23 ms·
ARRIS Cable Modem Has a Backdoor in the Backdoor
- ck2 11y agoCan't most ISPs replace the firmware on demand on most Docsis 3.0 modems ? This means they could manipulate it at any time.
- moftz 11y agoEncrypt everything between your computer and the server you're connecting to, ideally use a VPN. The ISP already owns the lines anyway, 0wning the modem doesn't really make much more of a difference. The reasoning behind being able to push new firmware to a modem from the ISP is automatic configuration and to stop abuse on the network although I'd rather configure things myself.
- iamthepieman 11y agoI have an Arris modem. Is there a way to mitigate this risk short of buying a new modem?
- throwaway2048 11y agono, as the nature of it forces it to be on your network edge.
- lstamour 11y agoThat said, it's possible that your cable company could protect you (and their other customers) at the expense of you possibly losing access to port forward SSH, etc.
- mhurron 11y agoWouldn't putting the Arris modem in bridging mode mitigate it? It should no longer be accessible via an outside IP at that point.
- throwaway2048 11y agoit almost certainly still has an externally accessible ip at that point for management purposes. (bridge 2 interfaces, add a virtual interface to the bridge)
- mhurron 11y agoI don't believe management from the CableCo is done over IP and the other management end requires being plugged into the LAN port.
- throwaway2048 11y agoas the article states, scans found wan acessible modem uis
- mhurron 11y agoYes, but by default a modem from your ISP is acting as a NAT device routing to a private IP space. By default, it has an externally available IP address and will answer on that or those addresses. Many can, however, be configured as a bridge, which turns the device into just a converter between physical mediums. You now need another device to route and act as your gateway. In that setup you shouldn't be able to find it with an IP connection scan, because it doesn't have one.
- simoncion 11y ago> Yes, but by default a modem from your ISP is acting as a NAT device routing to a private IP space. Not in my experience. The default modem provided by both Comcast and Knology (who is -I guess- now WOW!) is (or was, in the case of Knology) a bridge device that requires you to provide your own router. You have to ask for a modem that's also a router to get something that's not a bridge. That doesn't mean that the modem doesn't have an IP address, mind. AIUI, on Comcast's network the modem gets an IPv6 address so that they can do network management stuff to it.
- 11y ago
- lstamour 11y agoI'm not sure I'd trust Arris products at this point. From another blog post in 2014: "It is worth noting that on previous FW revisions the CGI calls did NOT require any authentication and could be called without providing a valid "credential" cookie." http://console-cowboys.blogspot.ca/2014/09/arris-cable-modem-backdoor-im.html http://console-cowboys.blogspot.ca/2014/09/arris-cable-modem... With mistakes like that, and three layers of backdoors, I'm half expecting discoveries of hardware backdoors next ...
- ilurk 11y agoI skimmed trough it so it wasn't clear to me. But if you ssh and have root access, then you should be able to change the password. As well as edit a startup script to move/delete the backdoor files. Try it at your own risk.
- mark-r 11y agoThe whole point of a backdoor is that changing the password is ineffective. And the backdoor isn't a file you can delete, it's just a couple of extra instructions buried in the code - the article made that clear.
- rspeer 11y ago> After a thoughtful analysis, the marketing committee advised w00tsec members to write a Keygen. In order to write a Keygen, we need a leet ascii art and a cool chiptune. Something old, something new. Of course exploits and chiptunes have always gone together like bread and butter. But now exploits need marketing committees too.
- a1k0n 11y agoNot a bad chiptune either: http://www.a1k0n.net/code/jsxm/#Ghidorah_-_Toilet_story_5.xm http://www.a1k0n.net/code/jsxm/#Ghidorah_-_Toilet_story_5.xm
- throwaway7767 11y agoWatched on YouTube, since I didn't have a FastTracker player handy: https://www.youtube.com/watch?v=Syc2NnPNnZs https://www.youtube.com/watch?v=Syc2NnPNnZs Listening to that put me in a good mood :)
- deleted 11y ago[deleted]
- tomschlick 11y agoDoes this affect their Surboard line? Specifically the SB6141? Its probably the most popular modem for people who don't wanna rent one from their provider.
