Live data from Hacker News

RCE on Telia Routers

full-disclosure.eu

11–20 of 51 posts

Re: RCE on Telia Routers

#11
post #8
post #5

So this issue affects Telia Lithuania clients. But I wouldn't be surprised if the same (or similar) issue affects clients in Sweden. The article mentions a leaked password hash from 2014, but as far as I know, there were at least 3 password (not hash!) leaks over the last 10 years. Generally, I recommend people buy their own routers and never use the "Self Service" for managing passwords. As for hostility of service…

Do you have the self service thing in Sweden? Granted I’m not a telia customer here in FIN, but have never seen this kind of functionality on my own home routers. Plain router admin always.

Telia routers in Sweden can be managed remotely from Telias web page. I don't mean port forward, but some other channel talk between admin tool on their website and the router. (You can also connect locally on the LAN and admin the router that way.)

Tangentially related Swedish bork:

https://medium.com/@rikardhjort/2-7-medical-calls-breached-i...

Re: RCE on Telia Routers

#12
post #8
post #5

So this issue affects Telia Lithuania clients. But I wouldn't be surprised if the same (or similar) issue affects clients in Sweden. The article mentions a leaked password hash from 2014, but as far as I know, there were at least 3 password (not hash!) leaks over the last 10 years. Generally, I recommend people buy their own routers and never use the "Self Service" for managing passwords. As for hostility of service…

Do you have the self service thing in Sweden? Granted I’m not a telia customer here in FIN, but have never seen this kind of functionality on my own home routers. Plain router admin always.

I couldn't find it on the web site, but I found something similar here:

https://apps.apple.com/se/app/telia-smart-wifi/id1459248896

https://play.google.com/store/apps/details?id=com.teliacompa...

They allow login with BankID (Swedish authentication system using Personal Identity Number) or a Telia login, implying I don't need the admin password printed on the back of the router so it ought to use the same type of backdoor I'd expect support personal has and the Lithuanian web site has.

Judging by the comments of both apps though, it seems it doesn't work at all... maybe they need to add more than 5 PHP workers.

Re: RCE on Telia Routers

#13
post #10

I really don't get the "Using malicious SSH server to trigger server side RCE" section. The language would do well with being a bit more clear wrt exactly which client and which server, and exactly where the RCE is happening. > In order to exploit RCE we needed to build a virtual test environment that fully copies Telia's PHP client. Step by step we have gone through the sequence of Telia's commands sent over the SSH…

I think they ran their own SSH server on the router for the SSH connect-back from Telia's server. SSH password auth sends the password to the server [router here]. This is encrypted over the network, but the server [router] decrypts it, so then you have that password, shared between all the routers. I'm not sure if libssh being vulnerable was relevant to their attack or not, perhaps that's just an aside, given they physically own the router anyway.

SSH pubkey auth would have avoided the problem I guess. Not sure if it would have helped their attitude though.

Re: RCE on Telia Routers

#14
post #10

I really don't get the "Using malicious SSH server to trigger server side RCE" section. The language would do well with being a bit more clear wrt exactly which client and which server, and exactly where the RCE is happening. > In order to exploit RCE we needed to build a virtual test environment that fully copies Telia's PHP client. Step by step we have gone through the sequence of Telia's commands sent over the SSH…

> Perhaps their high-level thought process is like this?

Yes, I think you're right and it was difficult to understand. The thinking is that, as you can trigger Telia servers to connect to you, using software which appears past its expiration date, you may be able to exploit that software to root their command and control server. Do that and you own Telias whole botnet of customers.

Re: RCE on Telia Routers

#15
post #10

I really don't get the "Using malicious SSH server to trigger server side RCE" section. The language would do well with being a bit more clear wrt exactly which client and which server, and exactly where the RCE is happening. > In order to exploit RCE we needed to build a virtual test environment that fully copies Telia's PHP client. Step by step we have gone through the sequence of Telia's commands sent over the SSH…

> Perhaps their high-level thought process is like this? Yes, I think you're right and it was difficult to understand. The thinking is that, as you can trigger Telia servers to connect to you, using software which appears past its expiration date, you may be able to exploit that software to root their command and control server. Do that and you own Telias whole botnet of customers.

