Live data from Hacker News

VPN users unmasked by zero-day vulnerability in Virgin Media routers

portswigger.net

51–60 of 97 posts

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#51
>"published details of the flaw nearly two years after first alerting Virgin Media"

Two Years !! - Ja this just makes me mad !

Sure security issues happen to the best of them and us, but dammit being alerted to this and just ignoring it, tells you EXACTLY the level of competence of management and their commitment to YOUR data.

If I may add a few data points, I recently had a look at some of the ISPs in my country, just "basic level stuff". I'm by no means a PEN-Tester. This is what I found:

1. ISP A

1.1 CLIENT-Side Localstorage, no validation: Thus if you are signed in, goto localstorage and change 'user-id:123' to 'user-id:456' - Congrats you are now logged in as user:456

1.2 All API's where you can pass in a user-id, did not check if you are allowed. Thus you can do "/api/getuserinfo/"

1.3 Same API, also brings back HASHED-PW and HASHED-PIN, I thought it was strange but what's the chance one can "crack" SHA on a PC these days, especially with 'proper' password libraries like bCrypt/Salt. Turns out there were NO SALTs added to hashed pw and it was SHA-256. Hashcat makes quick work of most passwords.

PS was also "funny" how they "HASHED" the PIN (4 digit value) that was also returned in API response. If you think hashcat is fast with passwords, you know how fast it is to test the hash-values for [0000-9999] :)

1.4 Time to respond: I managed to have a phone call with the CEO which at least sounded (I do think the response was 100% sincere) UPSET, WORRIED and asked that I send him all the info and recommendations I have.

Good response to a bad situation ! - Well done.

2. ISP B

2.1 Hmmm seems someone deployed a part of a .git folder to their website.. Only .git/INDEX and .git/HEAD were deployed but it was very easy to reconstruct the "commits/changesets" with something like GitTools and discovered part of the changesets was when they were doing lead generation via facebook and their CRM system. API keys were all hard coded and visible in changeset.(source code) Thus using the API keys one has access to their whole CRM it seems.

2.2 Company Response: Managed to track down CEO via LinkedIn, super nice guy and it's a BIG ISP. He was very upset about security and super thankful for my "responsible disclosure" he CC'd most of his exec-committee. CTO, InfoSec, COO and operations team. He's parting words. "I hope someday we can help you as well" ! Well done

3. ISP C

3.1 Wow they were/are just terrible. They have unauthenticated AJAX calls for their “account-pages,billing details, router details”. You ONLY had to “guess” the account number (very predictable account numbering scheme)

3.2 Company Response: Spent a few days tracking down their contact details. Managed to find their emails for CEO, COO, and a few other “CxO” people. I emailed them about the security on their site. Do they have an InfoSec team or where should I send the details to ? He responded to send it to him (so we know the email address works). After sending proof and details of their complete lack of security I got zero response. After TWO weeks I followed up with the CEO and he only replied (send me your contact number, no phone call yet) but they did seem to fix the security issues only once I followed up.

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#52

>"published details of the flaw nearly two years after first alerting Virgin Media" Two Years !! - Ja this just makes me mad ! Sure security issues happen to the best of them and us, but dammit being alerted to this and just ignoring it, tells you EXACTLY the level of competence of management and their commitment to YOUR data. If I may add a few data points, I recently had a look at some of the ISPs in my country, ju…

> Two Years !! - Ja this just makes me mad !

Just goes to show that "responsible disclosure" can be a very misleading term...

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#53
Why is the web browser allowing the Javascript program to access a different server than the one it was loaded from? They call this a "DNS rebinding attack", and it seems it could compromise any router that doesn't have a password set, not just this router? So isn't the real problem here the browser running untrusted code and giving it access to your local network because it didn't check if the DNS had changed?

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#54
post #29

I would consider the router untrusted when using a VPN, so blaming it for the attack seems misplaced. I'd go even one step further, and say that unprivileged applications using the VPN should have no way of discovering your real IP. Applications not using the VPN shouldn't be able to discover the VPN IP, at minimum not use/leak it by accident (e.g. via webrtc). IMO the safest way to access a VPN is from a VM which is…

I have a seedbox set up on freebsd with two jails. One jail runs wireguard and pf. The other jail runs transmission. They are connected by a virtual Ethernet cable (epair). The transmission jail can only talk to the internet via the VPN jail, which it is not aware of.