- scott_karana 11y agoI know the Surfboards originated from Motorola, so there's a faint hope that they're okay...
- tomschlick 11y agoI bought mine from Target 3 months ago and it still looks like it is running Motorola firmware even though it has an Arris logo stamped on the front of the device. https://s3.amazonaws.com/tomschlick-screenshots/BGYfaCbLVEsBh.png https://s3.amazonaws.com/tomschlick-screenshots/BGYfaCbLVEsB...
- Washuu 11y agoYep, they still run Motorola firmware. I discovered a few months ago Comcast is able to push firmware updates to customer owned modems without permission. So even if the backdoor is not present now there is no way to trust it will never be pushed to the devices.
- tomschlick 11y agoThats worrisome. I knew they could ping for info/reboot it but had no idea they had write access to the device.
- wmf 11y agoCable modems are based on a pre-Carterphone philosophy that the modem is an extension of the ISP and is completely owned (and 0wned), configured, updated, etc. by the ISP. They let you buy your own, but that doesn't change the protocol.
- peterwwillis 11y agoSeems like this only affects the LAN interface. Since most people aren't trying to break into your computer just to break into your cable modem, this shouldn't be considered a high priority exploit. Malware changing the DNS server on your router's DHCP server could be bad for you. But even though malware on your desktop attacking your network is bad, what's worse is there's malware on your desktop.
- Nacraile 11y ago"Shodan searches indicate that the backdoor affects over 600.000 externally accessible hosts" It doesn't look like this is LAN-only. Even if it were, an escalation from unprivileged code execution on a single device to MITM any connection out of a network hardly seems "low priority".
- johncolanduoni 11y agoI'm guessing they used Shodan to locate the models they knew were affected (i.e. by model numbers), not to try the backdoor on unsuspecting devices (which would be illegal).
- deleted 11y ago[deleted]
- rogerbinns 11y agoJust because you can't of a useful use by the bad guys, doesn't mean they can't :-) It is also quite possible the bad guys have figured out how to exploit this using regular Javascript - ie you don't need malware in your LAN, just Javascript in a browser.
- peterwwillis 11y agoAssuming you could exploit the browser's JS to submit such a request (I thought I remembered seeing a security feature of modern browsers to prevent this?) and assuming the web interface requires no authentication, you would only be able to enable WAN HTTP access. The telnet and ssh still appear to be LAN-only. And you still need the serial number to generate a password (does the web interface even show that?). I don't see a viable drive-by attack vector other than malware. edit It does look like telnet can be accessed via WAN, which is pretty bad.
- MertsA 11y agoAt least it appears to be based on the serial number. Only using the last 5 is still pretty bad though but plenty of cable modems treat the serial number as privileged information. It's already a password essentially for SNMP access provided that your ISP hasn't blocked access to it.
- esseye 11y agoIt is exactly as privileged as going to the website http://192.168.100.1 http://192.168.100.1 and clicking HW/FW versions, which proudly displays the complete serial for you. There is no authentication of any sort and it is not encrypted at any point.
- smcl 11y agoIt's a tiny bit funny that a cable modem called "arris" has a backdoor: http://www.cockneyrhymingslang.co.uk/slang/aris http://www.cockneyrhymingslang.co.uk/slang/aris
- MaxfordAndSons 11y agoI came here to say the same, so instead I'll add this: "I'd open an umbrella up me ARRIS for her" - Super Hans
- contingencies 11y agoHaha, we discovered that one playing scrabble last night. What are the chances?
- ars 11y agoWhen I try http://192.168.100.1/cgi-bin/tech_support_cgi http://192.168.100.1/cgi-bin/tech_support_cgi on an Arris modem it says: NET-DK/1.0 Error: 401 Unauthorized
- merlincorey 11y agoYes, that's demonstrated in the video. You have to login on another page before that page will work.
- deleted 11y ago[deleted]
- nandhp 11y agoOn my (newish) SB6183, I get "Read error: connection reset by peer".
