LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-17-2015, 05:04 AM   #1
Ulysses_
Senior Member
 
Registered: Jul 2009
Posts: 1,303

Rep: Reputation: 57
Not trusting adsl router, what are more secure alternatives?


Some adsl routers have additional login passwords that do not appear in the configuration, some penetration testers have found. And they are the same for all customers! For example this adsl router:

http://wwwen.zte.com.cn/en/products/...22_424137.html

Rather than switch to another model and hope there is no hidden security breaches in it, what else can one do?

Go back to the 56 kbits/s telephone line modems of 20 years ago?

Anything better?
 
Old 05-17-2015, 08:49 AM   #2
TobiSGD
Moderator
 
Registered: Dec 2009
Location: Germany
Distribution: Whatever fits the task best
Posts: 17,148
Blog Entries: 2

Rep: Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886Reputation: 4886
If you have a router that is compatible with OpenWRT you could use that instead of the firmware provided by the manufacturer.
 
1 members found this post helpful.
Old 05-17-2015, 10:24 AM   #3
Pearlseattle
Member
 
Registered: Aug 2007
Location: Zurich, Switzerland
Distribution: Gentoo
Posts: 999

Rep: Reputation: 142Reputation: 142
If you scan with nmon all your ports nothing should be open => done.
(EDIT: "scanning" meaning from the outside - e.g. from another server/VM that connects from the Internet to your router)
 
Old 05-17-2015, 11:04 AM   #4
Ulysses_
Senior Member
 
Registered: Jul 2009
Posts: 1,303

Original Poster
Rep: Reputation: 57
Maybe ports are always closed except after a special sequence is sent from the outside.
 
Old 05-17-2015, 11:14 AM   #5
Pearlseattle
Member
 
Registered: Aug 2007
Location: Zurich, Switzerland
Distribution: Gentoo
Posts: 999

Rep: Reputation: 142Reputation: 142
You're right, but that would be a really really really nasty thing.
Such a thing can exist only to have a specific purpose and the company that produces the device would most most probably be directly liable for any damage that such a backdoor generates, doesn't matter for which reason it exists.
Anyway, the only way to test against such possibilities is to test all possibilities - any HW could contiain such a backdoor.
 
Old 05-17-2015, 03:19 PM   #6
Ulysses_
Senior Member
 
Registered: Jul 2009
Posts: 1,303

Original Poster
Rep: Reputation: 57
What about a hardware device that connects to adsl but has no firmware, just a chip with adsl pins and nothing else, and everything is done in software, does this exist?

Last edited by Ulysses_; 05-17-2015 at 03:21 PM.
 
Old 05-19-2015, 04:37 AM   #7
dt64
Member
 
Registered: Sep 2012
Distribution: RHEL5/6, CentOS5/6
Posts: 218

Rep: Reputation: 38
Quote:
Originally Posted by Ulysses_ View Post
What about a hardware device that connects to adsl but has no firmware, just a chip with adsl pins and nothing else, and everything is done in software, does this exist?
That's basically how all the equipment works: just a (or a few) chips and the all the other stuff done in software. Firmware is software. So what was the question?
 
Old 05-19-2015, 04:44 AM   #8
Ulysses_
Senior Member
 
Registered: Jul 2009
Posts: 1,303

Original Poster
Rep: Reputation: 57
Firmware is closed-source, other software can be open-source.
 
Old 05-19-2015, 04:57 AM   #9
dt64
Member
 
Registered: Sep 2012
Distribution: RHEL5/6, CentOS5/6
Posts: 218

Rep: Reputation: 38
http://en.wikipedia.org/wiki/Firmware

according to the definition OpenWRT would be firmware and it's open source.
 
Old 05-19-2015, 05:10 AM   #10
Ulysses_
Senior Member
 
Registered: Jul 2009
Posts: 1,303

Original Poster
Rep: Reputation: 57
That's for high level features, it is not to the bare bones as a driver for an AD converter and a DA converter would be for example.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Not trusting adsl router - what can be done about it Ulysses_ Linux - Networking 2 05-17-2015 05:34 AM
LXer: Trusting Trust and Trusting Red Hat et al. LXer Syndicated Linux News 0 11-24-2013 06:14 AM
Secure alternatives to Yahoo! and Gmail nobuntu General 21 12-16-2012 05:37 PM
ADSL Routers Setup- Microsom Deskporte router 100 and Planet ADSL modem router mabonline Linux - Hardware 1 02-27-2004 05:36 PM
Configuring ADSL coonection using ADSL router... manu2004 Slackware 3 01-04-2004 04:42 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:41 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration