So this issue affects Telia Lithuania clients. But I wouldn't be surprised if the same (or similar) issue affects clients in Sweden. The article mentions a leaked password hash from 2014, but as far as I know, there were at least 3 password (not hash!) leaks over the last 10 years. Generally, I recommend people buy their own routers and never use the "Self Service" for managing passwords. As for hostility of service…
That's very irresponsible of you. You just said that someone could read someone elses medical data and there you are sitting on similar vulnerabilities out of principle. Shame. I know first hand that such big telcos are slow and bureaucratic. But they still need help and patience. They do after all have all the important government contracts.
RCE on Telia Routers
41–50 of 51 posts
Re: RCE on Telia Routers
#42Misleading title, these are cpe NAT boxes.
Re: RCE on Telia Routers
#43Misleading title, these are cpe NAT boxes.
Agree - came here concerned Telia backbone routers had an issue...
Edit: Also: Why is all of the technical discussion on this topic at the bottom of the page?
Re: RCE on Telia Routers
#44Earlier quoted context omitted.
I couldn't find it on the web site, but I found something similar here: https://apps.apple.com/se/app/telia-smart-wifi/id1459248896 https://play.google.com/store/apps/details?id=com.teliacompa... They allow login with BankID (Swedish authentication system using Personal Identity Number) or a Telia login, implying I don't need the admin password printed on the back of the router so it ought to use the same type of bac…
Well, it is risky hiring workers in Sweden.. if you don’t need them anymore it’s difficult to get rid of them!
Re: RCE on Telia Routers
#45Earlier quoted context omitted.
Oh, and they sold data about torrent users. That's right. A Swedish ISP selling personally identifiable information. Not giving it out because of a court order. I have steered many people away from them over the years. They would have to have at least a decade of good behaviour and a sun shining out of their ass before I would pick them.
> Oh, and they sold data about torrent users. That's right. A Swedish ISP selling personally identifiable information. Not giving it out because of a court order. Very interesting, can you please say more or point to somewhere? I couldn't parse if the last sentence was about you or Telia.
Re: RCE on Telia Routers
#46So this issue affects Telia Lithuania clients. But I wouldn't be surprised if the same (or similar) issue affects clients in Sweden. The article mentions a leaked password hash from 2014, but as far as I know, there were at least 3 password (not hash!) leaks over the last 10 years. Generally, I recommend people buy their own routers and never use the "Self Service" for managing passwords. As for hostility of service…
I did it once, I've found probably 10 other issues with customers, partners and our own products that I won't be reporting since I have to go through that process every time with my employer.
There is no benefit to me for reporting it aside from an automated thank you message when they close a ticket.
I'd submit/advise anonymously but I usually discover this stuff in a way they can trace it back to me.
So instead, my data as well as my customers, colleagues and good peoples data remains accessible to the internet.
I'm sorry for that.
Re: RCE on Telia Routers
#47Earlier quoted context omitted.
Agree - came here concerned Telia backbone routers had an issue...
I came here six hours ago thinking my mom's Telia-connected Macbook Air was at risk. Turns out none of that is true. More active moderation, please. Edit: Also: Why is all of the technical discussion on this topic at the bottom of the page?
Re: RCE on Telia Routers
#48Re: RCE on Telia Routers
#49Earlier quoted context omitted.
Well, it is risky hiring workers in Sweden.. if you don’t need them anymore it’s difficult to get rid of them!
This is just plain wrong. There are many ways to handle such a situation. One would be "visstidsanställning" which is employment for a pre-determined period.
Re: RCE on Telia Routers
#50Earlier quoted context omitted.
Right, and there's no possibility to do research/testing anonymously anyway. You use your personal e-Signature/ID card to logon to government sites, your logon is always tied to you.
It's possible that the programmers who built the system are really bad at security and really good at audit logging but I doubt it. Personally I would take the risk but I understand why others might not want to.
Many different hops will log things like HTTP paths, which include GET information - or DB audit logging which can easily be traced with message ID's or timestamp comparisons. It's surprising how easy it is to trace issues, debug logging is often left on in Production systems..
I wouldn't take that risk.