Welcome Guest ( Log In | Register )

Bump Topic Topic Closed RSS Feed
19 Pages « < 6 7 8 9 10 > » Bottom

Outline · [ Standard ] · Linear+

Unifi WARNING TO ALL UNIFI USERS, Threat warning, read inside

views
     
almaty
post Jun 2 2010, 06:36 PM

Enthusiast
*****
Senior Member
944 posts

Joined: Jan 2003
From: does not exist
bcoz we like the yellow fellow not the copycat blue bear
Neptern
post Jun 2 2010, 06:38 PM

On my way
****
Junior Member
518 posts

Joined: Aug 2005
I'm curious what kind of lame ass response will tmnut give smile.gif
TSrizvanrp
post Jun 2 2010, 06:43 PM

Getting Started
Group Icon
Elite
195 posts

Joined: Sep 2006



QUOTE(Neptern @ Jun 2 2010, 06:38 PM)
I'm curious what kind of lame ass response will tmnut give smile.gif
*
TMnet cable fault.. in your router. icon_idea.gif
gnx
post Jun 2 2010, 06:50 PM

New Member
*
Junior Member
43 posts

Joined: Jun 2006
TheStar has the news as well.

http://techcentral.my/news/story.aspx?file...235&sec=IT_News
ayamkambing
post Jun 2 2010, 07:00 PM

Getting Started
**
Junior Member
66 posts

Joined: Aug 2009
From: Kenpachi Fried Chicken!


QUOTE(gnx @ Jun 2 2010, 06:50 PM)
Will TMNet sue "rizvanrp" for exposing them? maybe say he is defaming TMNet? blink.gif
almaty
post Jun 2 2010, 07:07 PM

Enthusiast
*****
Senior Member
944 posts

Joined: Jan 2003
From: does not exist
he is stating a fact/truth. he has nothing to worry about. tm should thank him.

klseet
post Jun 2 2010, 07:27 PM

Getting Started
**
Junior Member
130 posts

Joined: Mar 2008
I was reading:
http://www.themalaysianinsider.com/malaysi...hacking-spying/
and the link leads me to here....

How ignorant yet stupid enough to turn-on remote access with guessable or findable password.... this is terrible .... what the hell TM is doing ?? shocking.gif

I must thank "rizvanrp" for discovering the facts rclxms.gif
at least now the public know TM is trying to do some funny things at out back-door without our knowledge. mad.gif
ayamkambing
post Jun 2 2010, 07:31 PM

Getting Started
**
Junior Member
66 posts

Joined: Aug 2009
From: Kenpachi Fried Chicken!


QUOTE(almaty @ Jun 2 2010, 07:07 PM)
he is stating a fact/truth. he has nothing to worry about. tm should thank him.
*
Butthurt companies dont like the truth where it hurts them at their pockets and reputation. A lawsuit may happen.
almaty
post Jun 2 2010, 07:46 PM

Enthusiast
*****
Senior Member
944 posts

Joined: Jan 2003
From: does not exist
Unifi ‘backdoor’ allows hacking, spying

http://blog.limkitsiang.com/2010/06/02/uni...hacking-spying/

read the first comment in the blog. carboncopy is wondering whether unifi users can file class action suit against tm LOL.

on the other hand i wonder what other manufacturers like linksys, aztech for eg think about unifi and the dir-615 exclusivity.



This post has been edited by almaty: Jun 2 2010, 07:59 PM
SUSsoundsyst64
post Jun 2 2010, 07:50 PM

I'm No-Longer-Noobs
*******
Senior Member
3,725 posts

Joined: Jul 2005
From: In /hardware/

QUOTE(ayamkambing @ Jun 2 2010, 07:00 PM)
Will TMNet sue "rizvanrp" for exposing them? maybe say he is defaming TMNet?  blink.gif
*
how to sue. Do they know rizvanrp in the first place? And to they know that they violate their own T&C ? biggrin.gif
skincladalien
post Jun 2 2010, 07:50 PM

Densha Otaku
******
Senior Member
1,914 posts

Joined: Jan 2003
From: New Selangor ^.^Y


i guess the challenger has blown up now. Wonder how the TM team gonna solve this
nitewish
post Jun 2 2010, 07:51 PM

Viva La Resistance
*****
Senior Member
810 posts

Joined: Feb 2008
From: 127.0.0.1



lol from TM's tweet
http://bit.ly/a4h2qs
SUSsoundsyst64
post Jun 2 2010, 07:53 PM

I'm No-Longer-Noobs
*******
Senior Member
3,725 posts

Joined: Jul 2005
From: In /hardware/

News Release

2 June 2010


STATEMENT


Telekom Malaysia Berhad ™ wishes to clarify the concerns raised by various parties with regards to the remote accessibility of UniFi routers which are part of the customer premises equipment (CPE) for all UniFi subscribers.

TM would like to assure all concerned parties that the only reason the UniFi router setting for remote access is enabled is for remote access troubleshooting purposes for the express use of our technical support personnel. In the event there is a technical support issue with any of our UniFi subscribers; at the first level of troubleshooting, TM’s network operation centre (NOC) can immediately remotely diagnose the problem before sending a support team on-site.

TM takes note of the security concerns that have been raised, and we have taken these issues to heart.

