07 Aug 2001
Security watchers are warning of a remote-access vulnerability in Alcatel ADSL modems which may allow an intruder to modify the software running the devices.
A message bouncing around the BugTraq security mailing list reports that there is an attack in progress, by unknown parties, against all Alcatel ADSL modems in use.
Alcatel modems are the European favourite for ADSL service providers, including UK companies such as BT Openworld.
Security watchers are speculating that someone may have upgraded the firmware of all Alcatel modems in use in Italy, meaning that other European countries could be next on the list if they haven't been hit already.
List messages report portscans against port 21, the port used to upgrade modem firmware, on all IP addresses in use by a number of Italian ISPs.
It would appear the attacker is scanning the ISPs' customers to check for Alcatel ADSL modems, and then modifying them.
Although no-one seems sure what the bogus firmware does, it is thought to contain some kind of backdoor which would give a remote attacker "Expert" access to the modem.
Other suspicious symptoms include the activation of the "ftp get" command for any level of user, and the appearance of some debugging facilities.
Andrea Costantino, a security bug hunter, recommends downgrading to your previous modem software and disabling everything apart from telnet/ftp access.
Constantino also took a swipe at Alcatel "for providing backdoored software and avoiding public distribution of patches."
As a result of this incident, Constantino said Alcatel should be more "open" to the coder and hacker community about security problems.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Sneak peek at the forthcoming glass-based machine
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Software Design Architect (Windows Database Application...
Lead Java Developer - Fast growing, young and international...
Job Specification Graduate Support Engineer...
Job Specification For: Software Developer...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?