- cxseven 11y agoI get that for any URL it doesn't serve
- thefastlane 11y agofrom a security standpoint, any recommendations for cable modem hardware and/or firmware?
- anExcitedBeast 11y agoDon't trust them. Add a system you control between the device and your internal network. If you're just worried about your traffic privacy and not just internal resources, establish an end-to-end encrypted tunnel from that jump system to a network or VPN provider you trust. Edit: excuse me, I misread your question. I thought you were asking for best practice. I don't have have a specific hardware recommendation (because I don't trust them :) )
- nickjj 11y agoA few years ago people on my ISP were ranting and raving about getting an Arris cable modem because it was one of the newer DOCSIS 3 modems. I wonder if the TM822 model is classified as "ARRIS SOHO-grade" because that's what the article mentions as having the backdoor.
- noobermin 11y agoI have WOW internet, and their provided modem was an Arris modem. It was a piece of garbage, so I bought a Netgear modem, sent the Arris back, and got $10 savings on my internet bill (for renting the crap modem). I'm even happier about that choice now. And yes, my new modem is DOCSIS 3.
- nickjj 11y agoWas it the same model? The TM822 has been pretty good to me. It maxes out at my ISP's reported speeds (30/5), no packet loss, low single digit latency and since it's hooked up to a UPS it hasn't been power cycled or rebooted in almost a year.
- noobermin 11y agoDarn, it's been more than half a year, so I don't remember the model name. It just recall it was Arris and the webpage manager thing had similar graphics and look to the one in the article (although they probably all have that). Nonetheless, regardless if it is the same model as they tested, this demonstrates that I really shouldn't trust anything from Arris now.
- nine_k 11y agoWhat kind of access should a cable company have to your cable modem? Should it at all? I mean, your ISP does not need any access to your edge router if the ISP gives you a standard Ethernet socket. How standardized are cable interfaces? What kind of custom setup may they legitimately need to work in a particular cable network?
- ascagnel_ 11y agoIn the case of cable internet service (not fiber), you'll almost never get a standard Ethernet socket. Chances are, you'll get a coaxial connection that requires a device to bridge the connectors and perform a handshake with your upstream provider. Of course, most consumers go with whatever hardware their provider gives them (usually a gateway to provide Wifi). This presents it's own problem: in the US, cable companies are trying to set up mesh networks/guest access, and so those gateways may be running a second semi-public as a node on the mesh.
- drbawb 11y agoWe just got new tenants in our (commercial) building. I'm honestly a bit upset as there are now _four_ new access points for a single tenant. "TWC WiFi", and "CableWifi", both unsecured (!!!), and then "TWC WiFi Passpoint" (which requires a TWC subscription to use.) I sure wish people wouldn't blindly trust the cable technician to configure their wireless network properly. Now there's just tons of RF noise, and people can leech bandwidth off our building. -- I frankly find it ridiculous, given the premium we pay for commercial internet (which is slower than my residential subscription), that we are expected to share it with their "mesh network."
- wtallis 11y agoAren't those SSIDs all on the same WiFi channel? Having split guest/internal networks broadcast from the same radio on the same channel really doesn't hurt things enough to care about. And it's almost certainly using separate DOCSIS channels or not counting toward the traffic shaping limit on your traffic, and it's prioritized lower than your business-class traffic when it's further upstream in TWC's network, so you don't need to worry about it affecting your WAN connection performance either.
- arca_vorago 11y agoYou know what really grinds my gears? The fact that on my newish surfboard modem, when I looked around for a new firmware version, low and behold, apparently Arris/Motorola refuse to release the firmware to the consumer/owner of the device, and say that it is the ISP's responsibility to update firmware! No it's not, it's my hardware! I understand the docsis 3.0 spec says otherwise, but I disagree with it. So I call my ISP (Suddenlink), and lo and behold, they say it's not supported and therefore won't update my firmware. Now I find out it's probably backdoored! You know, when the NSA and everyone else start talking about cybersecurity, I don't fucking beleive a word of it anymore, because if they were really concerned about security, they would be pushing for open source firmware modems, and would be letting these companies know about the vulns and pushing them to close them. Instead they sit on the 0-days like a treasure trove of new weapons.
