[30316] in bugtraq
conexant adsl router backdoor
daemon@ATHENA.MIT.EDU (Luca Bartolomai)
Sun Jun 1 15:52:47 2003
Date: 30 May 2003 08:32:29 -0000
Message-ID: <20030530083229.31409.qmail@www.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: Luca Bartolomai <mefistofle@libero.it>
To: bugtraq@securityfocus.com
Hi ,
I have acquired one router adsl conexant model Trident .
This modem is identical to the Italian version Digicom Michelangelo Office,
but the firmware is modding .
If get file CONFIG.REG from ftp modem server and edit it , you can see this
DWORD :
[Class\Protocol\Bridge\0000]
"DeviceId"=dword:00000000
"BackDoorEnabled"=dword:00000001
"EthernetFilterEnabled"=dword:00000000
"OutputProcessingEnabled"=dword:00000000
"SubnetMuxEnabled"=dword:00000001
BackDoorEnabled ? what is ?
I'am scaned with nmap but not found particular listen port .
it is a backdoor on ATM ?
I will continue to inquire
Best regards
Jack