Home Hub 4000 port 22 is open !

Felice
Contributor

Hello, I run a port scanner daily. Few days ago my scanner reported a new port open on my Home Hub 4000 router public IP, ssh port 22. It looks like Bell enabled sshd service on my router remotely without my knowledge and consent. Called support but was waste of time, never received call back from next level tech. Anyone know how to disable sshd on this router or block this port ? It's a vulnerability. 

0 24 6,764
1 helpful reply

Accepted Solutions

ZaneP
Community All-Star
Community All-Star

Hi @Felice 

A scan on port 22 on my HH4k shows it's filtered. Bell would use this port to access their modem. Why it's been opened to run an ssh daemon for no clear reason is uncertain.

There's no user access to disable or block this port.

You may want to post this question on the DSLR, Bell forum, as there are many tech-oriented people there who will likely reply. https://www.dslreports.com/forum/sympat

Keep us posted.

Cheers,

ZaneP

I am a Community All-Star and customer. I'm here to help by sharing my knowledge and experience. My views on Bell and the Community Forum are my own and not the views of Bell or any of its affiliates.

View reply in original post

24 REPLIES 24

ZaneP
Community All-Star
Community All-Star

Hi @Felice 

A scan on port 22 on my HH4k shows it's filtered. Bell would use this port to access their modem. Why it's been opened to run an ssh daemon for no clear reason is uncertain.

There's no user access to disable or block this port.

You may want to post this question on the DSLR, Bell forum, as there are many tech-oriented people there who will likely reply. https://www.dslreports.com/forum/sympat

Keep us posted.

Cheers,

ZaneP

I am a Community All-Star and customer. I'm here to help by sharing my knowledge and experience. My views on Bell and the Community Forum are my own and not the views of Bell or any of its affiliates.

Thanks @ZaneP ,

That's odd, this morning I asked a friend of mine to scan it on his HH4K and it's open on his too.

You need to scan from outside your home network. Try telnet'ing to yyour public IP port 22 from your smartphone data connection or from some other network like Videotron.

Regards,
Felice

ZaneP
Community All-Star
Community All-Star

I've tried to ssh to my public IP port 22, with my phone with a non-Bell data connection. Keeps timing out 🙄

I am a Community All-Star and customer. I'm here to help by sharing my knowledge and experience. My views on Bell and the Community Forum are my own and not the views of Bell or any of its affiliates.

mai1015
Contributor II

Hello, I have been using the Bell Hub 4000 for a while now. I was able to forward the SSH port to my computer so I could remotely connect to it. However, right now the router is not forwarding it anymore. When I try to connect remotely, I get an error message that says "port 22: no matching host key type found. Their offer: ssh-rsa, ssh-dss."

so, I assume that means the ssh port is open on router and wondering what could have happened to the router that caused it to open SSH port. There doesn't seem to be any setting to disable SSH on the router. As a result, I have to use an alternative port. Has anyone else experienced something similar?

ZaneP
Community All-Star
Community All-Star

Bell uses port 22 to manage the modem, afaik. Did your HH4000 get a firmware update recently?

Someone else posted to this Community forum re SSH, here . Also, a recent post was made to the Bell sub on Reddit, here . Sounds like an RSA key change? 

I am a Community All-Star and customer. I'm here to help by sharing my knowledge and experience. My views on Bell and the Community Forum are my own and not the views of Bell or any of its affiliates.

mai1015
Contributor II

i think do not know as it should be automatic. so i guess there is no way to close it?

Why is this marked as "solved"? 

There is a rogue dropbear server running on "Giga Hub", preventing the use of port 22 for user services.  This a big security risk, and very inconvenient for those of us that need port 22.

It's ridiculous, I've never seen this behaviour in 35 years of internet use.  A modem or router has no reason to block a standard and well-known port, especially one below 1024, for it's own internal use.  There are multiple CVEs on dropbear, and it forces me to do a lot of work to update other scripts to include port numbers.

Bell please revert your changes and allow your users to use the ports we've paid for, as is standard for any ISP in the world.

ZaneP
Community All-Star
Community All-Star

Agreed. This issue is not solved. MITM attack in SSH?

I am a Community All-Star and customer. I'm here to help by sharing my knowledge and experience. My views on Bell and the Community Forum are my own and not the views of Bell or any of its affiliates.

i actually call bell for it, and they have no idea about it and keep telling me that they do can not change anything other than resetting password. Guess will need another hot fix for the router.

ZaneP
Community All-Star
Community All-Star

The open port exposes exploits.

I don't think the first tier of Bell tech support is equipped to deal with this issue. You may want to post your specific concerns, with as much detail as you can provide, to the Bell Direct forum on DSL Reports, here . The forum is moderated by Bell techs, and your post is private. You'll need to register as a user, since anonymous posts are not accepted on that forum.

You could also post publicly, to get users' feedback and input, on this DSL Reports Bell forum

 

I am a Community All-Star and customer. I'm here to help by sharing my knowledge and experience. My views on Bell and the Community Forum are my own and not the views of Bell or any of its affiliates.

At some point in the past few months, my SSH forward to my home server stopped working.

I finally had time to explore in detail, and it appears the Giga Hub is responding with Dropbear SSH on port 22 instead of honouring my forward. This seems like a huge security risk, and overall broken as a concept, since it breaks the legitimate forward. The forward does work on another port.

Other posts suggest that this broke back in January with a firmware update.

Is Bell getting this issue fixed with another update?

User163974
Contributor

Any updates on this issue? Observing an open port 22 on my giga hub as well. To make it worse, user/pass auth is on and the ssh server being served is an outdated (by quite a few years) dropbear server with known vulnerabilities...why is something like this left open???? Fix please as we can't close it on our end?

Zadigre
Contributor III

I see this thread has been dead since December 2023... but it's still an issue (port 22 is still opened on my GigaHub. Is Bell listening? Any opened port is a security risk. Bell, when are you going to fix this?

Vanadiel
Community All-Star
Community All-Star

How are you scanning for the open port?

I am a Community All-Star and customer. I'm here to help by sharing my knowledge and experience. My views on Bell and the Community Forum are my own and not the views of Bell or any of its affiliates.