About adding a static route to my DOCSIS modem
blog.danman.eu
blog.danman.eu
I do all my routing on my router. The cable modem is just the box that turns the square cable into the round cable.
At least in those two cases (different ISPs), it’s possible to turn the device into bridging mode
It seems like the integration of both networks is quite a task and the bridge-mode feature is not a priority. How the bridge-mode is affected by the network backbone is unclear to me. IPv6 delegation also does not work for me.
This is tricky, because "telecom" only has POTS and cable TV within its scope. "Internet" service that just uses ethernet technologies are their own separate thing, and why "Ma Bell" megacorps can get away with their junk Internet service because it's regulated differently than POTS.
In the EU, the Directive 2015/2120 [1] enforces the ability of customers to bring their own modems, no matter if you are running fiber, xDSL or DOCSIS.
[1]: https://eur-lex.europa.eu/legal-content/DE/TXT/?uri=celex%3A...
[1]: https://www.teltarif.de/zwang-zum-router-trotz-routerfreihei...
But other coment is right. They have to allow you use your device.
Bothers me none of my modems have ever had the option to turn off WAN-side flashing, never know who is going to figure out how to take advantage of that.
It still would be easier to just put it into bridge mode if that's an option and use a better router, it is still an interesting hacking project!
Cable modems in general don't seem to really make much of an attempt at physical-access security, even though they rely on being "secure from the owner" to enforce ISP bandwidth limits. Back when I was on cable, my cable router didn't have an official bridge mode, but there was a way to get telnet by uncommenting a hidden settings field in the HTML (lol) and then you could use an undocumented command to enable it. Later, the ISP broke this in an update, possibly inadvertently: bridge mode was still there, but enabling it caused some process to crashloop and destroyed performance. I got tired of that nonsense, found an old firmware image, and directly flashed it to the SPI flash chip on the board (except I left the version metadata as the higher one, so it wouldn't try to update itself again). Worked fine until I moved out of that place and stopped using cable. The DOCSIS cert and private key were right there in the flash too, I'm pretty sure I still have a backup somewhere.
The funny thing is that you can use this method to illegaly increase your internet speed, since it is limited by the modem, not by the ISP's equipment.
No way. I wonder if this works with ADSL modems. That's absolutely insane.
So one of the reasons why its set by the cabinet is they charge different fees for different connection speeds.
So in the UK if you are limited to say a 40Mb or 80Mb download and whatever upload, when your adsl router/modem connects or negotiates a speed (max DSLAM throughput), even if you could negotiate a 100Mb speed, you would be throttled to whatever you package speed is and then with things like TR069 (https://en.wikipedia.org/wiki/TR-069) they can remote control your router. So that will include disconnecting your ADSL connection, reconnecting and giving you a new IP address if you dont pay for a fixed ip address. One ISP I tested could reset the connection and give you new IP address every second, it was literally as quick as the device could handle getting the new ip address in bridge mode.
Some firewall products also do throttling, its part of what is called traffic shaping as explained here (some reasonable docs) https://forum.netgate.com/topic/20089/how-to-using-squid-for... Traffic Shaping in general https://docs.netgate.com/pfsense/en/latest/trafficshaper/lim...
AFAIK the adls cabinets also have a separate RF communication channel possibly as an independent backup if the mainlines go down but power still remains. I know if the engineers so much as opens the door to a cabinet, it phones home possibly over the RF or maybe using both network and RF, havent established that yet, but things are quite joined up here from what I've been able to tell.
Other factors will which affect the DSL speed are the stability settings, so do you have little to no interference and error checking for max speed or do you go cautious and have lots of interference mitigation enabled on the adsl modem/router. Think of adsl as loads of radio stations all transmitting down a wire, to get more speed you tune into and listen to more radio stations all at the same time. For slower speeds you tune into just a couple radio stations. The frequency of the "radio" station also counts, like listening to poor radio quality on Long wave which can bounce around the planet, Medium Wave which can cover a sizable area or Frequency Modulation which you need to be close by to get. Same as mobile phone 2G, 3G, 4G & 5G. The bubble or area of 2G is massive, where as 5G is tiny, but that tiny bubble can transmit alot unlike 2G which is slower. Same sort of concept just transmitted & contained down a wire instead of over the air.
One reason hard coding the route in the modem is it can prevent random accesses to the GUI from malware in the computer or in other network devices and then other network security can come into play.
There's a lot of info in this post, and will be similar and thus relevant for hacking other devices.
For cable modems, the modem runs the ISP's firmware which downloads runtime parameters from the ISP. The supported modem list is modem's they have firmware for that run on their network
Afaik it's not very difficult for the ISP to detect modified modems
In the same vein it's also trivial to hack many IPTV boxes used by fiber/DSL providers to give you free shows and channels because they essentially filter out the options you can click on on the client side rather than do any server side validation. There was a somewhat prolific subforum on a Dutch tech forum that tried to get into customising ISP IPTV boxes (didn't even need to alter the firmware, just needed to mess around with some JSON in transit) but that got cease-and-desisted because the method people used to alter themes could just as easily unlock most paid content.
Sometimes it really does look like TV related ISPs are still living in the 90s when it comes to security boundaries.
With DOCSIS, though, there's frequency/time block negotiation going on that a central node needs to confirm.
A modem getting 1000mbps down on a 100mbps subscription should not be possible by simply flashing the modem with different firmware.
This problem has been solved for LTE and other wireless standards, there's no reason why DOCSIS should stick to this old design in their new iterations.
If someone gets free bandwidth or free TV shows, nothing is really lost in the process. It isn't like having your car stolen.
I used to run my own PCI DSL modem (read: router) on a Soekris. Sanoma S518 was ADSL1 only and difficult to get working FOSS drivers for (IIRC didn't work on *BSD). Sanoma S519 worked for ADSL2, but used a RTL8139 externally while it ran proprietary firmware for the DSL part. I ditched it when I got VDSL(2). Later on, I found a Draytek Vigor (IIRC with the numbers 130 or 132 in it) which did work with VDSL but I already gave up and ran a Fritz!box instead. Which used to be hackable, in the sense that you could get root on it, and mod it ('Freetz').