- bluedino 11y agoIt's not any different than wireless companies and cell phones - they will use the reason of not controlling the firmware causing connection issues with their proprietary networks
- arca_vorago 11y agoWhich is such a bullshit reason... but you are correct, unfortunately.
- X-Istence 11y agoYou can't update the firmware on your device even if you wanted to. The cable company is free to push whatever firmware they would like to your device at any time, you don't have a choice in the matter.
- ErikRogneby 11y agoWasn't there a project a while back where someone was building a open source modem/router from the ground up? A kick starter or something?
- imglorp 11y agoSince you need a DOCSIS modem box and a router, I would suggest people put a router box you fully control behind your ISP's DOCSIS brick, and just assume the latter is compromised continuously. I use pfsense on a usb stick in a little box with 2 ethernets.
- e40 11y agoYeah, no need to trust these things as firewalls.
- Igglyboo 11y agoWhat is a DOCSIS modem and why can't an open source one be built? Also, how does putting your router behind your DOCSIS modem help? Genuinely curious, don't know much about networking.
- bri3d 11y agoDOCSIS is the standard for IP networking over cable TV infrastructure. An open source modem can't be built because there's a huge certification / documentation fee from CableLabs and part of the requirements involve the cable carrier being able to control/update the modem at their whim. Putting your router behind the DOCSIS modem lets you firewall the modem the same way you'd firewall the Internet at large - that is, an attacker who compromises the modem wins the ability to specifically monitor your traffic, but does not immediately gain free access to your local network.
- Igglyboo 11y agoWould it be possible to just fake the cert or generate your own, in the same way that some people self sign SSL certificates instead of paying Verisign?
- annacollins 11y agoThat's really great.
- drmpeg 11y agoI returned my Arris TG862 because you can't really shut off the WiFi. Even though Comcast assured me that the public hotspot was disabled, I could see (with my SDR receiver) that it was still transmitting on channel 1. http://www.w6rz.net/comcastwifi.png http://www.w6rz.net/comcastwifi.png
- thiagobbt 11y agoAnd FCC approves it?
- userbinator 11y ago"transmitting" as in actually sending data, or just the radio left on, set by default to the lowest channel, and transmitting an otherwise useless carrier wave?
- drmpeg 11y agoTransmitting with a blank SSID apparently. It just adds to the congestion on 2.4 GHz for no reason. For myself, it interferes with my wireless development activities. See this thread on the Comcast forum where folks are seeing all sorts of bad behavior. http://forums.xfinity.com/t5/Home-Networking-Router-WiFi/Xfinity-HotSpot-FAQs/td-p/2307497 http://forums.xfinity.com/t5/Home-Networking-Router-WiFi/Xfi...
- paulannesley 11y agoHah I love this in the arris_backdoor.py output: > Bypassing EULA... > EULA served over HTTP > MiTMing EULA to include permissive clauses... > EULA bypassed using technique [1]
- ericfrederich 11y agoGood catch... That is hysterical
- AndyMcConachie 11y agoIs this a cable modem or a router? My definition of cable modem doesn't include an IP address. These POCs never include enough information for me. For instance, is this exploitable from the external interface, or only internal?
- mikequinlan 11y agoYou can address the Arris cable modem at ip address 192.168.100.1. Some providers disable this after it goes online. Here is one reference http://www.dslreports.com/forum/r20894378-What-is-the-cable-modem-s-IP-address http://www.dslreports.com/forum/r20894378-What-is-the-cable-...
