Go Back   Wireless and Wifi Forums > News > Newsgroups > uk.telecom.voip
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 07-18-2005, 05:40 AM
Tom
Guest
 
Posts: n/a
Default Grandstream BT 101 phone hacked?

Hi,

I have a SIP phone (Grandstream BT 101), which I use with Sipgate. However,
yesterday, when I tried to use it, it wouldn't work. I went to the settings
page of the phone, and discovered that the connection details had been
changed. The provider was no longer Sipgate but europasstelecom.com (many
settings had been changed).

I wonder if this is a bug following a self-firmware update, or if some
company hacked the phone to change the provider...

Tom



Reply With Quote
  #2 (permalink)  
Old 07-18-2005, 06:12 AM
Ivor Jones
Guest
 
Posts: n/a
Default Re: Grandstream BT 101 phone hacked?

Tom wrote:
> Hi,
>
> I have a SIP phone (Grandstream BT 101), which I use with Sipgate.
> However, yesterday, when I tried to use it, it wouldn't work. I
> went to the settings page of the phone, and discovered that the
> connection details had been changed. The provider was no longer
> Sipgate but europasstelecom.com (many settings had been changed).
>
> I wonder if this is a bug following a self-firmware update, or if
> some company hacked the phone to change the provider...
>
> Tom


Interesting, not come across that before. I'll make some enquiries..! Had
the firmware recently updated..?

Ivor



Reply With Quote
  #3 (permalink)  
Old 07-18-2005, 07:40 AM
Paul D.Smith
Guest
 
Posts: n/a
Default Re: Grandstream BT 101 phone hacked?

Please let us know what you find out! Hacking SIP phones could be a whole
new area of hurt for comsumers!

Although this shouldn't be able to hurt you commerically, it would allow
someone to fish for all your friends numbers, and could even listen in on
your conversations.

Anyone for secured media?...

Paul DS.



Reply With Quote
  #4 (permalink)  
Old 07-18-2005, 09:22 AM
Ian
Guest
 
Posts: n/a
Default Re: Grandstream BT 101 phone hacked?


"Tom" <Tom@nospam.com> wrote in message
news:Io6dnVmkZY9X3UbfRVnyuA@pipex.net...
> Hi,
>
> I have a SIP phone (Grandstream BT 101), which I use with Sipgate.

However,
> yesterday, when I tried to use it, it wouldn't work. I went to the

settings
> page of the phone, and discovered that the connection details had been
> changed. The provider was no longer Sipgate but europasstelecom.com (many
> settings had been changed).
>
> I wonder if this is a bug following a self-firmware update, or if some
> company hacked the phone to change the provider...
>
> Tom
>

Hi.

Ok, did you buy this set new? And when you programed it you set the tftp
server to 0.0.0.0 or an address on your network and changed the password.
If not and you left the tftp server address in when it reboots it will look
for the tftp server and update settings as nesesary.
To have "Hacked" it you would have needed port80 open and pointing at the
phone..
I very much doubt its been hacked.

What is even odder is that europasstelecom dont seem to have launched a
service yet!!!! and it looks like a MLM scheme as well, so any type of
advertising is good for dodgy agents.......even just getting the name
outthere....

Ian



Reply With Quote
  #5 (permalink)  
Old 07-18-2005, 11:29 AM
Paul D.Smith
Guest
 
Posts: n/a
Default Re: Grandstream BT 101 phone hacked?

> Ok, did you buy this set new? And when you programed it you set the tftp
> server to 0.0.0.0 or an address on your network and changed the password.
> If not and you left the tftp server address in when it reboots it will

look
> for the tftp server and update settings as nesesary.
> To have "Hacked" it you would have needed port80 open and pointing at the
> phone..
> I very much doubt its been hacked.
>
> What is even odder is that europasstelecom dont seem to have launched a
> service yet!!!! and it looks like a MLM scheme as well, so any type of
> advertising is good for dodgy agents.......even just getting the name
> outthere....
>


But does upgrading the firmware loose all customer settings? Is there no
facility for upgrading but restoring user configuration?

Paul DS.



Reply With Quote
  #6 (permalink)  
Old 07-18-2005, 12:52 PM
Andrew Gabriel
Guest
 
Posts: n/a
Default Re: Grandstream BT 101 phone hacked?

In article <42db928c$0$13702$ed9e5944@reading.news.pipex.net> ,
"Paul D.Smith" <paul_d_smith@x-hotmail.com> writes:
>But does upgrading the firmware loose all customer settings? Is there no
>facility for upgrading but restoring user configuration?


Much to my surprise, upgrading (and then downgrading again)
my sipura spa-3000 didn't lose any settings.

--
Andrew Gabriel


Reply With Quote
  #7 (permalink)  
Old 07-18-2005, 02:09 PM
Ian
Guest
 
Posts: n/a
Default Re: Grandstream BT 101 phone hacked?


