Sign up
 Vonage  

       
 
Vonage Forum Menu

Vonage Forums
Vonage VoIP Forum
jenjee Posted:
Hello, My
friend had
cancelled Vonage
over 5 years ago,
but still has the
modem
...

In The Forum:
Vonage
Topic:
Best way to dispose of Modem or Router
On May 26, 2012 at 18:09:22

sssscary Posted:
Hi, I realize this
post is old, but I
was just trying to
find out how to
auto delete
...

In The Forum:
VoIP Feature Wish List
Topic:
Auto-Delete Voicemail When Forwarded to Email!!
On May 24, 2012 at 08:08:15

sandyj Posted:
The last few days
I've gotten a
couple of calls
from angry people
demanding that
...

In The Forum:
Vonage
Topic:
Someone is using my phone number? Hacked?
On May 18, 2012 at 20:07:46

vrtlassit7 Posted:
Can anyone help me
figure out a
solution to create
a virtual
attendant? I own
a small
...

In The Forum:
VoIP Feature Wish List
Topic:
Virtual Attendant
On May 18, 2012 at 07:53:07

rodisport Posted:
I have had this
problem for more
than 4 months now
when i call some
one it doesn't
...

In The Forum:
Vonage UK
Topic:
no ringing tone
On May 14, 2012 at 18:17:44

js123 Posted:
we already have
vonage device how
can i reactivate
the service and
what is the
procedure.
...

In The Forum:
Vonage
Topic:
how to reactivate the service
On May 12, 2012 at 14:57:39

dconnor Posted:
A photo would be
helpful.
...

In The Forum:
Hard Wiring - Installation
Topic:
Problem with home wireup
On May 08, 2012 at 10:47:17

rival Posted:
Thank you! This
was my exact
problem. Outgoing
calls would fail,
incoming calls
...

In The Forum:
Vonage
Topic:
Dial tone ok, incoming calls ok, no outgoing calls
On May 03, 2012 at 21:11:35

stevejone Posted:
This is really a
good topic.It
gives a quite
detailed
information about
the jammer
...

In The Forum:
Vonage UK
Topic:
Application of Cell Phone Jammer
On May 03, 2012 at 11:29:58

MiveAmige Posted:
The nature of a
cell phone jammer

By
mobile jammer
(jammer, cell ph
...

In The Forum:
Vonage UK
Topic:
Application of Cell Phone Jammer
On May 02, 2012 at 18:55:02


Vonage VoIP Forums

Vonage In The News
Vonage Offers Free Calling to Latin American Destinations this Mother's Day Weekend

Vonage World® Now Includes Free Calling to Pakistan

Syndication

Vonage Customer Reviews
Appreciation
Appreciation



Vonage vs. Time Warner Cable SoCal
Vonage vs. Time Warner Cable SoCal



international connection
international connection



VDV21-VD adapter and Vonage service - a winner!
VDV21-VD adapter and Vonage service - a winner!



Should have signed up sooner!!!!
Should have signed up sooner!!!!




Vonage Reviews

Vonage http://lists.grok.org.uk/pipermail/full-disclosure/2005-November/038834.html ====================



http://lists.grok.org.uk/pipermail/full-disclosure/2005-November/038834.html

===============================================================

VENDOR:
UTStarcom

VENDOR NOTIFIED:
27 June, 2005 via sales at utstarcom.com

VENDOR RESPONSE:
None

PRODUCT:
UTStarcom F1000 Voip WIFI Phone
http://www.utstar.com/Solutions/Handsets/WiFi/

SOFTWARE VERSION:
s2.0
VxWorks (for Hornet VoWifi, ARM946ES (LE)
Factory Firmware) version 5.5.1.
Kernel: WIND version 2.6.
Made on Apr 5 2005, 14:49:39.

A. VULNERABILITY TITLE:
UTStarcom F1000 Voip Wifi phone SNMP daemon has default public read
credentials and the daemon cannot be disabled

VULNERABILITY DETAILS, IMPACT AND WORKAROUND:
UTstarcom F1000 SNMP daemon default public credentials allows an
attacker with access to the phone's SNMP daemon to read the phone's
SNMP configuration. This can lead to sensitive information disclosure.
In addition, the daemon's read/write credentials cannot be changed,
nor can the daemon be disabled via the phone's physical interface
(i.e. via keypad input). During testing, the SNMP daemon appeared
consistently die when connecting via Snmpwalk, requiring rebooting the
phone in order to restore SNMP service.

B. VULNERABILITY TITLE:
UTstarcom F1000 Voip Wifi Phone telnet server has known default
user/password credentials

VULNERABILITY DETAILS, IMPACT AND WORKAROUND:
The phone's operating system is Wind River's Vxworks. Default
credentials for this OS are publically known to be target/password.

