Live data from Hacker News

VPN users unmasked by zero-day vulnerability in Virgin Media routers

portswigger.net

31–40 of 97 posts

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#31

For context. This is Virgin Media which demands your passwords (including e-mail passwords) must be no longer than 10 characters, must begin with a letter, not a number and cannot include any special characters. Security is not their priority.

They also ask for your account password over the phone

I think they now only ask for the X, Y, and Zth characters, but they used to ask for the whole thing

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#32
post #30

Earlier quoted context omitted.

Correct, but in this case, it sounds like you didn't need to use the ISP router as your VPN gateway. If I understand the DNS rebinding attack reference correctly, you could be running the VPN software on your desktop/laptop and still have your IP revealed by your ISP router.

Arguably, a setup using a VPN for anonymity purposes is badly flawed if it allows traffic to anything but the VPN gateway. This includes the local network. Mediocre home appliances or (as in this case) ISP CPEs can easily deanonymize you.

Yes, but you do want deliberate access to specific services on the local network. Mainly NFS exports and the like.

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#33
post #2

Nobody should use ISP provided equipment for anything security sensitive, ever. ISPs don't care about security at all, aside from "security" as a sales term, and aside from when they're getting a bad name because of egregious failures. ARRIS shouldn't be given a year embargo, either. They're the same company who've known since 2016 about hardware issues which cannot be corrected in software in the Intel PUMA chipsets…

I think generally you don't get a choice when it comes to DOCSIS equipment. You can't just connect up your own (or at least no to Virgin Media's network)

This is one of the few positives I'll give to Comcast/Xfinity. I'm able to purchase my own DOCSIS modem (as long as it's on their compatibility list) instead of renting one from them.

AT&T U-verse I couldn't bring my own modem, and I understand that they're not a DOCSIS network either.

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#34
So all the while, for almost two years, Virgin didn't do squat about this. Gives me flashbacks to some of our disclosure interactions with PayPal and others.

Wonder why issues like this are so common - do they just de-prioritize vulnerabilities reported by researchers to death?

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#35
post #15

For context. This is Virgin Media which demands your passwords (including e-mail passwords) must be no longer than 10 characters, must begin with a letter, not a number and cannot include any special characters. Security is not their priority.

The same Virgin Media of "Posting it to you is secure, as it's illegal to open someone else's mail." infamy.... [0] [0] https://twitter.com/virginmedia/status/1162756227132198914?l...

Oh wow, even the year checks out.

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#36

These endpoints are available in modem only mode, but everyone I’ve asked who has a SH3 says that they’re not affected by this and the endpoint doesn’t return the IP address. If you’re in modem only mode, block HTTP traffic to 192.168.100.1 outbound from your firewall just to be sure. Seems relatively low impact, but still pretty bad. Not surprising from VM given the quality of their firmware.

I've been running my VM superhubs in modem-only mode ever since I got them; with OpenWRT on my own router behind it.

I've been blocking traffic to RFC1918 ranges (all of them) that attempts to egress the WAN interface for just as long.

It's almost like I knew that eventually, someone was going to find a vulnerability in their web panel, and I wanted to make sure it wouldn't be exploitable.

Oh wait, I didn't know. It's just common sense.

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#37
post #2

Nobody should use ISP provided equipment for anything security sensitive, ever. ISPs don't care about security at all, aside from "security" as a sales term, and aside from when they're getting a bad name because of egregious failures. ARRIS shouldn't be given a year embargo, either. They're the same company who've known since 2016 about hardware issues which cannot be corrected in software in the Intel PUMA chipsets…

[deleted]

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#38
Home hub is a spectacularly poor piece of kit. Long start up time from powering on, high energy usage, really poor software (repeat soft bricking from remote updates at random times of day and night), historically awful attitudes to security (see other comments). Everything was better rub as Telewest/NTL.

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#39

Earlier quoted context omitted.

I think generally you don't get a choice when it comes to DOCSIS equipment. You can't just connect up your own (or at least no to Virgin Media's network)

This is one of the few positives I'll give to Comcast/Xfinity. I'm able to purchase my own DOCSIS modem (as long as it's on their compatibility list) instead of renting one from them. AT&T U-verse I couldn't bring my own modem, and I understand that they're not a DOCSIS network either.

Rogers network in Canada also permits BYO— I've used my own modem for years as a TekSavvy cable customer, and recently upgraded from one owned modem to another (both purchased second hand, though, so who knows— maybe I've been pwnt all along).

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#40
post #28

Earlier quoted context omitted.

I must admit, I don’t know much about networking. But do you have some more information there? My German cable router is in modem-mode, and I’d be interested in knowing what kind of routing it still does.

DOCSIS networks usually assign some management IP address that the provider can access to perform remote diagnostics on the modem directly. It's usually invisible and inaccessible to the user. Also, in many cases there is a specific that the "modem" listens on, serving a web interface that allows switching back to "router" mode. This also wouldn't be possible with a "pure" modem (as it shouldn't have any concept of t…

That makes sense. After all, I weirdly had to use their webinterface to even put it into modem mode. Thanks.

Though now that I’m thinking of it, are you sure it uses IP? It’s not as if they can’t use other layers.

Post reply on HN