Welcome Guest ( Log In | Register )

Bump Topic Topic Closed RSS Feed

Outline · [ Standard ] · Linear+

Unifi WARNING TO ALL UNIFI USERS, Threat warning, read inside

views
     
Moogle Stiltzkin
post May 29 2010, 07:42 AM

Look at all my stars!!
*******
Senior Member
4,466 posts

Joined: Jan 2003
user posted image

TIME TO MASS COMPLAIN TO CFM. EVERYBODY On your mark.... GO!!



As an after thought, i hope they don't delay Unifi in my area because of this shocking.gif

This post has been edited by Moogle Stiltzkin: May 29 2010, 07:56 AM
Moogle Stiltzkin
post May 29 2010, 08:43 AM

Look at all my stars!!
*******
Senior Member
4,466 posts

Joined: Jan 2003
Just curious what is their purpose for doing this ???

1. more control to monitor unifi user usage ???

2. customer service support to help configure modem and router ???


Reason 1 i don't need, 2 i don't need if it means reason 1 :/

For Unifi should i get VPN ;x ??

This post has been edited by Moogle Stiltzkin: May 29 2010, 08:44 AM
Moogle Stiltzkin
post May 29 2010, 09:44 AM

Look at all my stars!!
*******
Senior Member
4,466 posts

Joined: Jan 2003
QUOTE(gkl83 @ May 29 2010, 09:40 AM)
is it possible or legal to replace TM's DIR-615?
*
I don't see why not. As long as you don't try that hack riv said possible to increase your speed to 100mb or any other speed then your subscribed speed ;x
Moogle Stiltzkin
post May 29 2010, 11:39 PM

Look at all my stars!!
*******
Senior Member
4,466 posts

Joined: Jan 2003
QUOTE(night_wolf_in @ May 29 2010, 05:18 PM)
im not sure if i should laugh or cry.

If you think they want to spy on YOU by creating a second management account. Then it is big fail for all you guys, pretending to know how internet works.

Your Modem/router will be connected a layer two switch. or lets say connected to a port. they can use "SPAN" to see all the traffic you are sending and receiving. 

But again, doing that to every indivicual will be really tiring. Easier is, run "SPAN" to the uplink, that is connecting the layer two switch to the distribution switch. and bam, they can get all i/o traffic from the whole switch.

WAIT.

They can add high end firewalls at the uplinks to every area (logical or geographical) or just again SPAN the traffic to the firewalls.  AND they practically SEE every traffic you sending.

Conclusion is. dont cry a river for a second account your ISP put it. if they did, it is to make your experience better. but if you think you can out smart them. please do.

How i know. I'm a CCNP and working under routing/ switching and security for some enterprise.


Added on May 29, 2010, 5:19 pm

No, they use packet shaping devices for that.
*
If i use VPN will that at least give me some privacy despite all the stuff you mentioned ??? That is all i want to know hmm.gif

Does anyone else think tmnut should hire Riv and give him a 6 figure salary ??? *raise hands thumbup.gif

This post has been edited by Moogle Stiltzkin: May 29 2010, 11:48 PM
Moogle Stiltzkin
post May 30 2010, 01:00 AM

Look at all my stars!!
*******
Senior Member
4,466 posts

Joined: Jan 2003
QUOTE(andrew9292 @ May 30 2010, 12:29 AM)
Probably why they put that up ;p

Okay, good job for TS as he found out this major security risk considering the number of IT grads and professionals these days are out there...
But posting this here is actually publicity to this loophole.

Only those who came to LYN would find out about this and if they are tech savvy enough, they will know how to get around it to minimize the exposure risk as much as possible.

But again, if someone with unholy intention stumbles upon this, it could mean disaster for those unaware and incapable to prevent it...

I would like to ask TS, now that you have found out and posted it to public, what is your next step? Will you report to relevant authorities?
Otherwise the purpose of this thread will be:

1. Publicize a major loophole in UniFi
2. Giving knowledgeable users the chance to avoid the risk, a really small amount of people in LYN.
3. Exposing a mass mount of UniFi-ers to exploits...

So, just be aware of that. I'm no IT expert with any qualification btw. TS, u're doing the right thing, salute! but there is still a loophole in what you are doing  tongue.gif haha
*
No no, i think it was right making this public. Maybe this will get into the star and we can pressure tmnut to let their users use their own routers.

If we do have any problem, we would call tmnut helpline 100 and they can send a technician over. No need to expose our security just for that doh.gif


So anyway, anyone working for the newspaper, and please copy paste riv's statement into the news, thx. A good headline would be "TMnut obsession with control leads to security loophole for Unifi consumer and business users alike" rolleyes.gif

This post has been edited by Moogle Stiltzkin: May 30 2010, 01:03 AM
Moogle Stiltzkin
post Jun 2 2010, 03:06 PM

Look at all my stars!!
*******
Senior Member
4,466 posts

Joined: Jan 2003
QUOTE(almaty @ Jun 2 2010, 01:10 PM)
eh apologist. firstly its a wifi router. secondly, stop deflecting blame to dlink!!
that router is a custom router that tm oem-d from dlink. you cant buy it off the shelf from any store.
it is a tm router. i dont care if dlink or flink or nolink or slolink made it.

the tm logo pasted everywhere.

user posted image
*
Oem or not the hardware is still a piece of shit for p2p especially and that is the truth.

