Welcome Guest ( Log In | Register )

Bump Topic Topic Closed RSS Feed

Outline · [ Standard ] · Linear+

Unifi Official TM UniFi High Speed Broadbrand Thread V7, News: VIP20, free instalation till 31/12

views
     
rizvanrp
post Oct 25 2010, 04:46 PM

Getting Started
Group Icon
Elite
195 posts

Joined: Sep 2006



QUOTE(Tentris @ Oct 25 2010, 09:40 AM)
Riz,

I fully support your cause.

http://www.aizuddindanian.com/voi/2010/10/...uring-unif.html

Also, i have access to the senior management of TM (Head of Technology, Giorgio, Head of Marketing, Rozalila, Head of Corporate Affairs, Izlyn). I have shared the issue with them. They can't claim to be unaware of the issue any longer.

They need to be aware that this problem they have in their service potentially opens them up to legal liability. If a customers' network is compromised because of this loophole that they intentionally created, then they are liable for any damages that may be caused (e.g. to customers' hardware, or if information is stolen, etc.)
*
Thank you for doing that, Tentris. If they insist on keeping the remote management open (which is flawed due to the usage of a master password and the exploitable nature of the firmware itself), the blood is on their hands as far as I'm concerned. All this discussion was spawned from :

1) TMs inability to realize that customers want full control over their own network
2) TMs trust in the vendor to provide hardware with a decent level of security

Some people have compared this to TM provided Streamyx routers with a default user/pass combo. The difference is that with Streamyx :

1) We've always had the ability to swap out their crappy hardware.
2) An attacker would not get an instant 5/10/20mbps uplink with your home network without you noticing that your uplink was saturated.
3) The TM Streamyx routers lack certain services which allow you to turn them into open proxies and the firmware itself is not exploitable AFAIK.
4) Streamyx speed is capped both at the physical and digital level.
5) Streamyx does not have a monthly 'quota'.

The ability to illegally increase your package speed (as rexio has kindly pointed out in his in depth technical 'laymans' guide /sarcasm), use the HSBB speeds as fast open proxies, mine information from users and possibly bypass the download quota (in the future) makes these Unifi routers valuable targets to outsiders especially since they're so easy to break into.. as TM is encouraging customers to just leave everything open.

QUOTE
From what I can see in this forum, most of the subscriber prefer the technician/installer to install the unifi as soon as possible, do you think the technician/installer even bother to help you change the username/password for each of the unifi's subscriver's house, it'll take longer time isn't it?

The idea that it would take a long time to simply change a password and notify the customer that there's a secondary hidden account in their router meant for administration purposes (as compared to running your roof pulling fiber optic cabling or something) is laughable. Do you have no work ethic? Should surgeons leave patients half open because they want to get off the operating table ASAP?

They can let the customer change this or set it to shared variable such as a PPPoE password so only the customer + customer service staff have access to it. Most importantly, they have to disable the remote management and ask the customer to enable it only when it is needed (and patch the damn firmware). If you subscribe to this 'tidak apa, aku malas' attitude, then you deserve to be screwed over by other people. TM might as well set and lock the default wifi password to 'unifi' and claim that at least that way, every Malaysian will receive free high speed wifi access.

This is supposed to be some revolutionary new infrastructure for us Malaysians, why should we repeat the mistakes of the past? Just because it's already an issue with Streamyx, why let it continue with Unifi when we're starting with a clean slate? Frankly, I'm just disappointed that the LYN forums has to do all the technical support for such a large company.

---

To the others who have thanked me, no prob I guess tongue.gif
rizvanrp
post Oct 28 2010, 10:08 PM

Getting Started
Group Icon
Elite
195 posts

Joined: Sep 2006



QUOTE(kollerss @ Oct 28 2010, 09:26 PM)
Noob here just a question

i just heard rumors will unify come to the area near kelana jaya, Taman Megah, taman mayang and some parts of Damansara jaya next year is that true? and i also heard that next year they are implementing the bandwidth cap
*
DJ @ KDU side has been fully covered since April, not sure about the stretch from DJ -> Kelana Jaya LRT there though
rizvanrp
post Oct 30 2010, 11:12 PM

Getting Started
Group Icon
Elite
195 posts

Joined: Sep 2006



QUOTE(dmc0105 @ Oct 30 2010, 09:49 PM)
Just got my tp-link WR1043ND wireless router...