- PhantomGremlin 11y agoIs this a cable modem or a router? Reminds me of the inane SNL sketch, whose catchphrase was: "New Shimmer is both a floor wax and a dessert topping!" My Arris (nee Motorola) SB6141 is a bridge and a router. It's actually very nicely done. When the modem can't access the cable infrastructure, it turns itself into a DHCP server and hands out IP addresses in the range 192.168.100.xx. This is useful for people at home whose configurations are such that their home networks won't work properly without some sort of DHCP server provided by the ISP. Once the modem can talk to the ISP, it turns itself into a bridge. The IP addresses the modem previously issued were valid for 30 seconds, so there will shortly be a new DHCPREQUEST which the modem bridges out to the ISP. From then on, the modem is transparent to IP traffic (but see below). My definition of cable modem doesn't include an IP address. This is highly useful. Once the modem has switched to being a bridge, it still responds to 192.168.100.1. There's all sorts of useful information there. E.g. DOCSIS status, Channel IDs, received Signal to Noise ratio, transmit Power Level, etc. There's even a nice (but short) log of the modem's interaction with the cable infrastructure. The modem is outside my firewall, so I don't really worry about it much. It's like anything else on the Internet as far as my home network is concerned. However, I do currently allow access to 192.168.100.1 (normally I block outbound RFC 1918 addresses). That is a potential problem should some rogue program on my network attempt to exploit a modem vulnerability. Maybe I'll just block all those addresses and only enable them in the firewall when I want to check the modem status.
- Demoneeri 11y agoCan they access the mainframe?
- reviseddamage 11y agoyo dawg...
- maximilianburke 11y agoI'n surprised this hasn't yet been branded the "ARRIS-Hole".
- Neolo 11y agoHi. I own Arris TG862G, TWC pushed their firmware on it, it seems much older than discussed here. Firmware Name: TS070563C_032913_MODEL_862_GW_TW_SIP_PC20 Firmware Build Time: Fri Mar 29 2013 I got a permanent password to advanced page/technician. But I don't have URL http://192.168.100.1/cgi-bin/tech_support_cgi http://192.168.100.1/cgi-bin/tech_support_cgi, it's 404 and as a result I don't know how to enable SSH. Can anyone help with this old firmware?
- deleted 11y ago[deleted]
- df_cryptostorm 11y agoI also have a TG862G, but from Xfinity (a Comcast company). The default admin page is @ http://192.168.100.1/ http://192.168.100.1/ & http://10.0.0.1/ http://10.0.0.1/, but neither of them have a /cgi-bin/tech_support_cgi. However, I discovered this page: http://10.0.0.1/wireless_network_configuration-1.php http://10.0.0.1/wireless_network_configuration-1.php (probably also exists on 192.168.100.1) which looks like a secret wifi config page that has more advanced options than the normal wifi config page @ http://10.0.0.1/wireless_network_configuration.php http://10.0.0.1/wireless_network_configuration.php (I found the wireless_network_configuration-1.php file by viewing the source of a few pages on 10.0.0.1, it was hiding in some HTML comments). On the normal wifi config page, you can only edit the settings for your "Private" wifi hotspot, but on this -1.php page you can also edit the two "Public" hotspots: "xfinitywifi", and one that (on mine) looked like: "XHS-A6B18523". Since you can edit these two "Public" ones, you can also viewed the stored WPA key for XHS ("xfinitywifi" has no key). Once I grabbed the XHS-* key and connected to it, I received a 172.16.12.100 IP (a subnet I've never seen on the other access point). On this one the gateway IP was 172.16.12.1. Nmap shows these ports on that gw IP: 443 = NET-DK 1.0 (ssl) 5001 = Arris/1.0 UPnP/1.0 miniupnpd/1.0 (Status: 501 Not Implemented) 8080 = (SIP end point; Status: 501 Not Implemented) and same as the above for ports 8081 & 8888 & 5540. All of those SIP ports were just HTTP servers that looked exactly like the customer version you see on http://10.0.0.1/ http://10.0.0.1/ , except that my admin pass didn't work on it (tried the defaults too, plus some guesses). When I went to https://172.16.12.1/ https://172.16.12.1/ it redirected me to /cgi-bin/status_cgi, which contains a link to /cgi-bin/tech_support (which redirects to /cgi-bin/adv_pwd_cgi). So maybe you could try all of that to see if your TG862G works the same :-) P.S. I tried the password of the day thing but the seed must be different on this one, and the SNMP thing doesn't exist on any of these webservers.