Strictly speaking they didn't show that two separate consumer routers have the same remote management password.

Re: RCE on Telia Routers

#16
post #5

So this issue affects Telia Lithuania clients. But I wouldn't be surprised if the same (or similar) issue affects clients in Sweden. The article mentions a leaked password hash from 2014, but as far as I know, there were at least 3 password (not hash!) leaks over the last 10 years. Generally, I recommend people buy their own routers and never use the "Self Service" for managing passwords. As for hostility of service…

> I personally know at least 5 exploitable vulnerabilities in some government websites, but I won't be disclosing them, since that will land me in a lot of trouble.

Thats what full disclosure is for. Drop the vuln somewhere via Tor, maybe point someone there via some anonymous comunique. Et voila, you made the world a safer and better place.

Imho sitting on vulnerabilities is immoral as long as anonymous full disclosure is possible.

Re: RCE on Telia Routers

#17
post #4

Telia is just horrible. I use them because I have no other option where I live, which is very unusual in Sweden. Their support is absolute horse shit. You can't get a static ip unless you have a company and it regularly goes down for hours. If you login on your account on their homepage you get this popup 1 time each day: https://imgur.com/Y0Gx8EY Where they utilize a dark pattern to make users check the boxes and ha…

Oh, and they sold data about torrent users. That's right. A Swedish ISP selling personally identifiable information. Not giving it out because of a court order. I have steered many people away from them over the years. They would have to have at least a decade of good behaviour and a sun shining out of their ass before I would pick them.

> Oh, and they sold data about torrent users. That's right. A Swedish ISP selling personally identifiable information. Not giving it out because of a court order.

Very interesting, can you please say more or point to somewhere? I couldn't parse if the last sentence was about you or Telia.

Re: RCE on Telia Routers

#18
post #15

Earlier quoted context omitted.

> Perhaps their high-level thought process is like this? Yes, I think you're right and it was difficult to understand. The thinking is that, as you can trigger Telia servers to connect to you, using software which appears past its expiration date, you may be able to exploit that software to root their command and control server. Do that and you own Telias whole botnet of customers.

Strictly speaking they didn't show that two separate consumer routers have the same remote management password.

They didn't show it but they did say the old routers share the same password. I can take that at face value, it's easy enough for a Lithuanian researcher to verify by asking a friend, I assume they did.

They say later models allow only pub keys but didn't go into more details. I would assume they all have the same keys in firmware if not shown otherwise.

Either way, the Telia CnC server would know all unique (if so) passwords or keys, so it may make little difference if exploited.

Re: RCE on Telia Routers

#19
post #9
post #5

So this issue affects Telia Lithuania clients. But I wouldn't be surprised if the same (or similar) issue affects clients in Sweden. The article mentions a leaked password hash from 2014, but as far as I know, there were at least 3 password (not hash!) leaks over the last 10 years. Generally, I recommend people buy their own routers and never use the "Self Service" for managing passwords. As for hostility of service…

Would the ability to anonymously disclose vulnerabilities help? I fear that disclosures like that would just be ignored, though.

What one should do is to involve the www.NKSC.lt - Nation Cyber Security Center. They have a form to submit vulnerabilities

I did send a few reports from throwaway email accounts, but the issues did not get resolved.

I suspect there's another way to go about it - if you're a Telia customer - send them GDPR Article 33 request.

Re: RCE on Telia Routers

#20
post #15

Earlier quoted context omitted.

Strictly speaking they didn't show that two separate consumer routers have the same remote management password.

They didn't show it but they did say the old routers share the same password. I can take that at face value, it's easy enough for a Lithuanian researcher to verify by asking a friend, I assume they did. They say later models allow only pub keys but didn't go into more details. I would assume they all have the same keys in firmware if not shown otherwise. Either way, the Telia CnC server would know all unique (if so)…

> but they did say the old routers share the same password

Ah, missed that.

Post reply on HN