Went to rizzy site for guide and this happened...

» Click to show Spoiler - click again to hide... «

*
Lolol, looks like someone hit my joomla smile.gif Brb

EDIT : Lol, note to self -- don't use shared web hosting from Malaysian companies + Joomla.

This post has been edited by rizvanrp: Oct 30 2010, 11:24 PM
rizvanrp
post Oct 31 2010, 01:29 AM

Getting Started
Group Icon
Elite
195 posts

Joined: Sep 2006



QUOTE(dmc0105 @ Oct 31 2010, 01:06 AM)
Pls up ur webserver... Need to see the guide...
*
Site is back up but I'm gonna be moving to another host (dedicated linux box instead of shared hosting) + rebuilding the site.

QUOTE(MX510 @ Oct 31 2010, 01:11 AM)
Apa sudah jadik kena root ?
*
Got hit by a some new Joomla exploit doh.gif They were nice enough not to delete anything but left behind some of their files (compressed PHP shell). No idea what the hosting company is doing at the moment. Anyway, saw this coming a while back and I already setup a backup server but it's going to take some time to port it over.
rizvanrp
post Oct 31 2010, 04:42 PM

Getting Started
Group Icon
Elite
195 posts

Joined: Sep 2006



QUOTE(Acrisius @ Oct 31 2010, 04:28 PM)
That's bad thing about Free Source, full of bugs. I think they just defaced your page without exploit root access on hosting serverĀ  blink.gif
*
Lol, yeah. I found the initial attack vector along with a ly0kha shell scattered among the files in the shared hosting account. Had a feeling this entire month that something like this would happen so I had the site backed up + a static version planned to address the issue. For some reason, they took about 3 hours to compromise the account and I'm guessing that my webhost had an AV firewall which blocked PHP shells while they were trying to upload it.. so they compressed it twice and unpacked it once it was uploaded. My Joomla administrator directory was password protected so I assume that they exploited one of the default Joomla modules (as I never installed any 3rd party ones and disabled most of them). Some googling shows they hit a few other websites with the same exploit.

Doesn't matter anyway, site is back up on a hardened VPS.

UPDATE: Looks like it wasn't just my site that was hit, few Shinjiru servers were rooted.

This post has been edited by rizvanrp: Oct 31 2010, 09:19 PM
rizvanrp
post Nov 14 2010, 09:01 PM

Getting Started
Group Icon
Elite
195 posts

Joined: Sep 2006



QUOTE(tuckker @ Nov 14 2010, 06:29 PM)
Question on Unifi:

1. Unifi's phone is a VOIP phone. What is the phone number for it? Same as 03-xxxx xxxx?

2. Can we plug this VOIP line that comes with Unifi, into a IP PBX, so internal users in the company can call from this VOIP line?
*
1. Yeah

2. Depends on what BTU you're using and your other equipment really. I believe there's some security checks using DHCP parameters in place to prevent non BTU clients from patching into the VOIP network. I haven't done much research on this because my own Fiberhome is pretty restrictive and I lack VOIP equipment to test it with.
rizvanrp
post Nov 21 2010, 02:15 AM

Getting Started
Group Icon
Elite
195 posts

Joined: Sep 2006



QUOTE(nkarul85 @ Nov 20 2010, 10:13 PM)
guyz, this rumor is true???
*
No, nothing is finalized.
rizvanrp
post Nov 21 2010, 02:22 AM

Getting Started
Group Icon
Elite
195 posts

Joined: Sep 2006



QUOTE(nkarul85 @ Nov 21 2010, 02:20 AM)
rizvan

i cant login to my acc
when i enter password, got this message  There is already an active session

almost 2week cant login
any idea wat should i do??

i need to check something
*
What account are you talking about and where are you logging in?

3 Pages < 1 2 3Top
Topic ClosedOptions
 

Change to:
| Lo-Fi Version
0.0727sec    0.44    8 queries    GZIP Disabled
Time is now: 29th November 2025 - 01:09 AM