RE: ISP reconfiguring cable modem?

From: Yvan Boily (yboily_at_seccuris.com)
Date: 05/29/04

  • Next message: oni_at_omgsoleetyes.com: "Re: ISP reconfiguring cable modem?"
    To: "'Paul Kurczaba'" <paul@myipis.com>
    Date: Fri, 28 May 2004 20:04:42 -0500
    
    

    You really need to read the DOCSIS standards to get a handle on how cable
    modems work.

    Most cable modems are assigned a configuration via a file transferred from a
    TFTP server (At least they were a few years ago...)

    The cable plant runs on a separate address space and is not directly
    addressable (if configured properly) from the computer connected to the
    cable modem.

    When you agree to the terms of service you agree to the configuration
    provided by the service provider. Tampering with the provided configuration
    settings constitutes theft of service, and is punishable by heavy fines and
    possibly jail time depending on where you are.

    For more info see http://www.cablelabs.com

    > -----Original Message-----
    > From: Paul Kurczaba [mailto:paul@myipis.com]
    > Sent: Thursday, May 27, 2004 2:12 PM
    > To: security-basics@securityfocus.com
    > Subject: ISP reconfiguring cable modem?
    >
    > On this ZDNet article
    > (http://zdnet.com.com/2100-1107_2-5218720.html?tag=zdaresources), it
    > mentions that to help prevent spam, comcast could remotely
    > reconfigure the
    > cable modem if it sees that user is sending out a bunch of
    > spam. How is it
    > possible to remotely configure the cable modem? Would it be a
    > TCP/IP or
    > cable signal that would reconfigure the modem? If it is
    > TCP/IP, couldn't a
    > hacker screw up the modem? If it is a cable signal, what
    > happens if the
    > cable user bought the modem at best buy or compusa (it wouldn't be ISP
    > specific)
    >
    > -Paul Kurczaba
    >
    >
    >
    > --------------------------------------------------------------
    > -------------
    > Ethical Hacking at the InfoSec Institute. Mention this ad and
    > get $545 off
    > any course! All of our class sizes are guaranteed to be 10
    > students or less
    > to facilitate one-on-one interaction with one of our expert
    > instructors.
    > Attend a course taught by an expert instructor with years of
    > in-the-field
    > pen testing experience in our state of the art hacking lab.
    > Master the skills
    > of an Ethical Hacker to better assess the security of your
    > organization.
    > Visit us at:
    > http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    > --------------------------------------------------------------
    > --------------
    >
    >
    >

    ---------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
    any course! All of our class sizes are guaranteed to be 10 students or less
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of in-the-field
    pen testing experience in our state of the art hacking lab. Master the skills
    of an Ethical Hacker to better assess the security of your organization.
    Visit us at:
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ----------------------------------------------------------------------------


  • Next message: oni_at_omgsoleetyes.com: "Re: ISP reconfiguring cable modem?"

    Relevant Pages

    • [NEWS] Cable Modem Termination System Authentication Bypass
      ... The first issue involves cable modems not manufactured by Cisco that allow ... historical behavior allows an unauthorized configuration to be downloaded ... cable modem systems. ... Customers with service contracts may upgrade to ...
      (Securiteam)
    • Re: Help with Motorola SB5120
      ... > menus of the SBG5120 Cable Modem other then resetting the modem." ... "There are no changes that can be made BY END USERS in the configuration ... Changes to the modem configuration are made by the owners of the network ...
      (comp.dcom.modems.cable)
    • Re: firewall needed?
      ... indicated some of the configuration problems others have expressed. ... something which keeps some tabs on your outgoing access can better your odds ... >> I just reciently got a cable modem. ... >> I used to run zone alarm on my win98se machine I was sharing the ...
      (comp.security.firewalls)
    • Re: Cable modems and FreeBSD
      ... Here are short descriptions of PPPoE and PPTP: ... As for a cable modem, it is a persistant connection. ... something I rarely have to do with my FreeBSD box. ... I configured the firewall using the SIMPLE configuration in rc.firewall, ...
      (comp.unix.bsd.freebsd.misc)
    • RE: modifying configuration registrar inside cisco 2600 so as to change password
      ... modifying configuration registrar inside cisco 2600 so as to ... > pen testing experience in our state of the art hacking lab. ... Attend a course taught by an expert instructor with years of in-the-field ...
      (Security-Basics)