Live data from Hacker News

Linksys CherryBlossom Advisory

linksys.com

11–20 of 46 posts

Re: Linksys CherryBlossom Advisory

#11
post #10

> If users believe their router firmware may have been compromised, Linksys recommends that users download the latest available firmware from http://www.linksys.com/support/ and update your router. Is there a hardware feature that makes the firmware boot secure in a way that prevents the firmware from interfering with the update? Such as croning itself to reinstall the compromise when you're not looking? Or lying tha…

Download from non-TLS site, yeah, what could go wrong.

Re: Linksys CherryBlossom Advisory

#12
So ... the latest available firmware for mine is from jan 2016. Clearly there would be no fix in that firmware. So the idea is that I'm installing a known/assumed/hoped "good" firmware, to replace the potentially bad firmware. Yes?

(And the latest available is newer than what's on my router now, so might as well.)

Re: Linksys CherryBlossom Advisory

#13
post #10

> If users believe their router firmware may have been compromised, Linksys recommends that users download the latest available firmware from http://www.linksys.com/support/ and update your router. Is there a hardware feature that makes the firmware boot secure in a way that prevents the firmware from interfering with the update? Such as croning itself to reinstall the compromise when you're not looking? Or lying tha…

Need something with a TPM, like an Onhub/Google Wifi.

Re: Linksys CherryBlossom Advisory

#14
post #13
post #10

> If users believe their router firmware may have been compromised, Linksys recommends that users download the latest available firmware from http://www.linksys.com/support/ and update your router. Is there a hardware feature that makes the firmware boot secure in a way that prevents the firmware from interfering with the update? Such as croning itself to reinstall the compromise when you're not looking? Or lying tha…

Need something with a TPM, like an Onhub/Google Wifi.

Yes, I was speaking to these routers in particular.

Because if they don't have this, then this is bad security advice against what is considered a targeted attack.

Re: Linksys CherryBlossom Advisory

#15
post #12

So ... the latest available firmware for mine is from jan 2016. Clearly there would be no fix in that firmware. So the idea is that I'm installing a known/assumed/hoped "good" firmware, to replace the potentially bad firmware. Yes? (And the latest available is newer than what's on my router now, so might as well.)

Yes, not an exploit - just a modified firmware that they might have installed if they broke in via other means (physical or wifi cracking for example).

Re: Linksys CherryBlossom Advisory

#17
post #4

I wonder if a factory reset is enough in all cases - the source for the factory reset has to be on the device itself. I haven't played with it much, but there are ways to persist after a reset on Android, I'd assume the same is possible here. Very happy to be corrected. Anyone know what the cheapest Linksys I could buy is, and whether these vulnerabilities have been released publicly?

If the security of your router is of concern to you I would recommend setting up your own FreeBSD+pfSense router. Another option is to setup a vpn server that all your devices connect to to access the internet. In that scenario it won't matter if your router is compromised because all traffic flowing through would be encrypted.

PFSense runs PHP as root. Let that just sink in for a second, does that sound like a recipe for security?

Nevermind the community, when it comes to vaguely complex things like IPTV and similar, support is either legacy or gone.

At this point OpenWRT is the only sane choice, at least it doesn't run everything as root and isn't going to shove off Multicast UDP packet forwarding support in the next year or two.

Re: Linksys CherryBlossom Advisory

#18
post #10

> If users believe their router firmware may have been compromised, Linksys recommends that users download the latest available firmware from http://www.linksys.com/support/ and update your router. Is there a hardware feature that makes the firmware boot secure in a way that prevents the firmware from interfering with the update? Such as croning itself to reinstall the compromise when you're not looking? Or lying tha…

Linksys security guy here - we got that firmware update tidbit from the cherryblossom documentation.

The firmware implant (aka flytrap) reproduces all of the router's normal functionality. On page 122 of the cherryblossom docs, it says that the firmware upgrade feature is implemented normally by the flytrap, and that if a user attempts to upgrade their router's firmware, it will overwrite the flytrap firmware.

Re: Linksys CherryBlossom Advisory

#19

I wonder if a factory reset is enough in all cases - the source for the factory reset has to be on the device itself. I haven't played with it much, but there are ways to persist after a reset on Android, I'd assume the same is possible here. Very happy to be corrected. Anyone know what the cheapest Linksys I could buy is, and whether these vulnerabilities have been released publicly?

A factory reset _is not_ enough. A factory reset will just clear a part of the NVRAM that holds configuration - any firmware implant will still be on the device.

There were no vulnerabilities included in the cherryblossom leak. The firmware implant deployment instructions included in the leak don't mention using any vulnerabilities either.

Almost all of the devices listed in the cherryblossom leak are not being sold anymore.

Re: Linksys CherryBlossom Advisory

#20
post #16

Isn't this a lie though? They do not mention remote compromise and I would bet dollars to doughnuts most old routers have RCE holes.

There were no vulnerabilities included in the cherryblossom leak.

If you have any information about RCEs, Cherryblossom details we may have missed, or any other vulnerabilities in Linksys devices, please email me directly at benjamin.samuels at belkin.com

Post reply on HN