TM also acknowledges that there is a need to balance the public’s level of comfort with regards to security and privacy and TM’s own commitment to faster support turnaround time. As such, TM would like to maintain the higher level of service enabled by remote access management on customer routers, and in recognition of that TM will immediately change every UniFi customers’ router management password into a high security, unique one (which will be only known to the customer and TM). TM will notify all our Unifi customers of this change accordingly.
ayamkambing
post Jun 2 2010, 07:54 PM

Getting Started
**
Junior Member
66 posts

Joined: Aug 2009
From: Kenpachi Fried Chicken!


QUOTE(soundsyst64 @ Jun 2 2010, 07:50 PM)
how to sue. Do they know rizvanrp in the first place? And to they know that they violate their own T&C ? biggrin.gif
*
Suing a forummer is an easy task. All u need is police report and/or lawyers letter to demand such, and can hold this forum board accountable.

So if want to say something bad about TMnet, careful la. Now all blogs and news site points to this thread...so careful abit. tongue.gif


Added on June 2, 2010, 7:56 pm
QUOTE(soundsyst64 @ Jun 2 2010, 07:53 PM)
News Release

2  June 2010


STATEMENT


Telekom Malaysia Berhad ™ wishes to clarify the concerns raised by various parties with regards to the remote accessibility of UniFi routers which are part of the customer premises equipment (CPE) for all UniFi subscribers.

TM would like to assure all concerned parties that the only reason the UniFi router setting for remote access is enabled is for remote access troubleshooting purposes for the express use of our technical support personnel. In the event there is a technical support issue with any of our UniFi subscribers; at the first level of troubleshooting, TM’s network operation centre (NOC) can immediately remotely diagnose the problem before sending a support team on-site.

TM takes note of the security concerns that have been raised, and we have taken these issues to heart.

TM also acknowledges that there is a need to balance the public’s level of comfort with regards to security and privacy and TM’s own commitment to faster support turnaround time. As such, TM would like to maintain the higher level of service enabled by remote access management on customer routers, and in recognition of that TM will immediately change  every UniFi customers’ router management password into a high security, unique one (which will be only known to the customer and TM). TM will notify all our Unifi customers of this change accordingly.
*
Not good enough

Remote access should only be granted on a need to bases by the client, and no TM staff should know nor be allowed such access unless explicitly granted.

They still want to maintain it. How can they assure that their TM staff dont exploit it?

This post has been edited by ayamkambing: Jun 2 2010, 07:56 PM
MX510
post Jun 2 2010, 08:05 PM

Love Me Sin Hate Me Sinner
*******
Senior Member
4,038 posts

Joined: Aug 2005
From: Earth



Actually they also did this on their corporate customer it just ur router username n password tongue.gif . Nobody can install anything into it tongue.gif . Even default username n password for Streamyx are also unsecured if u set the modem dial and store ur password in there tongue.gif
lok3i
post Jun 2 2010, 08:07 PM

cycling for a healthy life
****
Senior Member
559 posts

Joined: Mar 2009


rizvanrp really famous this time..
TM screw up..
TSrizvanrp
post Jun 2 2010, 08:10 PM

Getting Started
Group Icon
Elite
195 posts

Joined: Sep 2006



QUOTE(MX510 @ Jun 2 2010, 08:05 PM)
Actually they also did this on their corporate customer it just ur router username n password tongue.gif . Nobody can install anything into it tongue.gif . Even default username n password for Streamyx are also unsecured if u set the modem dial and store ur password in there tongue.gif
*
MX there's a difference between their Riger DSL modem which is pretty crappy and only has a web UI compared to a custom made DLINK DIR-615 with full SSH access.. full SSH access you can SSH tunnel.. you can view the conntrack table.. you can modify the iptables and DNS servers to redirect users to phishing sites..
almaty
post Jun 2 2010, 08:13 PM

Enthusiast
*****
Senior Member
944 posts

Joined: Jan 2003
From: does not exist
QUOTE(ayamkambing @ Jun 2 2010, 07:54 PM)
Remote access should only be granted on a need to bases by the client, and no TM staff should know nor be allowed such access unless explicitly granted.

They still want to maintain it. How can they assure that their TM staff dont exploit it?
*
exactly. totally agree with you on this.

example...employee plans to leave tm or finds out he is getting fired etc...he starts to collect user/pwd wink.gif




ayamkambing
post Jun 2 2010, 08:16 PM

Getting Started
**
Junior Member
66 posts

Joined: Aug 2009
From: Kenpachi Fried Chicken!


QUOTE(rizvanrp @ Jun 2 2010, 08:10 PM)
MX there's a difference between their Riger DSL modem which is pretty crappy and only has a web UI compared to a custom made DLINK DIR-615 with full SSH access.. full SSH access you can SSH tunnel.. you can view the conntrack table.. you can modify the iptables and DNS servers to redirect users to phishing sites..
*
Sir, this is very greek to me. icon_question.gif
TSrizvanrp
post Jun 2 2010, 08:17 PM

Getting Started
Group Icon
Elite
195 posts

Joined: Sep 2006



MX will understand biggrin.gif

19 Pages « < 6 7 8 9 10 > » Top
Topic ClosedOptions
 

Change to:
| Lo-Fi Version
0.0195sec    0.58    6 queries    GZIP Disabled
Time is now: 4th December 2025 - 03:35 AM