HELPING YOU TO THE BEST

Hack BSNL Broadband

Disclaimer : The information provided below is for educational purpose only. The author is not responsible for any misuse of the information and discourages any illegal use of it.

Bsnl Broadband continues to grow as one the most popular broadband services in India with high speed facilities of upto 2 mpbs. But a large number of users of this service are vulnerable to hacker attacks because discovering and hacking the vulnerable victims of this network is shockingly simple. If you are a Bsnl Broadband user then immediately assess the security of your internet connection and take appropriate steps to secure yourself.

First lets see how simple it is to get bsnl broadband usernames and passwords. For this you shall need a ipscanner tool called Angry IP Scanner

Ok so lets begin...

Step 1 : Start Angry IP scanner and goto options > ports. Type in 80 in the first ports textbox and click ok.Then goto options > options ; in the display section select "only open ports" and click ok&save.
Now on the main screen put in the ip scan range as something 59.*.0.0 - 59.*.255.255 (for e.g. 59.95.2.3) and click the start button. And the list that shall follow next are the victims. In this example we choose the range 59.95.0.0 - 59.95.255.255. You will be surprised at the number of victims you discover.

Step 2 : Pick the ip-address of any of them and open up your browser and type in ht*p://59.*.*.* (the * should be replaced by the values from the ip you are using. A box will popup asking for username and password. Enter the username : admin and password : admin .There is a high chance that you will be able to login with that username and password.
admin-admin is the default username and password that is set while manufacturing the adsl modem devices.

What follows next is the modem administration panel.
Simply search for the "WAN" option and click it. On the next page you will find the username and password of that user. now right-click on the page and click view source. in Mozilla/Opera This frame -> view frame source

Now in the source code search for this : INPUT TYPE="PASSWORD"
and the value field of this input element will have the password

if its not there as in case of D-Link DSL 502T ADSL Routers the search for this

input type="hidden" name="connection0 ppoe:settings/password" value="password" id="uiPostPppoePassword"and the value field will have the password

Well each steps take less than 1 minute so getting username passwords wont take even 2 minutes and is easier than sending a mail.And this exposes the weak security of bsnl broadband users.

Well this is not a weakness but more of a mis-configuration which leads to insecurity. If you understand networking then you would probably realise that it was merely logging into the remote administration service of the modem and nothing else. This was not really hacking but a simple search of victims who are absolutely ignorant of their weak security on the internet

Most routers have an option where remote management can be disabled. In other words, you can only connect to the configuration interface from the internal network, not the WAN(Internet) side. You would definitely want to make sure remote management is not active to protect yourself.

Note : On SmartAX MT880 eventhough Remote Management is disabled , it permits remote logins from over the Internet. So change your mode administration passwords immediately

The problem is that the professionals at Bsnl are ignorant of such simplicity of networking and unable to advise the users or guide them to take proper security measures leaving their customers and themselves absolutely unsecure.

Now lets check a few more options related to this issue. A bsnl broadband modem can be used in two modes. RFC Bridged mode and pppoe mode.

In the RFC Bridged mode the device behaves like a modem device that is attached to your computer and you use some dialup software to dial into the isp through this modem.This is PPPOE from the PC and the adsl device is a good modem. This mode is safer as the username password are on your pc and nothing is on the modem.

In the PPPOE mode the adsl device becomes a router - a distinct network device with many features enabled. In this mode the username password is stored in the modem which will dial to the isp and establish the internet connectivity. The computers will just connect to this router who would be their primary gateway. Now this is the mode where the risk exists.

If remote administration is enabled the remote users from the internet can login to this modems administration panel. Now the main problem is the default admin username-password which most users dont change due to ignorance. "admin-admin" is pair that works in most cases giving you full access to the modems internals. What follows next is simple as drinking a glass of orange juice.

Many users install firewalls and think they are safe, but they fail to understand that the firewall protects their PC not the "router" since the topology is like(PC) -> router -> internet

So how should you secure yourself ?
1. Use RFC Bridged mode if it is sufficient for you.
2. Change the default admin password of your modem.
3. Disable wan ping reply . ( this will prevent the hackers from directly discovering your pc when it is on the internet)
4. Disable remote configuration feature.
5. Check your broadband usage on a regular basis and compare it with your own surfing schedules to check whether someone else has used it or not. If suspiscious usage is indicated then immediately change your bband password as well. Or a better suggestion will be to change broadband passwords on a regular basis.

13 comments:

Big B said...

there's an easier way to retrieve the password. Just use Firefox and install a xpi plugin called unmask password. Well, that's an information only. You better use it in right way ;)

Rohit said...

but ders a problem,even after retrieving username and password,we cant use it.only one account per modem...is der a tweak??

Anonymous said...

after getting the username and password still not connecting to internet
when trying the message is coming
"aCCESS WAS DENIED THE USERNAME AND/OR PASSWORD WAS INVALID ON THIS DOMAIN"
PLEASE TELL ME THE SOLUTION

bhanu said...

ggggggggggggg

Anonymous said...

so u copied from the article
Hacking Bsnl Broadband Passwords

Anonymous said...

hi try this IPMango
This is an amazing geotracking site

Anonymous said...

take this is latest hacked account enjoy!!!!


i got it from orkut

any one :

http://rapidshare.com/files/117654503/bsnl_hacked_account_may_2008.rar

http://rapidshare.com/files/117549410/LogIn.zip

Anonymous said...

take this is latest hacked account enjoy!!!!
Anonymous said...

take this is latest hacked account enjoy!!!!

i got it from orkut

any one :

http://rapidshare.com/files/117654503/bsnl_hacked_account_may_2008.rar

http://rapidshare.com/files/117549410/LogIn.zip


Its a fake, dont d/l anythin..

Anonymous said...

Initially when BSNL started its broadband service Port binding was not enabled. They have done this some 2 years back in chennai.
I am sure that there is a way in by pasing this port binding which disables connection from other landlines other than the prescribed line for an User account. Security is made for someone to break it..which allows more innovation. BSNL will surely have a hole in its security..hope we crack it someday!

Anonymous said...

why must i use http://59.*.*.254 leaving one ip http://59.&.&.1 where *= subnet basic rules 255 is a broadcast IP and &= some special IP which is a RADIUS server which authenticates users? i may just as well telnet into it? isnt it? telnetting is a way dumber method these days. but hell yeahhhhhhhhhhhh, it works. and dude? you need to brush up your IP addressing thingie. ;-) *.255 is a broadcast and &.1 is the radius server, never try and attempt these servers. :-p
my 2 cents. and chennai? mmmmmmm....... where you all folks hang out? which area exactly? i just carry my back pack and custom linux and woooooooooosh around. ;-)
dont worry build the world classiest firewall and IDS and IPS if you leave yout telnetd or 23 port open? i will say a hi and leave a bye note. ;-)

z0mbie said...

Police will pwn u guys i swear ..

,,!,,

Anonymous said...

No IP adress is loading properly.

Shefeek Jinnah said...

It was possible some.But now bsnl has implemented port binding on most of its connection..so even if you get somebody else password,you cant just simply use it.A BSNL broad band account can be accessed only from his land line number on which the account is registered.But its a fact that its easy to get bsnl broad band password.I explained the measures needed to be taken to secure your connection from being hacked in this link
http://www.shefeekj.com/attention-broadband-users-you-might-be-trapped.html