[71081] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Trusting COTS - What's really in the box?

daemon@ATHENA.MIT.EDU (Sean Donelan)
Tue Jun 8 01:33:50 2004

Date: Tue, 8 Jun 2004 01:32:50 -0400 (EDT)
From: Sean Donelan <sean@donelan.com>
To: nanog@merit.edu
In-Reply-To: <40C53365.3080508@outblaze.com>
Errors-To: owner-nanog-outgoing@merit.edu


On Tue, 8 Jun 2004, Suresh Ramasubramanian wrote:
> Several third party firmwares for the linksys wrt54g wireless AP +
> "router" (which, of course, is owned by brand C) implement sshd using
> dropbear. For example, the ones at sveasoft, and at h.vu.wifi-box.net

How do you know what you get in the box is the same as what was
shipped from the factory?  Or was it just re-sealed and put back
on the shelf with an altered configuration?

http://www.securityfocus.com/archive/1/364977

If you buy your network equipment off Ebay, what are you really
getting?  Does it come with hitchhiking firmware pre-installed?
The power of the Internet means the bad guys don't need to care
who buys the tampered equipment, because it can "call home" and
tell the bad guy where it ended up.


home help back first fref pref prev next nref lref last post