3 ms·
I suppose I just don't know what exploits could be implanted -- are there forms of rootkits that can go undetected? Or have all of these infected firmware been
by kfrzcode 8y ago
I suppose I just don't know what exploits could be implanted -- are there forms of rootkits that can go undetected? Or have all of these infected firmware been reverse engineered and the exploit in question cataloged?
According to ArsTech in this article (https://arstechnica.com/information-technology/2018/05/hackers-infect-500000-consumer-routers-all-over-the-world-with-malware/ https://arstechnica.com/information-technology/2018/05/hacke...) the VPNFilter exploit can survive a reboot - so how can a simple reboot disinfect if the only delta is the owner of [one of] the second stage callback IP addresses? I haven't seen any mechanics explained that would actually disinfect the router.
I appreciate your response with actual critical thinking tips and not just flippancy - I don't know where else to have these types of discussions.
- ggm 8y agoThe attack had three components: infection, sign-in with an initiator head-end, and then second/third stage download. As I understand it, from reading around: The FBI took over an "initiator" headend which bootstraps a simpler infection into the actual threat/attack code. The low level infection can't be removed simply, that demands new code from the maker or an OpenWRT type source. The FBI took over the domain namer behind a service which acts as the sign-in site. The attack mode code is not in your firmware, it has to be re-downloaded. If you block the initiator login, you aren't "clean" but you cannot complete download of attack code to mount the DDOS If you reboot, the low level infection tries to sign in, and is blocked, and so can't get the second/third stage downloads.
- kfrzcode 8y agoOk, so it's kind of like burning a line in a forest fire - the fire is still fire, but it's controlled and used in such a way that it should stop the bigger blaze from crossing said line? Thanks for this insightful response. I know a lot of readers would just tell me to do my own research but this was really enlightening.
- ggm 8y agoNah.. I don't like that metaphor. I think I like this one better. Back in the day, cable TV was crypted, and people had to have cable TV decoder cards with a key to fit a slot in the receiver. So, in the UK, somebody worked out how to decode the keypair, and you could buy a keycard in the pub for like GBP50, instead of paying the cable company GBP100/mo. But the cards, they have a fixed life. They don't last forever, you have to keep coming back for more. The real fix is obviously to fix the crypto, but there are a million receivers out there. Nobody has time to go round each one. So what the cops did, is find where the faked out keycards are being printed and shut down the print house, so imagine... if you then get the city electric company to power cycle every house, when its receiver reboots, it needs a new keycard, but they can't get one any more, 'cept from the cable company. Fixed? No, but you cut the problem off at the knees. Oh wait: we all wanted those sweet stolen keycards. I gotta think of a better metaphor :-)