambar View Post
No telnet port open here, and Im on a superhub, firmware V5.5.2R30.

Yes, I know port 22 is open, I specifically opened it.
He's on a business hub not a residential hub so different firmware
Kymmy is offline   Reply With Quote
Old 30-12-2011, 10:30   #12
Milambar
cf.geek
 
Join Date: Jan 2008
Posts: 742
Milambar has much to be proud ofMilambar has much to be proud ofMilambar has much to be proud ofMilambar has much to be proud ofMilambar has much to be proud ofMilambar has much to be proud ofMilambar has much to be proud ofMilambar has much to be proud ofMilambar has much to be proud ofMilambar has much to be proud of
Re: Superhub Telnet

Ah, okay, I missed that bit.
__________________
Algebra is great.

For a food-dish, of radius Z, and thickness A, you can say it is PI*Z*Z*A
Milambar is offline   Reply With Quote
Old 30-12-2011, 11:59   #13
Kymmy
Cable Forum Team
 
Kymmy's Avatar
 
Join Date: Dec 2007
Age: 43
Posts: 16,274
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: Superhub Telnet

On the two IP's sent to me I get no response on SSH or Telnet
Kymmy is offline   Reply With Quote
Old 30-12-2011, 12:43   #14
kwikbreaks
Grumpy old man
 
kwikbreaks's Avatar
 
Join Date: May 2010
Services: 10Mbps VMNG300, Buffalo WHR-G54S Tomato FW, Vodafone mobile BB, FoxSat HDR for TV, Vonage VOIP
Posts: 1,313
kwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful onekwikbreaks is the helpful one
Re: Superhub Telnet

Quote:
Originally Posted by ccarmock View Post
Well it exposes itself with that login banner....
That was the business hub - I was interested to know if they'd made yet another error with the standard hub which is in half a million homes...
__________________
Dear God in Heaven please send some clothes for the poor ladies in daddies computer.
Adios Virgin Media - To Infinity and Beyond
kwikbreaks is offline   Reply With Quote
Old 30-12-2011, 13:39   #15
ccarmock
cf.addict
 
Join Date: Jun 2008
Posts: 333
ccarmock is a glorious beacon of lightccarmock is a glorious beacon of lightccarmock is a glorious beacon of lightccarmock is a glorious beacon of lightccarmock is a glorious beacon of lightccarmock is a glorious beacon of lightccarmock is a glorious beacon of light
Re: Superhub Telnet

Thanks for testing Kymmy. I do get a login from the first of the two IP addresses I sent out and also the internal one.

I wonder if some filtering is going on somewhere as the event log has now two rejected Telnet logins from different external IP addresses.
ccarmock is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Google Search




All times are GMT +1. The time now is 21:02.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
Copyright © 2003 - 2012, Cable Forum.
(server1.cableforum.co.uk)

SEO by vBSEO 3.3.2