BTC USD 83,596.9 Gold USD 4,154.41
Time now: Jun 1, 12:00 AM

UniFi ‘backdoor’ allows hacking, spying

BasicCX

Super Active Member
Messages
6,223
Joined
Sep 8, 2008
Messages
6,223
Reaction score
172
Points
73
UniFi ‘backdoor’ allows hacking, spying

KUALA LUMPUR, June 2 — Over 1,000 UniFi customers are exposed to a potential security risk of attacks from hackers and spying when using the high speed broadband service from Telekom Malaysia.

The security risk comes from a second administration account on routers that UniFi customers have to use.

The routers have the option for remote management enabled and customers were not informed and therefore unable to reset the password.

Security consultant Dinesh Nair, who has seen the second administration account, said that it appeared to be for maintenance purposes and allows Telekom Malaysia to troubleshoot UniFi problems remotely.

But he added that the password was “guessable” and with the remote management option turned on, it left the router vulnerable to unauthorised access and abuse such as forcing dropped connections and listening to the setting up of email passwords.

“It’s a security risk,” said Dinesh

“Telekom Malaysia should have been open about it from day one. The potential for damage is there.”

He said that the remote management option should have been turned off by default and turned on only when Telekom Malaysia needed remote access.

He added that it was particularly critical for business UniFi customers as competitors could try and gain unauthorised access to company IT systems via the remote management option.

“It’s a foot in the door,” he said.

When contacted, Telekom Malaysia said that they will discuss the issue with their technical team and issue a response.

One broadband industry executive said that the severity of the risk depended on the permissions that were granted to the remote access user.

“Can they reset the box? Or is it just to monitor usage?” said the executive.

“But the risk is greater for business users than home users as it could pose a security breach.”

UniFi user KC Lau said he was upset after reading about the issue on a techie forum and recalled how his technician told him not to change the passwords on even his WiFi router so that Telekom Malaysia technicians could have remote access.

“Why can’t we change the password on our own WiFi router?” he said.

As of May 7, there were about 1,700 UniFi customers.

Telekom’s UniFi service is part of its High Speed Broadband (HSBB) project was initiated in 2008 and is initially be available in fourareas around the Klang Valley: Shah Alam, Subang Jaya, Taman Tun Dr Ismail and Bangsar. It will be expanded to another 22 areas by June and a further 22 by December.

By 2012, TM expects to hit 1.2 million premises passed.

- The Malaysian Insider
 
By 2012, TM expects to hit 1.2 million premises passed.
lambat lagi la aku nak merasa HSBB ni.. pe cite ntah TM NUT ni.. die je nak monopoli semua pengguna.. pastu ble da ramai sngt mule la servis jd bengong.. nk fikir untung je..
 
TM da agree nk tukar remote access setting ...baru 1700 cust..hehe
 
Wah dalam seribu tu termasuk saya sorang.
 
malaysian insider? diorang ni anti government sket.. maybe nak jatuhkan business GLC government..
 
TM ni slalu je ak kol kl ader maslah..alhamdulillah..servis 4/5..
 
lambat lagi la aku nak merasa HSBB ni.. pe cite ntah TM NUT ni.. die je nak monopoli semua pengguna.. pastu ble da ramai sngt mule la servis jd bengong.. nk fikir untung je..

TM tak monopoli... kene paham skit...TM pelopor telekomunikasi malaysia..kalo monopoli takkan la TM no 4 company telekomunikasi kat m'sia ni:D
 
UniFi untuk tempat baru saja. Tempat yang dah ada copper cable diaorang tak pasang Fiber Optic. Biasanya untuk tempat orang ber"wang". PPRT ke Kampung ke, tak merasa la.
 
UniFi untuk tempat baru saja. Tempat yang dah ada copper cable diaorang tak pasang Fiber Optic. Biasanya untuk tempat orang ber"wang". PPRT ke Kampung ke, tak merasa la.

Telok Panglima Garang dah ada sevice Unifi nie:)cgrock
 
Back
Top
Log in Register