@Gaurav15 The exchange officer has raised a docket to the Noida BSNL office and there is no reply from them. And Since tomorrow is Sunday so I guess they won't be answering tomorrow too!
I’m sorry this is a bit off-topic question but I’m wondering if someone with malicious intent get’s hold of the PPPoE credentials of a BSNL FTTH customer, can they use it in any means that will prevent the actual customer from authenticating themselves with BSNL uplink servers or knocking them out of connectivity?
Someone else on this forum had that happen to them yes. You have to be under the same LCO for that I believe, and they'll also need your VLAN id. Your LCO probably have both of them.
You can change your default password on https://fuptopup.bsnl.co.in
Login with your user id and default password (which is "password") and there'll be an option to change it.
^this and my friend actually confirmed it himself, he logged in with his credentials on his neighbours bsnl ftth and it worked. . I can't check, there are no bsnl ftth users nearby.
It does make sense, compared to ADSL we're not getting dedicated lines, just a single fiber backend only divided into VLANs. Anyone can connect to the same line with your VLAN id and PPPoE credentials to use your internet. If they connect while you are offline, you can't connect either. BSNL only allows one active session.
Thanks a lot for your inputs. But doesn’t BSNL do MAC address binding of the customers actual ONU/ONT and cross verify it upon PPPoE authentication? And if BSNL is aware of this vulnerability they should be encouraging the users to change the default PPPoE password as soon as it’s installed on their premises! They don’t even have a bug free interface that lets the user change their own PPPoE password. And it’s only possible from the native IP pool. These needs to change. And is there any other means that BSNL would be able to do on their part to patch this vulnerability?
@Adithya@Gaurav15
Is the PPPoE password change done via https://fuptopup.bsnl.co.in/ instantaneous? Is there any delay for change to take effect. If yes, how long? And is there anything else to be kept in mind to make this process foolproof?!
Sorry again for topic-hijacking the thread but I feel what discussed is somewhat relevant to the original topic.
I've never changed the password, so can't say for sure. But your password alone should make it foolproof. Default BSNL password is 'password' since ADSL age and everyone knows it. There was a time when I could use someone else's ADSL credentials to use internet , but then BSNL restricted ADSL to the correct phone number address or something. Nothing yet for FTTH other than VLAN
This website uses affiliate links. This means that if you click on a link and make a purchase, we may receive a commission. This does not affect the price you pay for the product.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.