The "Gringo"

Around that time, in about 2005, internet access had gone from dial-up to what we called broadband. That basically meant we no longer had to tie up a phone line and dial a number to access the internet. The same line could be used for phone calls while, at the same time, maintaining a permanent connection to the network. Speeds went up and we started to use the internet more and more. The arrival of broadband also enabled video streaming (low quality, at first) and downloading larger files.
Along with the proliferation of always-on internet connections came a greater risk of attacks targeting the equipment installed in people’s homes. In general, computers were not kept on all the time, but there was at least a broadband modem that stayed on 24/7. That made it an interesting target. A common attack pattern at the time involved gaining access to the modem’s admin interface and changing its configuration, affecting all the computers connected to that network. The attacker could then modify the modem’s DNS settings, making all devices on the network use a server under their control, allowing them to redirect connections to fake sites used to commit fraud, identity theft, and other kinds of scams.
Since our main client was Brasil Telecom, the company was always trying to identify new projects with them. When we discussed the issue of ADSL modems, it became clear that there was a huge variety of models in use and that Brasil Telecom did not always keep an inventory of which model was installed at each residence. Most of the time, the customer used the modem supplied by the ISP itself, but this was not always properly recorded. It was also possible to buy a modem on your own and replace the ISP-provided equipment.
Beyond the lack of control over which modem was in use, there was no centralized management of these modems’ configurations. Normally, the user or an installation technician did a basic setup and left the equipment running. That meant many modems were left with default passwords and with the admin interface exposed to the internet. All it took was for someone to know the default password of that model to access and change the configuration from anywhere in the world. It is not hard to imagine how this became a constant source of attacks and problems for the telcos.
The project we designed consisted of running a scan from inside Brasil Telecom’s network to identify the model of the modem used on each broadband connection. It was a huge customer base, so the work needed to be automated as much as possible. Since it was not possible to cover every model on the market, we limited the scope to about ten models supplied by the operator itself.
The first challenge was to find a way to identify the model used on each connection. We used Nmap and began developing specific signatures to recognize each of those modems. We had access to a lab with all the equipment used by Brasil Telecom, where we ran the initial tests. After validation by their technical team, our system was put into operation in the production network. With the collected data, we identified not only the model used in most of the telco’s ADSL connections, but also which devices had the admin interface accessible from the internet. Our part of the project ended there: fixing or reconfiguring the modems was not in scope — that was their technical team’s responsibility. It was a really great project to work on: fun, challenging, and a great learning experience. And we delivered everything that was planned.
Another story from that time was both funny and a little sad. The company was trying to become a reseller of SIEM software, that is, a security information and event management tool. They had managed to schedule a presentation at Serpro, which is huge and always a major buyer. Closing a contract there would be a major win for a small company, still early in its journey.
With the meeting scheduled, they managed to bring an engineer over from the United States to demo the product. He arrived in Brasília the day before, and we had dinner to get to know him and talk a bit about the next day’s meeting. Since I was the most senior technical person in Brasília at the time, I was invited to dinner along with one of the partners, who handled the commercial side. During the conversation, the American asked basic questions: what the company did, how big the team was, where the offices were, and so on. When he asked about the number of employees, the partner said we were 45 people. In practice, we must have been about 15, at most. It was a blatant lie, but I was there just as a bystander and did not get into the conversation. We wrapped up dinner, dropped the American off at the hotel, and I headed home.
The next morning, I was on my way to Brasil Telecom as usual when the phone rang. It was the same partner from dinner. He was clearly nervous and told me to change my route and go immediately to Serpro. He asked if I knew the SIEM product well. I answered truthfully: not very well. He then let out one of his typical lines: “You will have half an hour to learn everything, because the gringo is not doing well and is not going to make it to the meeting.” I went to Serpro, presented the American’s slides, and tried to answer the questions as best I could. In most cases, the answer was that we would check with the specialists in the United States and get back to them later. That was all we could do.
Later, I was told what happened. According to the partner, in the morning, when he went to pick up the American at the hotel, the gringo did not answer the phone. The partner then went up to his room, knocked on the door, and found him really sick. It got to the point where he had to go to the pharmacy to buy medicine to see if the American would feel better, but he was clearly unable to give a presentation. He said the hotel receptionists had mentioned that the American had arrived the night before with two women and had probably overdone the partying. He had apparently gone to a nightclub and tried to “score in Brazil.”
Whether he scored or not, I don’t know. What I know is that I lost: I had to give a presentation to a huge client without the slightest knowledge of the product I was presenting. And this was not the last time this kind of story crossed my path. Make a note of it, because it will come back later.