Live data from Hacker News

Backdoor found in Linksys, Netgear Routers

github.com

61–70 of 144 posts

Re: Backdoor found in Linksys, Netgear Routers

#61

Earlier quoted context omitted.

What is the tool being shown on slide 18? It looks like it breaks the assembly into basic blocks and shows a control flow graph based on that. Very cool tool, is it open-source?

No, it's IDA Pro, and it's very, very expensive.

The evaluation version is rather usable and there's a free version of an older release.

Re: Backdoor found in Linksys, Netgear Routers

#62
post #45

"And the Chinese have probably known about this back door since 2008." http://www.microsofttranslator.com/bv.aspx?from=&to=en&a=htt... That's a pretty scary prospect. If its been 'known' and exploited since at least 2008. Poor form Netgear/Linksys.

Probably not Netgear or Linksys' choice. The Treasonous Act, aka, the Patriot Act has a black version that forces such companies to do as they're told and shut up about it.

Re: Backdoor found in Linksys, Netgear Routers

#63

Earlier quoted context omitted.

Can you tell me which parts you couldn't get? I want to test my understanding - I'll see if I can explain it to you.

Can you just do an "Explain like I'm five" please.

Well, it is like a game that you can play with your eyes closed. Imagine that you close your eyes and then somebody gives you a large toy made out of LEGOs. And you figure out what this toy is, with your eyes closed! That's what he did.

Re: Backdoor found in Linksys, Netgear Routers

#64

Why backdoor?? That's what I want to know.

Why what? It's a backdoor in the sense that it allows you to change settings on the modem with no credentials. It's plausible that on a badly configured network this port could be exposed to the Internet. Anyone want to check Shodan?

> It's plausible that on a badly configured network this port could be exposed to the Internet.

It's also plausible that an attacker could find one of these in the local coffee house or any other place that offers public wifi and get at it from the internal side that way, or war driving for access points using weak passwords or WEP, or small office corporate networks with mischievous employees, or an attacker compromising a single PC on the LAN and then using this to change the DNS handed out by the router's DHCP and compromising the others, ...

Re: Backdoor found in Linksys, Netgear Routers

#65
post #42

Earlier quoted context omitted.

My main problems were with the memes. Seriously, nothing against a little humor in your slides. But making every seconds slide a meme reference gets annoying pretty fast :)

Agreed, the slides were unreadable. A simple text document would have sufficed...

Not only that, but it's the original "open" format.

Re: Backdoor found in Linksys, Netgear Routers

#66
post #35

Interesting. Reminds me of the hack I did on a (mandatory) modem/router forced on AT&T users. They had a bunch of problems with it, so one day I got fed up after the millionth disconnect and cracked it open. Got a serial root shell by using the "magic !" command (completely randomly discovered) and dumped the source to the web UI(in Lua/haserl). From there found the equivalent of a SQL injection vulnerability and use…

AT&T have not forced me to use a specific modem with their DSL service.

Re: Backdoor found in Linksys, Netgear Routers

#67
post #6

I hacked my Fritz!Box (yeah, a bad name for a german router) and I'm entirely sure that it has a backdoor integrated too. That's why I wiped and flashed it with an alternative image. That and the Telecom's Speedport router are the most popular routers by far in Germany. And both have backdoors, I know that other router manufacturers also integrate backdoors from a source who works at such a company. A friend can also…

This is probably NOT a backdoor. Most likely your ISP is using a technique like TR-069. This enables them to push settings for voip/TV, and in your friends case wifi. A lot of DSL providers are starting to use this for less intrusive (?) goals like measuring noise and attenuation at the clients end once a day, so they can adjust the speed accordingly. AVM is a very nice company and you should not accuse them without…

> AVM is a very nice company and you should not accuse them without proof.

You shouldn't accuse anybody without proof. But since this is Hacker News I'll disagree with the first part of that sentence. AVM is probably the least hacker-friendly company I've ever come across. For example, they're so hell-bent on violating the GPL that they've taken it to court (and lost) [1].

1. http://fsfe.org/activities/ftf/avm-gpl-violation.en.html

Re: Backdoor found in Linksys, Netgear Routers

#68

Earlier quoted context omitted.

What is the tool being shown on slide 18? It looks like it breaks the assembly into basic blocks and shows a control flow graph based on that. Very cool tool, is it open-source?

No, it's IDA Pro, and it's very, very expensive.

$800/$1600 isn't it?
Post reply on HN