Live data from Hacker News

Linksys CherryBlossom Advisory

linksys.com

41–46 of 46 posts

Re: Linksys CherryBlossom Advisory

#41
post #32

Earlier quoted context omitted.

Linksys security guy here - we got that firmware update tidbit from the cherryblossom documentation. The firmware implant (aka flytrap) reproduces all of the router's normal functionality. On page 122 of the cherryblossom docs, it says that the firmware upgrade feature is implemented normally by the flytrap, and that if a user attempts to upgrade their router's firmware, it will overwrite the flytrap firmware.

On the basis that most linksys owners never touch or upgrade their firmware, why aren't linksys (and other manufacturers) products shipped with a physical hardware 'read-only' switch for the firmware to prevent unauthorised remote upgrades?

That makes entirely too much sense. They already have the hardware in the form of the WPS button which no one uses.

Re: Linksys CherryBlossom Advisory

#42
post #33
post #27

Earlier quoted context omitted.

You can disable management via the WAN port and/or wi-fi if you put OpenWRT on them.

There should have never been management access enabled by default via WAN or WLAN on ANY router to be honest. In a misguided effort to make their consumer devices more 'friendly'[1] they've just made them more insecure. -- [1] Even though most users have no idea the management interface even exists.

It's a tough call. The comms companies who provide my router provide millions of them. They want ACS/TR-069 by default and use it for automated updates.

I always disable it, but I'll bet I'm something like 1:10k in that respect.

Re: Linksys CherryBlossom Advisory

#43
post #16

Isn't this a lie though? They do not mention remote compromise and I would bet dollars to doughnuts most old routers have RCE holes.

There were no vulnerabilities included in the cherryblossom leak. If you have any information about RCEs, Cherryblossom details we may have missed, or any other vulnerabilities in Linksys devices, please email me directly at benjamin.samuels at belkin.com

"This customized firmware can be loaded onto a router using one of the following methods:"

If I understood things correctly, the Cherryblossom thing is a firmware and while this particular leak didn't mention any new RCEs I am surprised a bit that the possibility of using any other RCE was categorically ruled out by the wording of the advisory.

Re: Linksys CherryBlossom Advisory

#44
post #7

> If users believe their router firmware may have been compromised, What would make them believe that? Wish they had a detection tool as well. Anyone know of one?

I wonder if there are easy way to dump the firmware and do a sign / hash check on another machine

Not really. Devices like consumer routers just weren't designed with these things in mind unfortunately.

Re: Linksys CherryBlossom Advisory

#45

Earlier quoted context omitted.

I wonder if there are easy way to dump the firmware and do a sign / hash check on another machine

Not really. Devices like consumer routers just weren't designed with these things in mind unfortunately.

Not even with some jtag line ?

Re: Linksys CherryBlossom Advisory

#46

Earlier quoted context omitted.

Not really. Devices like consumer routers just weren't designed with these things in mind unfortunately.

Not even with some jtag line ?

Sorry I thought you meant an easy way. You could with a jtag interface, but even then the filesystem would have been modified from normal operation so the image of the firmware you dumped would have a different hash than the stock image. You could extract the filesystem and check the binaries and poke around for thing that shouldn't be there, but all this isn't exactly something the average person could do to see if they were infected. If you have the equipment and expertise definitely. Honestly these companies need to step up their game and just make better products in my opinion. It's not like the technology isn't available.
Post reply on HN