"Paul D.Smith" <paul_d_smith@x-hotmail.com> wrote in message
news:42db928c$0$13702$ed9e5944@reading.news.pipex. net...
> > Ok, did you buy this set new? And when you programed it you set the tftp
> > server to 0.0.0.0 or an address on your network and changed the

password.
> > If not and you left the tftp server address in when it reboots it will

> look
> > for the tftp server and update settings as nesesary.
> > To have "Hacked" it you would have needed port80 open and pointing at

the
> > phone..
> > I very much doubt its been hacked.
> >
> > What is even odder is that europasstelecom dont seem to have launched a
> > service yet!!!! and it looks like a MLM scheme as well, so any type of
> > advertising is good for dodgy agents.......even just getting the name
> > outthere....
> >

>
> But does upgrading the firmware loose all customer settings? Is there no
> facility for upgrading but restoring user configuration?
>

No. But settings can be part of the TFTP process, more info here
http://tanesha.net/Wiki/GratissipTftpd.html. Personly this is the first time
I have heard of a GS being "hacked" and as I mentioned its strange that the
company mentioned doesnt have a service just a MLM scheme of types running.

Ian



Reply With Quote
  #8 (permalink)  
Old 07-19-2005, 12:54 AM
Tom
Guest
 
Posts: n/a
Default Re: Grandstream BT 101 phone hacked?

Hi,

The software was upgraded automatically apparently. I bought the phone from
new, and originally went to a single page to put my settings. I am using
Sipgate, and also added a password. The phone is also in a DMZ, so not
protected by firewall.

When I then tried to use the phone later on, it wouldn't work, so I logged
on the web interface again, and saw a new interface (three tabs instead of a
single page, so the phone must have downloaded automatically an upgrade from
the manufacturer), and the provider details had changed. The phone wouldn't
connect anyway since I don't have an account with them.

I found all of this very strange. I changed the settings manually back to
Sipgate, and the phone is now working again...


"Ivor Jones" <ivor@despammed.invalid> wrote in message
news:3k0vi6FrrkgnU1@individual.net...
> Tom wrote:
>> Hi,
>>
>> I have a SIP phone (Grandstream BT 101), which I use with Sipgate.
>> However, yesterday, when I tried to use it, it wouldn't work. I
>> went to the settings page of the phone, and discovered that the
>> connection details had been changed. The provider was no longer
>> Sipgate but europasstelecom.com (many settings had been changed).
>>
>> I wonder if this is a bug following a self-firmware update, or if
>> some company hacked the phone to change the provider...
>>
>> Tom

>
> Interesting, not come across that before. I'll make some enquiries..! Had
> the firmware recently updated..?
>
> Ivor
>
>




Reply With Quote
  #9 (permalink)  
Old 07-19-2005, 10:45 AM
Lee
Guest
 
Posts: n/a
Default OT: Why downgrade spa-3000?


"Andrew Gabriel" <andrew@cucumber.demon.co.uk> wrote in message
news:42dba60a$0$38044$5a6aecb4@news.aaisp.net.uk.. .
> In article <42db928c$0$13702$ed9e5944@reading.news.pipex.net> ,
> "Paul D.Smith" <paul_d_smith@x-hotmail.com> writes:
>>But does upgrading the firmware loose all customer settings? Is there no
>>facility for upgrading but restoring user configuration?

>
> Much to my surprise, upgrading (and then downgrading again)
> my sipura spa-3000 didn't lose any settings.
>


Out of interest - why did you downgrade?



Reply With Quote
  #10 (permalink)  
Old 07-19-2005, 12:09 PM
Andrew Gabriel
Guest
 
Posts: n/a
Default Re: OT: Why downgrade spa-3000?

In article <3k43teFs1m45U1@individual.net>,
"Lee" <me@privacy.net> writes:
>
> "Andrew Gabriel" <andrew@cucumber.demon.co.uk> wrote in message
> news:42dba60a$0$38044$5a6aecb4@news.aaisp.net.uk.. .
>> Much to my surprise, upgrading (and then downgrading again)
>> my sipura spa-3000 didn't lose any settings.

>
> Out of interest - why did you downgrade?


The version 3 firmware introduced and fault whereby all the
syslog messages are missing the PRI header so they aren't
usable. In the version 2 firmware, most of the syslog messages
are more correctly formed (a few only are missing the PRI header
and unusable).

Also, the version 3 firmware didn't fix the TCP window handling
problem which was the main reason for trying the upgrade. This
prevents the browser interface working properly when the browser
system advertises a large TCP window (i.e. probably something
over 32k, but not window scaling), and it is running across a WAN
or sufficient routers such that more than 32k of data gets
buffered across the network. It looks to me like the spa-3000 is
perhaps tripping on some associated 16bit arithmetic which needs
to be 32 bit arithmetic, screwing up its TCP sequence calculations,
and gets stuck in a TCP restransmit loop. If you have control of
the TCP window advertised from the browser system, knocking it
down to 20k is a workaround.