By default, the telnet deamon is listening on the phone (TCP port 23)
providing WIFI network access to the phone's OS. Attackers can telnet
to the phone and gain access to the phone's Vxworks OS using the known
default credentials.

Impact is full access to the Vxworks OS, including debugging, direct
memory dumping/injection, read/write device, user and network
configuration files, enable/disable/restart services, remote reboot.
For a workaround, the default login/password can be changed.

C. VULNERABILITY TITLE:
UTstarcom F1000 Voip Wifi Phone rlogin (TCP/513) unauthenticated access

VULNERABILITY DETAILS, IMPACT AND WORKAROUND:
The phone's rlogin port TCP/513 is listening by default and requires
no authentication. An attacker connecting to the phone via
telnet/netcat is dropped into a shell without any login. The shell
provides an attacker full access to the Vxworks OS, including
debugging, direct memory dumping/injection, read/write device, user
and network configuration files, enable/disable/restart services,
remote reboot.

There appears to be no workaround as neither the service can be
disabled, nor can authentication to rlogin be enabled.



Read The Full Thread:

So I assume that the F1000 security issues are now resolved?


Have a look at the complete link: http://secunia.com/advisories/17629/ It

shawnmer posted "http://lists.grok.org.uk/pipermail/full-disclosure/2005-November/038834.html ====================" on 12/13/2005

Vonage Service Plans


Vonage VoIP Members
Members List Members
New Raniinody
New Today 3
Yesterday 3
Total 64297

Who Is On Site
Visitors 135
Members 0
Total 135


Vonage VoIP Forum Members:
Login Here
Not a Member? You can Register Here
As a registered member you will have access to the VoIP Speed Test, Vonage Service Announcements and post comments in the
Vonage VoIP Forums

Vonage Stock Price
Value: 1.70
Change:   -0.03
Up to 15 Minute Delay

Site Search
 




1Unlimited calling and other services for all residential plans are based on normal residential, personal, non-commercial use. A combination of factors is used to determine abnormal use, including but not limited to: the number of unique numbers called, calls forwarded, minutes used and other factors. Subject to our Reasonable Use Policy and Terms of Service.

2Shipping and activation fees waived with 1-year agreement. An Early Termination Fee (with periodic pro-rated reductions) applies if service is terminated before the end of the first 12 months. Additional restrictions may apply. See Terms of Service for details.

HIGH SPEED INTERNET REQUIRED. †VALID FOR NEW LINES ONLY. RATES EXCLUDE INTERNET SERVICE, SURCHARGES, FEES AND TAXES. DEVICE MAY BE REFURBISHED. If you subscribe to plans with monthly minutes allotments (for example, U.S. & Canada 300), all call minutes placed from both from your home and registered ExtensionsTM phones will count toward your monthly minutes allotment. ExtensionsTM calls made from mobiles use airtime and may incur surcharges, depending on your mobile plan. Alarms, TTY and other systems may not be compatible. Vonage 911 service operates differently than traditional 911. See www.vonage.com/911 for details.

** Certain call types excluded.

www.vonage-forum.com is not an official Vonage support website & is independently operated.
All logos and trademarks are property of their respective owners. All comments are property of their posters.
All other www.vonage-forum.com content is © Copyright 2002 - 2012 by 4Sight Media LLC.

Thinking of signing up for Vonage but have questions?
Business and Residential customers can call Toll Free 24 hours a day at: 1-888-692-8074
No Vonage Promotional Codes or Coupon Codes are required at www.vonage.com.

[ | | | | | ]

Vonage Forum Site Maps

Vonage | VoIP Forum | How VoIP Works | Wiring and Installation Page Two | International Rate Plans 2 | Internet Phone
Promotion | Vonage Review | VoIP | Broadband Phone | Free Month | VoIP | Phone Service | Rebate
Phone | Latest News | VoIP Acronyms | Vonnage | Vontage | Deal | Site Maps

The Vonage Forum provides the Vonage sign up Best Offer Promotion Deal as a means to offset our cost.
If you are considering signing up for Vonage and have found our Vonage News, Customer Reviews, Forums
& all other parts of this site useful, please use our Vonage FREE Month sign up offer Deal Coupon.


Vonage VoIP Phone Service is redefining communications by offering consumers
& small business VoIP Internet phones, an affordable alternative to traditional phone service.
The Vonage VoIP Forum Generated This Page In: 0.32 Seconds and 236 Pages In The Last 60 Seconds
The Vonage VoIP Forum