Live data from Hacker News

Backdoor found in Linksys, Netgear Routers

github.com

81–90 of 144 posts

Re: Backdoor found in Linksys, Netgear Routers

#82
post #72

About a year ago I left a cable modem and internet service (Time Warner) at an apartment I was moving out of while my friend continued to stay there. I had configured the thing in a manner I thought to be fairly secure -- strong password, no broadcast, etc.. One day the internet goes down and my friend doesn't know what to do. She calls the ISP and asks them what's wrong. They say they can't release any information a…

I had a problem of DNS poisoning on my router + modem for a long time even though remote access was disabled and my computers were clean. The DNS entries kept changing to bad ones (even after a factory reset). I ended up switching the modem to bridge mode and using a router of my own to resolve the problem.

Re: Backdoor found in Linksys, Netgear Routers

#83
post #31

Can this be fixed by changing the firmware to OpenWRT or DD-WRT?

Yes, this isn't a hardware backdoor, it's all in the software.

This backdoor is a software backdoor - there may be hardware backdoors too. Hardware backdoors are much, much harder to find as there is no real way to track one down without trying to reverse the actual hardware itself, and that is close to impossible. So while we can confirm there is a software backdoor in this router, we can't confirm if any other router does or doesn't have a hardware one.

Re: Backdoor found in Linksys, Netgear Routers

#84
post #60

From the sounds of it, these are purposely made backdoors? or something ignored ? My expression: http://i.imgur.com/pYJMKC6.jpg

NSA/Government/Military mindset.... secrecy by obscurity. It's now "We'll just hide our backdoor, really, super well. No one will every find it. And we'll use our deep black VPN no one knows about....and hope no one notices."

[deleted]

Re: Backdoor found in Linksys, Netgear Routers

#86

Earlier quoted context omitted.

Can you just do an "Explain like I'm five" please.

Well, it is like a game that you can play with your eyes closed. Imagine that you close your eyes and then somebody gives you a large toy made out of LEGOs. And you figure out what this toy is, with your eyes closed! That's what he did.

HEY LOOK! We have an ass over here!!!

Re: Backdoor found in Linksys, Netgear Routers

#87

Has there been a technical write-up on this yet? I honestly tried to read the presentation and had to quit after the third superfluous meme slide.

TLDR of the presentation: found a service that returns all the configurations on the router (including admin username, admin password, wifi password, etc.). Also, found a bunch of buffer overflows.

Re: Backdoor found in Linksys, Netgear Routers

#88
post #72

About a year ago I left a cable modem and internet service (Time Warner) at an apartment I was moving out of while my friend continued to stay there. I had configured the thing in a manner I thought to be fairly secure -- strong password, no broadcast, etc.. One day the internet goes down and my friend doesn't know what to do. She calls the ISP and asks them what's wrong. They say they can't release any information a…

You and others that are curious about what end user equipment management controls are possible might enjoy reading about specs like TR-069, etc.

http://www.lightreading.com/tr-069-still-sexy-after-all-thes...

Re: Backdoor found in Linksys, Netgear Routers

#89
post #72

About a year ago I left a cable modem and internet service (Time Warner) at an apartment I was moving out of while my friend continued to stay there. I had configured the thing in a manner I thought to be fairly secure -- strong password, no broadcast, etc.. One day the internet goes down and my friend doesn't know what to do. She calls the ISP and asks them what's wrong. They say they can't release any information a…

>Time Warner had left a backdoor in all their modems that gives them administrative access to my private connection

Yes, their modems. On the connection that they provide for you.

A cable modem is considered CPE (customer premise equipment), meaning it is part of the infrastructure a telco uses to provide you with connectivity. Usually they own it, but in any case they have full control over it, as they should - it's part of their network. They may choose to delegate some configuration via a web GUI, but that's at their discretion -it's theirs to administer.

Business telecom has a formalized notion of a demarc (demarcation point), the place where the telco network ends and yours begins. AT&T owns and is responsible for the fiber/T1/POTS lines as they come through the wall, as well as the CPE (often a large rackmount Cisco router) to which it connects. Their contract is to provide connectivity on specific ethernet ports/fibre GBICs/whatever of that CPE. Whatever happens downstream of those ports is your problem, and whatever happens upstream is their problem.

Both sides will treat this connection as hostile - you'll have your own NATing router up and the telco's router, if it even has a configuration interface listening on your NIC, won't let you in. It would be inappropriate for AT&T to have any sort of access to the router you own and inappropriate for you to attempt any sort of access to AT&T's CPE.

Time Warner has been shifting recently towards placing WiFi on their side of the (logical) demarc. Which makes sense, since most people would rather not be responsible for administering any infrastructure - they just want Time Warner to deliver them WiFi. It sounds like you have this kind of setup, in which case Time Warner's access is not "backdoor" but "building owner" - you're renting a room.

If you'd prefer, you can (have them) turn off their WiFi, go buy a nice wireless router, and connect it to the modem. In this case Time Warner is providing you with a connection on an ethernet port; the device you've plugged in is your own (your side of the demarc) and they have no right to touch its configuration, nor are they responsible for it working correctly.

EDIT: The obvious analogy that would have simplified much of this is that a cable modem is like an electrical meter.

Re: Backdoor found in Linksys, Netgear Routers

#90
post #73

ScMM = SerComm, perhaps? Many of Linksys' old DSL modems were manufactured by them, AFAIK.. and it seems many of the noted 'probably affected' models have a SerComm manuf'ed device for at least one revision of that model line More probable SerComm manuf'ed devices are visible at the WD query link below.. http://wikidevi.com/w/index.php?title=Special%3AAsk&q=[[Manu...

confirmed as working on an old (2005/2006) Diamond DSL642WLG / SerComm IP806Gx v2 TI based modem router, btw
Post reply on HN