--
Andrew Gabriel

Reply With Quote
  #11 (permalink)  
Old 07-21-2005, 09:39 AM
Lee
Guest
 
Posts: n/a
Default Re: OT: Why downgrade spa-3000?


"Andrew Gabriel" <andrew@cucumber.demon.co.uk> wrote in message
news:42dced6e$0$38046$5a6aecb4@news.aaisp.net.uk.. .
> In article <3k43teFs1m45U1@individual.net>,
> "Lee" <me@privacy.net> writes:
>>
>> "Andrew Gabriel" <andrew@cucumber.demon.co.uk> wrote in message
>> news:42dba60a$0$38044$5a6aecb4@news.aaisp.net.uk.. .
>>> Much to my surprise, upgrading (and then downgrading again)
>>> my sipura spa-3000 didn't lose any settings.

>>
>> Out of interest - why did you downgrade?

>
> The version 3 firmware introduced and fault whereby all the
> syslog messages are missing the PRI header so they aren't
> usable. In the version 2 firmware, most of the syslog messages
> are more correctly formed (a few only are missing the PRI header
> and unusable).
>
> Also, the version 3 firmware didn't fix the TCP window handling
> problem which was the main reason for trying the upgrade. This
> prevents the browser interface working properly when the browser
> system advertises a large TCP window (i.e. probably something
> over 32k, but not window scaling), and it is running across a WAN
> or sufficient routers such that more than 32k of data gets
> buffered across the network. It looks to me like the spa-3000 is
> perhaps tripping on some associated 16bit arithmetic which needs
> to be 32 bit arithmetic, screwing up its TCP sequence calculations,
> and gets stuck in a TCP restransmit loop. If you have control of
> the TCP window advertised from the browser system, knocking it
> down to 20k is a workaround.
>


Not sure what all that means, but thanks! ;-)

I have an spa-3000 that appears to be working fine but thought I would
check.

Lee



Reply With Quote
  #12 (permalink)  
Old 07-26-2005, 08:35 AM
VoIP Knowledge
Guest
 
Posts: n/a
Default Re: Grandstream BT 101 phone hacked?

Settings can be downloaded via TFTP as the GS supports auto-provisioning. My
guess is that you have set the tftp server entry unknowingly to europass's
server. They did have a service called Noodle, which went out of business
before it started.

The Knowledge


"Ian" <spam"AT"bathfordhill.co.uk> wrote in message
news:11dne1hpd2bq4e2@corp.supernews.com...
>
> "Paul D.Smith" <paul_d_smith@x-hotmail.com> wrote in message
> news:42db928c$0$13702$ed9e5944@reading.news.pipex. net...
> > > Ok, did you buy this set new? And when you programed it you set the

tftp
> > > server to 0.0.0.0 or an address on your network and changed the

> password.
> > > If not and you left the tftp server address in when it reboots it will

> > look
> > > for the tftp server and update settings as nesesary.
> > > To have "Hacked" it you would have needed port80 open and pointing at

> the
> > > phone..
> > > I very much doubt its been hacked.
> > >
> > > What is even odder is that europasstelecom dont seem to have launched

a
> > > service yet!!!! and it looks like a MLM scheme as well, so any type of
> > > advertising is good for dodgy agents.......even just getting the name
> > > outthere....
> > >

> >
> > But does upgrading the firmware loose all customer settings? Is there

no
> > facility for upgrading but restoring user configuration?
> >

> No. But settings can be part of the TFTP process, more info here
> http://tanesha.net/Wiki/GratissipTftpd.html. Personly this is the first

time
> I have heard of a GS being "hacked" and as I mentioned its strange that

the
> company mentioned doesnt have a service just a MLM scheme of types

running.
>
> Ian
>
>




Reply With Quote
Sponsored Links
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
is this true? "Cell Phone Tricks" Joe alt.cellular.nokia 12 03-28-2007 10:28 AM
Review of Nokia 6280 on the Three 3g network in the UK. Problems, pitfalls and solutions Jonathan uk.telecom.mobile 6 03-22-2007 01:12 PM
Could anything more go wrong with an o2 upgrade than this? (long) Anim uk.telecom.mobile 8 12-09-2006 08:30 AM
Oxygen Phone Manager II v2.11.5 for Symbian OS smartphones is just released! Oxygen Software alt.cellular.nokia 3 10-24-2006 03:27 PM
Myopic Economist article: Skype and "How the internet killed the phone business" Valiant uk.telecom.voip 5 09-16-2005 04:11 PM


All times are GMT. The time now is 02:51 AM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45