BTAgent – CPE backdoor
cryptome.org
BTAgent – CPE backdoor
1–10 of 19 posts
Re: BTAgent – CPE backdoor
#2Re: BTAgent – CPE backdoor
#3The BTAgent is there to manage the devices - e.g. Updating them. Its possible that some stats are there to improve line quality as well. To me that seems a reasonable tradeoff, and if I wasn't happy with it then it is always possible to use your own piece of CPE.
The other point is that the interface that BTAgent runs on isn't exposed to the internet, it is only available from the management network so someone obtaining the keys for BTAgent would also have to compromise the management network - at which point bt has bigger problems!
Re: BTAgent – CPE backdoor
#4See also http://www.ispreview.co.uk/index.php/2013/12/confusion-alleg...
In a nutshell, some ISPs will effectively hijack publicly routable ranges for internal use if they know that there's no way those addresses will ever be used for real public services. In this case, a UK ISP is re-using the US DoD's 30.0.0.0/8 network. Anecdotally I've heard the inverse is also true (US ISPs use UK MoD ranges).
Re: BTAgent – CPE backdoor
#5Here have our free router so that we can access your network whenever we want.
Re: BTAgent – CPE backdoor
#6Re: BTAgent – CPE backdoor
#7While the pdf from cryptome was initially published almost a year ago the person who reverse engineered the firmware has been visited by the police and then sent a response to cryptome in response to the pdf to clear up some misconceptions.
Re: BTAgent – CPE backdoor
#8While the pdf from cryptome was initially published almost a year ago the person who reverse engineered the firmware has been visited by the police and then sent a response to cryptome in response to the pdf to clear up some misconceptions.
Re: BTAgent – CPE backdoor
#9I was initially interested when I first saw this last year, but it turns out to be complete FUD. See http://www.revk.uk/2013/12/paraniod-ravings.html for the take on the original disclosures from the MD of one of the UK's most technical ISPs (and believe me, he's no fan of BT's). See also http://www.ispreview.co.uk/index.php/2013/12/confusion-alleg... In a nutshell, some ISPs will effectively hijack publicly routable…
Re: BTAgent – CPE backdoor
#10While the pdf from cryptome was initially published almost a year ago the person who reverse engineered the firmware has been visited by the police and then sent a response to cryptome in response to the pdf to clear up some misconceptions.
Is it a crime to reverse engineer routers provided by an ISP? (Honest question, I know things like MAC spoofing are illegal, which can be used in the UK to get free cable TV / Internet).