Live data from Hacker News

VPN users unmasked by zero-day vulnerability in Virgin Media routers

portswigger.net

11–20 of 97 posts

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#11

Earlier quoted context omitted.

I think generally you don't get a choice when it comes to DOCSIS equipment. You can't just connect up your own (or at least no to Virgin Media's network)

You can take those routers and use it as a modem only. Then put your own router in front of it.

Which then burdens you with a double NAT which shouldn't ever be necessary if the industry had their shit together.

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#12

Earlier quoted context omitted.

You can take those routers and use it as a modem only. Then put your own router in front of it.

Which then burdens you with a double NAT which shouldn't ever be necessary if the industry had their shit together.

No you don't. In modem mode the VM routers only issue a single IP (the internet facing IP) over DHCP to a single host (your router)

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#13
For context. This is Virgin Media which demands your passwords (including e-mail passwords) must be no longer than 10 characters, must begin with a letter, not a number and cannot include any special characters.

Security is not their priority.

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#15

For context. This is Virgin Media which demands your passwords (including e-mail passwords) must be no longer than 10 characters, must begin with a letter, not a number and cannot include any special characters. Security is not their priority.

The same Virgin Media of "Posting it to you is secure, as it's illegal to open someone else's mail." infamy.... [0]

[0] https://twitter.com/virginmedia/status/1162756227132198914?l...

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#16
post #14
post #5

This appears to use API endpoints that are available if the modem is in ISP mode and acting as the Wi-Fi, etc. Does this also affect the router when used in modem mode?

How is this not prevented by same origin policy etc?

Since they mention a DNS rebinding attack, I would assume the victim visits or is redirected to attacker.com. This then has all the JS to talk to the unsecured router API endpoints. Now after a few seconds the attacker.com's IP address is switched to 192.168.0.1 (or whatever the routers default IP is) and zap: the SOP is circumvented.

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#17

Earlier quoted context omitted.

You can take those routers and use it as a modem only. Then put your own router in front of it.

It's still not really modem-only mode. They do routing in there, mainly for their management layer.

I must admit, I don’t know much about networking. But do you have some more information there? My German cable router is in modem-mode, and I’d be interested in knowing what kind of routing it still does.

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#18
post #12

Earlier quoted context omitted.

Which then burdens you with a double NAT which shouldn't ever be necessary if the industry had their shit together.

No you don't. In modem mode the VM routers only issue a single IP (the internet facing IP) over DHCP to a single host (your router)

Fwiw not all modems support this (and some do but the ISPs disable it).

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#19
post #15

For context. This is Virgin Media which demands your passwords (including e-mail passwords) must be no longer than 10 characters, must begin with a letter, not a number and cannot include any special characters. Security is not their priority.

The same Virgin Media of "Posting it to you is secure, as it's illegal to open someone else's mail." infamy.... [0] [0] https://twitter.com/virginmedia/status/1162756227132198914?l...

Wow, that's just spectacular!

Quick! Let's outlaw poverty, violence, theft and coercion, and we're good!

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#20
post #2

Nobody should use ISP provided equipment for anything security sensitive, ever. ISPs don't care about security at all, aside from "security" as a sales term, and aside from when they're getting a bad name because of egregious failures. ARRIS shouldn't be given a year embargo, either. They're the same company who've known since 2016 about hardware issues which cannot be corrected in software in the Intel PUMA chipsets…

Yeah, avoid ARRIS whenever you can. Their modems make cable internet a dreadful experience, which it shouldn't have been.

Here's the list with modems affected by the hardware bug you mentioned: https://www.badmodems.com/

Post reply on HN