next up previous
Next: Hub console Up: Setup and Configuration Previous: RIP

Ascend Pipeline 50 console

The Ascend Pipeline 50 has a console available via Telnet. Ideally, this console should be disabled. This is currently not possible with the Pipeline 50. The Pipeline also does not provide any way to lock the console after too many failed attempts, or to log this occurance. It is therefore possible for an attacker to spend weeks trying to break into the Pipeline without any indication that this is occuring.

A very good password should be chosen for it, a firmware that allows the console to be turned off should be sought, or it should be replaced with a model of ISDN router that does not have this flaw.



Michael C. Richardson
1998-11-15