I don't use it for torrent but I run Wireguard on my router and have 802.11q VLANs that only routes through each of those interfaces.

This way all I need to do is tag packets on whichever device they come from and they only go out via that interface.

I also have separate Wi-Fi SSIDs for each of those so changing my exit node is as simple as choosing a different one.

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#55

Earlier quoted context omitted.

I think generally you don't get a choice when it comes to DOCSIS equipment. You can't just connect up your own (or at least no to Virgin Media's network)

This is one of the few positives I'll give to Comcast/Xfinity. I'm able to purchase my own DOCSIS modem (as long as it's on their compatibility list) instead of renting one from them. AT&T U-verse I couldn't bring my own modem, and I understand that they're not a DOCSIS network either.

Comcast makes you downgrade to a business account if you want to get a reverse DNS entry from them. Reverse DNS is a requirement if you want to host your own e-mail and not have your mail categorized as spam. Comcast business accounts don't allow you to use your own DOCSIS modem.

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#56
post #55

Earlier quoted context omitted.

This is one of the few positives I'll give to Comcast/Xfinity. I'm able to purchase my own DOCSIS modem (as long as it's on their compatibility list) instead of renting one from them. AT&T U-verse I couldn't bring my own modem, and I understand that they're not a DOCSIS network either.

Comcast makes you downgrade to a business account if you want to get a reverse DNS entry from them. Reverse DNS is a requirement if you want to host your own e-mail and not have your mail categorized as spam. Comcast business accounts don't allow you to use your own DOCSIS modem.

>Comcast business accounts don't allow you to use your own DOCSIS modem.

Not true. I have multiple business locations using customer owned surfboards.

Might be a requirement for static addresses but it's not for business service in general.

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#58
This is what a Network Slug[1] is for.

"A Network Slug, or "Slug", is a transparent layer 2 firewall running on a device with only two interfaces."

...

"A Slug has no IP address, cannot be reached on the network, and does not increment IP TTL."

...

So, for instance, I have a port 22 slug that I can insert anywhere in the physical chain of a network that passively, and silently, blocks all traffic except for TCP 22.[2]

You could clamp down further and restrict it to port 22 and your specific VPN endpoint IP.

Foolproof ? Perhaps not - but a huge piece of defense-in-depth that makes the use of a (port 22) VPN much safer.

[1] https://john.kozubik.com/pub/NetworkSlug/tip.html

[2] https://john.kozubik.com/pub/NetworkSlug/images/sg-1000-back...

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#59
post #29

I would consider the router untrusted when using a VPN, so blaming it for the attack seems misplaced. I'd go even one step further, and say that unprivileged applications using the VPN should have no way of discovering your real IP. Applications not using the VPN shouldn't be able to discover the VPN IP, at minimum not use/leak it by accident (e.g. via webrtc). IMO the safest way to access a VPN is from a VM which is…

I have a seedbox set up on freebsd with two jails. One jail runs wireguard and pf. The other jail runs transmission. They are connected by a virtual Ethernet cable (epair). The transmission jail can only talk to the internet via the VPN jail, which it is not aware of.

Jails/Containers should be fine as well.

Just need to make sure host applications don't see the network interface provided by the VPN gateway, so they don't accidentally leak it (linking it to your real IP). A typical example are browsers when using WebRTC.

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#60
post #28

Earlier quoted context omitted.

I must admit, I don’t know much about networking. But do you have some more information there? My German cable router is in modem-mode, and I’d be interested in knowing what kind of routing it still does.

DOCSIS networks usually assign some management IP address that the provider can access to perform remote diagnostics on the modem directly. It's usually invisible and inaccessible to the user. Also, in many cases there is a specific that the "modem" listens on, serving a web interface that allows switching back to "router" mode. This also wouldn't be possible with a "pure" modem (as it shouldn't have any concept of t…

Note that even many actual DOCSIS modems have management interfaces and are not pure.

I have always been able to view the management page for my Arris/Motorola Surfboard modems.

Post reply on HN