Alcatel gets security warning

Europe's favourite ADSL modems are under attack from unknowns.

Written by James Middleton

Security watchers are warning of a remote-access vulnerability in Alcatel ADSL modems which may allow an intruder to modify the software running the devices.

A message bouncing around the BugTraq security mailing list reports that there is an attack in progress, by unknown parties, against all Alcatel ADSL modems in use.

Advertisement

Alcatel modems are the European favourite for ADSL service providers, including UK companies such as BT Openworld.

Security watchers are speculating that someone may have upgraded the firmware of all Alcatel modems in use in Italy, meaning that other European countries could be next on the list if they haven't been hit already.

List messages report portscans against port 21, the port used to upgrade modem firmware, on all IP addresses in use by a number of Italian ISPs.

It would appear the attacker is scanning the ISPs' customers to check for Alcatel ADSL modems, and then modifying them.

Although no-one seems sure what the bogus firmware does, it is thought to contain some kind of backdoor which would give a remote attacker "Expert" access to the modem.

Other suspicious symptoms include the activation of the "ftp get" command for any level of user, and the appearance of some debugging facilities.

Andrea Costantino, a security bug hunter, recommends downgrading to your previous modem software and disabling everything apart from telnet/ftp access.

Constantino also took a swipe at Alcatel "for providing backdoored software and avoiding public distribution of patches."

As a result of this incident, Constantino said Alcatel should be more "open" to the coder and hacker community about security problems.

Tags:

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols and Iain Thomson

03 Oct 2008

6.49 MBPodcast Special: Views from the Valley More...

Podcast image

02 Oct 2008

14.35 MBComputing podcast - Next-generation broadband Britain; and we report from Gartner's IT security summit More...

Shaun Nichols and Iain Thomson

26 Sep 2008

3.43 MBPodcast Special: Views from the Valley More...

Poll

Google Android

Google Android

Are you intending to try out a Google Android mobile phone?

Previous poll results

Spotlight

ISSE 2008

Sharing information key to cracking e-crime

Reluctance to report breaches only adding to the problem   More...

AMD logo

AMD expected to split into two

Separate entities to focus on chip design and manufacturing   More...

CA logo

CA pushes into virtualisation management space

Data Center Automation Manager looks after virtual and physical resources   More...

Hacking

Europeans charged in US hack attacks

British man facing 15 years in prison   More...

Primary Navigation