Live data from Hacker News

RCE on Telia Routers

full-disclosure.eu

31–40 of 51 posts

Re: RCE on Telia Routers

#31
Wow. It's a complete tragic comedy.

> And, yes, it turns out that Telia's client does not attempt to verify the remote server's [customer's router] public key ...and then... Using malicious SSH server to trigger server side RCE !!

> First, Telia did not have a PGP key and did not know how to use it, so instead they asked us to ZIP the report with password and send the password over a separate email (private GMail). I hope Telia's engineers will be reading this article, so I would like to explain why the report should be encrypted. !!

> Thank you for the information. We will continue to check whether you made your report legally without violating any law. And we will ensure that no fake information will be published that could do any harm to the company's reputation and to the critical part of Lithuanian network infrastructure. !!

> And finally, we found that the hash was cracked and was available in the old "weakpass" database !!

Re: RCE on Telia Routers

#32
post #26
post #5

So this issue affects Telia Lithuania clients. But I wouldn't be surprised if the same (or similar) issue affects clients in Sweden. The article mentions a leaked password hash from 2014, but as far as I know, there were at least 3 password (not hash!) leaks over the last 10 years. Generally, I recommend people buy their own routers and never use the "Self Service" for managing passwords. As for hostility of service…

Observation: You're using the same kind of approach as the "I almost found a vulnerability" and "but I won't be disclosing them, since that will land me in a lot of trouble" as the submitted post does.

You're absolutely correct. And I completely understand the author's point of view.

By disclosing the vulnerability, I'd be taking a risk of a criminal investigation. This is not a joke. This has already happened at least once in Lithuania.

I have a job, one that has nothing to do with infosec, but I'd be risking that job if I had an ongoing criminal investigation.

Re: RCE on Telia Routers

#33
I've known their `ladmin` password for a looong while - it was available online at least since 2015. And as far as I'm aware - the same password was used for multiple Telia routers' models (ADB-branded ones) - not just a single model.

There also was a user called `tadmin`, but I wasn't able to figure out the password for that one.

Re: RCE on Telia Routers

#34
post #32
post #26

Earlier quoted context omitted.

Observation: You're using the same kind of approach as the "I almost found a vulnerability" and "but I won't be disclosing them, since that will land me in a lot of trouble" as the submitted post does.

You're absolutely correct. And I completely understand the author's point of view. By disclosing the vulnerability, I'd be taking a risk of a criminal investigation. This is not a joke. This has already happened at least once in Lithuania. I have a job, one that has nothing to do with infosec, but I'd be risking that job if I had an ongoing criminal investigation.

[deleted]

Re: RCE on Telia Routers

#35
Doesn't surprise me. Spectrum has the same thing here in the US. All their devices have telnet or SSH or web access on an internal VLAN, with weak passwords like "T!m3W4rn3rC4bl3" (I'm not joking). A list of passwords was readily accessible to, at least, all SMB customer support technicians in the old TWC areas as of a few years ago.

Re: RCE on Telia Routers

#36
It's exceedingly likely that other ISPs do this exact same thing. I've always, always used my own router and, when possible, my own modem.

Even if it's not a glaring security hole like this one, using the ISP's router makes it easier for them to monitor you and serve you ads using "DNS assistance"-type programs. And most of the time you pay them for it with an extra $5-$10 on your monthly bill!

Re: RCE on Telia Routers

#37
post #28

Earlier quoted context omitted.

This might be dangerous if you initially planned to disclose responsibly and did the research/testing of the vulnerability without anonymization. In that case if you were to release the vulnerability anonymously and it wasn't exploited before they could still figure out that you did it by examining the logs and finding your early non-anonymous attempts.

Right, and there's no possibility to do research/testing anonymously anyway. You use your personal e-Signature/ID card to logon to government sites, your logon is always tied to you.

It's possible that the programmers who built the system are really bad at security and really good at audit logging but I doubt it. Personally I would take the risk but I understand why others might not want to.

Re: RCE on Telia Routers

#38

Telia is just horrible. I use them because I have no other option where I live, which is very unusual in Sweden. Their support is absolute horse shit. You can't get a static ip unless you have a company and it regularly goes down for hours. If you login on your account on their homepage you get this popup 1 time each day: https://imgur.com/Y0Gx8EY Where they utilize a dark pattern to make users check the boxes and ha…

That's pretty interesting, because in my experience [1] Telia is by far the best ISP in Estonia. However this is historically the government ISP that Telia purchased, so some of the culture might still be rather different.

To contrast with your experience, I've never had issues with the support, private customers can get static IPs just fine, and my fiber connection and router has uptime measured in years.

Also compared to other local ISPs, the Telia global peering is unmatched. Latency is consistently lower and connections to exotic countries still achieve high bandwidth.

--

[1] I've been a Telia client for over 20 years now at four different locations.

Re: RCE on Telia Routers

#39
post #29
post #21

Earlier quoted context omitted.

Well, it is risky hiring workers in Sweden.. if you don’t need them anymore it’s difficult to get rid of them!

This is just plain wrong. There are many ways to handle such a situation. One would be "visstidsanställning" which is employment for a pre-determined period.

Sure, you can work around the labour laws in many ways, but he is likely referring to a normal full time employment contract as most people do when they talk about employment.

And he's not wrong in the figurative way, the labour laws are quite strict and the unions are in an impossibly strong standing in Sweden.

Re: RCE on Telia Routers

#40
post #5

So this issue affects Telia Lithuania clients. But I wouldn't be surprised if the same (or similar) issue affects clients in Sweden. The article mentions a leaked password hash from 2014, but as far as I know, there were at least 3 password (not hash!) leaks over the last 10 years. Generally, I recommend people buy their own routers and never use the "Self Service" for managing passwords. As for hostility of service…

That's very irresponsible of you. You just said that someone could read someone elses medical data and there you are sitting on similar vulnerabilities out of principle. Shame.

I know first hand that such big telcos are slow and bureaucratic. But they still need help and patience. They do after all have all the important government contracts.

Post reply on HN