Comment on This Week in Security: Arch AUR, Steam Marketplace, WordPress All Face Issues, Taco-Themed Coding, and Mythos Makes National News by Cogidubnus Rex

Comment on This Week in Security: Arch AUR, Steam Marketplace, WordPress All Face Issues, Taco-Themed Coding, and Mythos Makes National News by Cogidubnus Rex 图片 1

Regarding the PPP vulnerability, I once went for a summer job at BT labs in Ipswich. Not really a formal interview, just asking questions as we looked around the place - one of those was about the current BT ADSL authentication (this being IIRC 2002 so earlyish in BT's ADSL rollout). I had a think, and couldn't fathom why there would be authentication for ADSL as your line is tagged with the phone number, and you can't have multiple ISPs with ADSL (based on the not so straightforward process of switching ADSL ISP) so what role does authentication play? To stop somebody tapping your phoneline and 'stealing' your internets?

As it turned out, the 'authentication' is to route you to your ISP so potentially you could have multiple ISPs on the same line, which is some niche cases could be useful. I never found out if one could use credentials for another ISP on your line (which I heavily suspect wouldn't work). As ADSL then used PPPoA it may not have been susceptible but if it was then what would have happened had one provided zero length credentials the BTs RADIUS servers :)

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论