Reply
Thread Tools
qole's Avatar
Moderator | Posts: 7,109 | Thanked: 8,820 times | Joined on Oct 2007 @ Vancouver, BC, Canada
#31
Originally Posted by t3h View Post
If you install SSH, it allows anyone to connect remotely to your device if they know your password. The password is widely known for the root account ("...."), so anyone who does ssh root@1.2.3.4 (being the IP of the tablet) can use that password to get in.
Now it's even easier for an attacker. Someone gave the default password in the same thread as my description of the exploit. So you can pretty much assume you will be hacked with SSH and the default password.
 
Posts: 156 | Thanked: 44 times | Joined on Dec 2007
#32
Originally Posted by qole View Post
Someone gave the default password in the same thread as my description of the exploit.
The password was widely known before I mentioned it (http://www.google.com/search?q=rootme+nokia)...

There's no reason not to change it, and it's trivial to change.

Last edited by t3h; 2007-12-18 at 03:04.
 
Posts: 17 | Thanked: 0 times | Joined on Dec 2007
#33
Trivial to change perhaps ... BUT ... anyone who hasn't visited this specific thread (most Tablet owners) won't know they need to... !

By the way - as a non-Linux, fairly tech-savvy, user, but not geek - please can someone explain how to change the password ! It may be trivial, but *I* don't know how, just like many other readers of the thread I suspect ;-)

Walter

Last edited by Wally; 2008-01-19 at 01:21.
 
free's Avatar
Posts: 739 | Thanked: 159 times | Joined on Sep 2007 @ Germany - Munich
#34
The linux command for changing the password is...

drums..





suspsense...











passwd

!!
 
Posts: 334 | Thanked: 55 times | Joined on Aug 2007 @ Eastern Ontario, Canada
#35
This is a great thread, very informative. Thank you everybody.

A question: If I install ssh (and change the password) then is there a simple (one-click?) way for me to enable/disable ssh so that I can minimize the time I have port 22 open? Ideally, the tablet should boot with ssh disabled.
 
free's Avatar
Posts: 739 | Thanked: 159 times | Joined on Sep 2007 @ Germany - Munich
#36
Originally Posted by dont View Post
Ideally, the tablet should boot with ssh disabled.
You'll need xterm and root access:
Take care, with the following steps, ssh will not start anymore at boot!
sudo gainroot
rm /etc/rc2.d/S20ssh

to revert the start at boot:
sudo gainroot
cd /etc/rc2.d
ln -s ../init.d/ssh S20ssh


To start ssh:
sudo gainroot
/etc/init.d/ssh start

To stop it:
/etc/init.d/ssh stop

You can also change the port ssh is listening:
/etc/default/ssh:
SSHD_OPTS="-p 666"
Will listen on port 666
 
Posts: 31 | Thanked: 0 times | Joined on Dec 2007
#37
Hi everyone.

I have a bit of knowledge in computer/apps/network security, and I have a N810 nit with SSH server and openvpn to my private server, etc.
I use it with several Wifi hotspots (and HSDPA networks, in Europe, through a 6120c). I use CIFS file sharing, SSH,...

It's true the tablet _is open_ (in terms of UDP/TCP/IP connectivity, i.e. NO firewall on it), and you don't have to install a server software to be vulnerable.
OS2008 is a Linux distro, and as such can be subject to all kind of attacks, even if the probability (it's mainly a _client_ device), impact, and risk (depending on what you store on your nit, and how) are (rather) low.

Right now, I'm looking for/to build a N8x0 firewall, but have few time to play arround with iptables on my tablet. I have a small script I ported from my servers, but cannot achieve what I want to.

Did someone write an app/patch/script such as "tablet firewall" ?
If not, but if there are people willing to make or port such an app ?

I've searched Maemo.org, Garage,... I've not found anything similar.

I have small knowledge of Linux Kernel, iptables, compilation, and right now, I have an (empty ;-) OS2008 dev environnment running...

I can help, and I really want to have at least a FW script (launched through Kerez ?).

XooH


EDIT : This thread is interresting (on NIT/linux/security) :
http://www.internettablettalk.com/fo...light=firewall

Last edited by XooH; 2008-03-13 at 09:22. Reason: Adding a link
 
Posts: 4,556 | Thanked: 1,624 times | Joined on Dec 2007
#38
Originally Posted by free View Post
You'll need xterm and root access:
Take care, with the following steps, ssh will not start anymore at boot!
sudo gainroot
rm /etc/rc2.d/S20ssh

to revert the start at boot:
sudo gainroot
cd /etc/rc2.d
ln -s ../init.d/ssh S20ssh


To start ssh:
sudo gainroot
/etc/init.d/ssh start

To stop it:
/etc/init.d/ssh stop

You can also change the port ssh is listening:
/etc/default/ssh:
SSHD_OPTS="-p 666"
Will listen on port 666
Hmm, isn't there a directory you can place scripts in so that when you say "ssh start" in bash or xterm it'd just run that script (it checks the directory then runs the relevant script or program?). I forget which directory it is..
__________________
Originally Posted by ysss View Post
They're maemo and MeeGo...

"Meamo!" sounds like what Zorro would say to catherine zeta jones... after she slaps him for looking at her dirtily...
 
Posts: 3,841 | Thanked: 1,079 times | Joined on Nov 2006
#39
Originally Posted by XooH View Post
It's true the tablet _is open_ (in terms of UDP/TCP/IP connectivity, i.e. NO firewall on it), and you don't have to install a server software to be vulnerable.
Sure you do. Otherwise there won't _be_ anything to connect to.

A netstat -ant on my N800 shows that it's listening on the following TCP ports:

22 (because I installed an ssh server)
12493 (part of Skype)

Checking UDP:
2049 (dnsmasq)
12493 (part of Skype).

That's it. Without servers listening you're _not_ vulnerable. And using e.g. iptables to block the ports above would simply make those services stop working. (Edit: e.g. SSH must be secured by other means, e.g. using only RSA authentication, or changing password etc.)
__________________
N800/OS2007|N900/Maemo5
-- Metalayer-crawler delenda est.
-- Current state: Fed up with everything MeeGo.

Last edited by TA-t3; 2008-03-13 at 15:53.
 
Posts: 364 | Thanked: 54 times | Joined on Feb 2008
#40
while security is certainly a non-trivial issue...some folks out there definitely seem to require a tin-foil-hat 24/7...

I subscribe to the Darwinian idea of personal wireless security...stoopid people should not breed. If someone is arrogantly stoopid enough to splat their info out there w/no regard to proper encryption...they deserve what they get. Eventually these sorts will stop using the internet and the world will once again be safe from the AOL users of the world thus ending the way we are heading toward the Idiocracy style of life.

FYI, most serious wifi hotspot style routers now have full on virtual servers which completely isolate peers (or potential peers) not only from each other but also from the primary network served by the router. So, if desired, nodes cannot see each other over whatever network is being run. Even my travel/pocket Wifi router CTR350 from Cradlepoint has this all built-in...

And remember when getting your tin foil hat, get some ear plugs too so nobody can hear what you are thinking.
 
Reply


 
Forum Jump


All times are GMT. The time now is 11:33.