All the latest UK technology news, reviews and analysis

Alcatel gets security warning

by James Middleton

07 Aug 2001

Be the first to comment

  • Tweet this

Security watchers are warning of a remote-access vulnerability in Alcatel ADSL modems which may allow an intruder to modify the software running the devices.

A message bouncing around the BugTraq security mailing list reports that there is an attack in progress, by unknown parties, against all Alcatel ADSL modems in use.

Alcatel modems are the European favourite for ADSL service providers, including UK companies such as BT Openworld.

Security watchers are speculating that someone may have upgraded the firmware of all Alcatel modems in use in Italy, meaning that other European countries could be next on the list if they haven't been hit already.

List messages report portscans against port 21, the port used to upgrade modem firmware, on all IP addresses in use by a number of Italian ISPs.

It would appear the attacker is scanning the ISPs' customers to check for Alcatel ADSL modems, and then modifying them.

Although no-one seems sure what the bogus firmware does, it is thought to contain some kind of backdoor which would give a remote attacker "Expert" access to the modem.

Other suspicious symptoms include the activation of the "ftp get" command for any level of user, and the appearance of some debugging facilities.

Andrea Costantino, a security bug hunter, recommends downgrading to your previous modem software and disabling everything apart from telnet/ftp access.

Constantino also took a swipe at Alcatel "for providing backdoored software and avoiding public distribution of patches."

As a result of this incident, Constantino said Alcatel should be more "open" to the coder and hacker community about security problems.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

98%

0%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Software Design Architect (Windows Database Application)

Software Design Architect (Windows Database Application...

Lead Java Developer - Mobile- Digital- Amsterdam

Lead Java Developer - Fast growing, young and international...

Graduate Software Support Engineer

Job Specification Graduate Support Engineer...

c# or asp.net Software Developer

Job Specification For: Software Developer...

To send to more than one email address, simply separate each address with a comma.