Live data from Hacker News

RCE on Telia Routers

full-disclosure.eu

21–30 of 51 posts

Re: RCE on Telia Routers

#21
post #8

Earlier quoted context omitted.

Do you have the self service thing in Sweden? Granted I’m not a telia customer here in FIN, but have never seen this kind of functionality on my own home routers. Plain router admin always.

I couldn't find it on the web site, but I found something similar here: https://apps.apple.com/se/app/telia-smart-wifi/id1459248896 https://play.google.com/store/apps/details?id=com.teliacompa... They allow login with BankID (Swedish authentication system using Personal Identity Number) or a Telia login, implying I don't need the admin password printed on the back of the router so it ought to use the same type of bac…

Well, it is risky hiring workers in Sweden.. if you don’t need them anymore it’s difficult to get rid of them!

Re: RCE on Telia Routers

#22
post #4

Telia is just horrible. I use them because I have no other option where I live, which is very unusual in Sweden. Their support is absolute horse shit. You can't get a static ip unless you have a company and it regularly goes down for hours. If you login on your account on their homepage you get this popup 1 time each day: https://imgur.com/Y0Gx8EY Where they utilize a dark pattern to make users check the boxes and ha…

Oh, and they sold data about torrent users. That's right. A Swedish ISP selling personally identifiable information. Not giving it out because of a court order. I have steered many people away from them over the years. They would have to have at least a decade of good behaviour and a sun shining out of their ass before I would pick them.

Who are the better alternatives in Sweden ?

Re: RCE on Telia Routers

#23
post #8

Earlier quoted context omitted.

Do you have the self service thing in Sweden? Granted I’m not a telia customer here in FIN, but have never seen this kind of functionality on my own home routers. Plain router admin always.

Telia routers in Sweden can be managed remotely from Telias web page. I don't mean port forward, but some other channel talk between admin tool on their website and the router. (You can also connect locally on the LAN and admin the router that way.) Tangentially related Swedish bork: https://medium.com/@rikardhjort/2-7-medical-calls-breached-i...

It's the same with Telia Estonia.

And they use dropbear to connect to the router to do changes from remote/customer service/online customer portal, if you're curious (you can see it in logs of the router, Inteno ones)

Re: RCE on Telia Routers

#24
post #16
post #5

So this issue affects Telia Lithuania clients. But I wouldn't be surprised if the same (or similar) issue affects clients in Sweden. The article mentions a leaked password hash from 2014, but as far as I know, there were at least 3 password (not hash!) leaks over the last 10 years. Generally, I recommend people buy their own routers and never use the "Self Service" for managing passwords. As for hostility of service…

> I personally know at least 5 exploitable vulnerabilities in some government websites, but I won't be disclosing them, since that will land me in a lot of trouble. Thats what full disclosure is for. Drop the vuln somewhere via Tor, maybe point someone there via some anonymous comunique. Et voila, you made the world a safer and better place. Imho sitting on vulnerabilities is immoral as long as anonymous full disclos…

This might be dangerous if you initially planned to disclose responsibly and did the research/testing of the vulnerability without anonymization. In that case if you were to release the vulnerability anonymously and it wasn't exploited before they could still figure out that you did it by examining the logs and finding your early non-anonymous attempts.

Re: RCE on Telia Routers

#25
post #4

Earlier quoted context omitted.

Oh, and they sold data about torrent users. That's right. A Swedish ISP selling personally identifiable information. Not giving it out because of a court order. I have steered many people away from them over the years. They would have to have at least a decade of good behaviour and a sun shining out of their ass before I would pick them.

Who are the better alternatives in Sweden ?

Bahnhof is usually suggested as they seem to be more privacy friendly.

Re: RCE on Telia Routers

#26
post #5

So this issue affects Telia Lithuania clients. But I wouldn't be surprised if the same (or similar) issue affects clients in Sweden. The article mentions a leaked password hash from 2014, but as far as I know, there were at least 3 password (not hash!) leaks over the last 10 years. Generally, I recommend people buy their own routers and never use the "Self Service" for managing passwords. As for hostility of service…

Observation: You're using the same kind of approach as the "I almost found a vulnerability" and "but I won't be disclosing them, since that will land me in a lot of trouble" as the submitted post does.

Re: RCE on Telia Routers

#28
post #16

Earlier quoted context omitted.

> I personally know at least 5 exploitable vulnerabilities in some government websites, but I won't be disclosing them, since that will land me in a lot of trouble. Thats what full disclosure is for. Drop the vuln somewhere via Tor, maybe point someone there via some anonymous comunique. Et voila, you made the world a safer and better place. Imho sitting on vulnerabilities is immoral as long as anonymous full disclos…

This might be dangerous if you initially planned to disclose responsibly and did the research/testing of the vulnerability without anonymization. In that case if you were to release the vulnerability anonymously and it wasn't exploited before they could still figure out that you did it by examining the logs and finding your early non-anonymous attempts.

Right, and there's no possibility to do research/testing anonymously anyway. You use your personal e-Signature/ID card to logon to government sites, your logon is always tied to you.

Re: RCE on Telia Routers

#29
post #21

Earlier quoted context omitted.

I couldn't find it on the web site, but I found something similar here: https://apps.apple.com/se/app/telia-smart-wifi/id1459248896 https://play.google.com/store/apps/details?id=com.teliacompa... They allow login with BankID (Swedish authentication system using Personal Identity Number) or a Telia login, implying I don't need the admin password printed on the back of the router so it ought to use the same type of bac…

Well, it is risky hiring workers in Sweden.. if you don’t need them anymore it’s difficult to get rid of them!

This is just plain wrong. There are many ways to handle such a situation. One would be "visstidsanställning" which is employment for a pre-determined period.

Re: RCE on Telia Routers

#30
post #5

So this issue affects Telia Lithuania clients. But I wouldn't be surprised if the same (or similar) issue affects clients in Sweden. The article mentions a leaked password hash from 2014, but as far as I know, there were at least 3 password (not hash!) leaks over the last 10 years. Generally, I recommend people buy their own routers and never use the "Self Service" for managing passwords. As for hostility of service…

>>> I personally know at least 5 exploitable vulnerabilities in some government websites, but I won't be disclosing them, since that will land me in a lot of trouble.

I can tell you from experience, the only way to reliably get a vulnerability fixed is to publish on Twitter.

Of course if you've got vulnerabilities in government sites and power plants, you may prefer to not disclose to twitter to avoid harm to the public. Sitting on vulnerabilities in the absence of alternative is a perfectly ethical and reasonable choice.

Post reply on HN