QUOTE
But, more significantly, the 615 could reliably sustain only 32 connections in the maximum simultaneous connections test. Ubicom questioned these results when they first posted in the charts and said its tests (also done with IxChariot) produced results more like the 625's. D-Link had no comment on the results.


WAN to LAN Throughput: 87.5 Mbps

LAN to WAN Throughput: 88.1 Mbps

Total Simultaneous Throughput: 62.1 Mbps

Maximum Simultaneous Connections: 32  !!!

user posted image

Uploaded with ImageShack.us 
http://www.smallnetbuilder.com/content/view/30349/187/



All tmnut did was make a piece of shit an even bigger pile of piece of shit (which sadly they proved possible by making it a security disaster and needlessly not letting their users use their own routers) shakehead.gif

This post has been edited by Moogle Stiltzkin: Jun 2 2010, 03:21 PM
Moogle Stiltzkin
post Jun 3 2010, 03:57 AM

Look at all my stars!!
*******
Senior Member
4,466 posts

Joined: Jan 2003
QUOTE(VengenZ @ Jun 3 2010, 01:54 AM)
I am proud of u rivan:
http://www.tm.com.my/about-tm/media-centre...IFIROUTERS.aspx
STATEMENT


Telekom Malaysia Berhad ™ wishes to clarify the concerns raised by various parties with regards to the remote accessibility of UniFi routers which are part of the customer premises equipment (CPE) for all UniFi subscribers.

TM would like to assure all concerned parties that the only reason the UniFi router setting for remote access is enabled is for remote access troubleshooting purposes for the express use of our technical support personnel. In the event there is a technical support issue with any of our UniFi subscribers; at the first level of troubleshooting, TM’s network operation centre (NOC) can immediately remotely diagnose the problem before sending a support team on-site.

TM takes note of the security concerns that have been raised, and we have taken these issues to heart.

TM also acknowledges that there is a need to balance the public’s level of comfort with regards to security and privacy and TM’s own commitment to faster support turnaround time. As such, TM would like to maintain the higher level of service enabled by remote access management on customer routers, and in recognition of that TM will immediately change  every UniFi customers’ router management password into a high security, unique one (which will be only known to the customer and TM). TM will notify all our Unifi customers of this change accordingly.
*
This if frakkin bullshit. All they said is

1. they are keeping remote access despite our complaints for the CHOICE of not having it (we don't want them poking around inside our stuff. And we don't want a backdoor for l33t hackers.)

2. Their only solution is to change the operator password so we cannot access....... so if we can't access, how do we bypass their shitty router and use our own using Riv's method of making the Dir-615 a vlan bridge (i refuse to use their 32 concurrent connections capable hardware for routing my p2p downloads), and connect it to our own router instead. Why is tmnut ignoring the other issue at hand??? They did not even mention any solution for letting us use our own routers. That is bullshit vmad.gif

This post has been edited by Moogle Stiltzkin: Jun 3 2010, 03:59 AM
Moogle Stiltzkin
post Jun 3 2010, 10:36 AM

Look at all my stars!!
*******
Senior Member
4,466 posts

Joined: Jan 2003
QUOTE(+Newbie+ @ Jun 3 2010, 10:26 AM)
Actually, if you read that carefully, they said they will change the passwords and then share that password with the customer. If they live up to their word, once they change it and inform you the new password, just change it back to another password.
If TM needs access in future, let them call you and you can reset the password to a temp password, let them use it and then change the password again in future.
*
Oh :/

Well if that is the case, we will just have to see then hmm.gif

This post has been edited by Moogle Stiltzkin: Jun 3 2010, 10:37 AM
Moogle Stiltzkin
post Jun 15 2010, 11:16 PM

Look at all my stars!!
*******
Senior Member
4,466 posts

Joined: Jan 2003
QUOTE(coollguy100 @ Jun 15 2010, 09:38 PM)
hi

is there possible to just use our own router instead of theirs.... like belkin. what configuration need to do ???
*
http://unifi.athena.my/index.php

cool.gif
Moogle Stiltzkin
post Jun 25 2010, 01:29 PM

Look at all my stars!!
*******
Senior Member
4,466 posts

Joined: Jan 2003
QUOTE(morpheus3929 @ Jun 25 2010, 04:57 AM)
HOLY CRAP! JUMPIN JIGGAWATS WATSON! dude, by uploading the screenshot, aren't you risking yourself and other UNIFI subscribers from hackers and arseholes?  shocking.gif
*
Don't worry. tmnut is keeping tabs so they should fix it.
Moogle Stiltzkin
post Jun 30 2010, 01:20 PM

Look at all my stars!!
*******
Senior Member
4,466 posts

Joined: Jan 2003
QUOTE(vNistelrooy @ Jun 30 2010, 05:04 AM)
this is very alarming..my concern is if they can trace what the user download off the net..
*
They already do that doh.gif
Moogle Stiltzkin
post Sep 21 2010, 07:40 PM

Look at all my stars!!
*******
Senior Member
4,466 posts

Joined: Jan 2003
QUOTE(azrulex @ Sep 21 2010, 04:54 PM)
just installed unifi today.. they completed it quite fast. Already disabled remote mgmt and changed both admin & operator password. hehe
*
So.... how much prons have you downloaded so far laugh.gif

Fast?

Topic ClosedOptions
 

Change to:
| Lo-Fi Version
0.0269sec    0.48    7 queries    GZIP Disabled
Time is now: 9th December 2025 - 10:52 AM