ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

BT Home Hub encryption under fire

Tom Espiner ZDNet.co.uk

Published: 16 Apr 2008 12:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Ethical hackers from open-source research site GNUCitizen have claimed to have found a flaw in BT Home Hub router encryption.

Adrian Pastor, a security researcher who contributes to the GNUCitizen site, claimed he had been able to build a program that acts like a "rainbow table", or list of possible keys, to discover default BT Home Hub WEP encryption keys.

"In the case of the BT Home Hub in the UK, we can narrow down the number of possible keys to about 80," wrote Pastor in a blog post. "In order to avoid the brute-forcing computation time required by the 'stkeys' tool, I created 'BTHHkeygen' which looks up the possible keys for a given SSID [service set identifier] from a pre-generated 'SSID->keys' table. Think of it as a rainbow table for cracking the BT Home Hub's default WEP encryption key." WEP, which stands for "wired equivalent privacy", is an encryption algorithm used on wireless networks. 

Pastor said his research was made possible by the work of independent security researcher Kevin Devine, who last September published a strategy to crack WEP algorithms by debugging router set-up wizards. Devine found that, for some ISPs, the router's serial number is used to derive both the default SSID and the default encryption key.

Pastor applied this research to BT Home Hub routers and found that, by systematically trying all the logical options — so-called "brute-forcing" — he could derive the unique code of each hub or SSID and the encryption key.

Read this

Comment
PGP: Encryption alone no cure for data breaches

In the fight against security breaches, PGP CEO Phil Dunkelberger cautions that encryption by itself is not the answer...

Read more +

"Once the list of around 80 keys is obtained, the second step in the attack is to try each of them automatically, until the valid key is identified," Pastor continued. "For this purpose I created 'BTHHkeybf', which is a fancy wrapper around the 'iwconfig' Linux tool."

Pastor claimed he tested three different BT Home Hubs and that "the attack seems to work fine". BT Home Hub routers are made by Thompson.

The researcher recommended that BT customers switch from using WEP to using WPA (Wi-Fi protected access) encryption and change the default password.

BT admitted that there was a problem with the routers but said it didn't believe that any customers had been affected.

"It's important to realise that, although it has been possible to demonstrate a theoretical scenario where the hub may be vulnerable, we don't believe it is something that should affect the majority of BT customers in real life," said a BT spokesperson.

BT also recommended that customers change the default wireless key and the encryption type from WEP to WPA, but added that customers should change the administrator login password of the Hub Manager and leave the Hub switched on at all times, to receive firmware updates.

In January, BT denied GNUCitizen claims that users of BT's Home Hub routers could be conned into making premium-rate VoIP calls due to the continued existence of a security hole in the router's firmware.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
7 out of 7 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Network Engineer, Cisco, PIX, Juniper, Swift, BT Radianz, London City

They are also planning to use BT Radianz's managed network, which will connect their backoffice to another office overseas. Ideally it would be ...

Spanish Speaking Data Network Engineer- London- Training- Cisco- 37k

Wireless standards IEEE 802.11A/B/G standards and wireless encryption techniques such as WEP, WPA and Radius Authentication. K.eden at Huxely.co.uk ...

Technician Network Operations - London, South East

Nortel/Cisco and Juniper Router Support. Vendors: Alcatel : ATM and Frame Relay Platforms Nortel : Switches and CPE Routers Juniper : Core and Edge ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Biometric devices. Do you need one?

When saying “biometrics” I am not thinking about law enforcement, AFIS systems, national ID and visa projects. I first think about personal solutions that will make my life easier.... More

1 comment

Barracuda launches counter-suit agains...

Court cases are never pleasant or simple. The ongoing battle between security companies Trend Micro and Barracuda Networks took a new twist on Wednesday, when Barracuda launched a counter-suit... More

Post a comment

Mobile Speed Demon: Wireless Surpasses...

Mobile Speed Demon: Wireless Surpasses Landline Author: Eric Everson, Founder MyMobiSafe.com As I look around my house and throughout my network of friends, I instantly realize... More

Post a comment