10 ms·
0day vulnerability in firmware for HiSilicon-based DVRs, NVRs and IP cameras
- whalesalad 7y agoWhen you see how small some of these devices are it makes you realize how easy it would be for a malicious actor to bug just about anything you own. A simple cell phone charger becomes a listening device that could have an LTE modem hiding in it. People are worried when they find a raspberry pi sitting in the network rack - and rightfully so - but fail to realize that you can achieve pretty much the same thing by hiding in plain sight. Imagine how much you could fit into a 6-port commodity surge protector.
- adrianpike 7y agoGlade plug-ins are innocuous, roomy inside, and have convenient constant 120v. Take a peek next time you're in a semi-public space if there's any that are suspiciously not-smelly.
- lifeisstillgood 7y agoAnd one could easily walk round many building just plugging them in. I mean how many people would remove a glade-plug-in just in case Dorothy from accounts likes the smell? Dorothy might just replenish the scent dispenser every six weeks.
- Polylactic_acid 7y agoI would unplug them to avoid creating air pollution.
- lifeisstillgood 7y agoDorothy would give you a hard stare. And defund your project.
- catalogia 7y agoDorothy doesn't have to see you do it. Do it earlier in the morning or later in the evening, or during lunch. Which, incidentally, is how Dorothy the corporate spy might have installed the device without anybody noticing her be the one to do it.
- lifeisstillgood 7y agoSo, unplug the device and leave it on Alice's Desk. if Dorothy gives you a hard stare, then you know she must have had access to the video feed in the plug-in, and so is the corporate spy. But if Dorothy instead gives Alice a hard stare, Dorothy is innocent. But if you return that morning to find the device plugged back in, Alice must be the spy. Unless Bob from HR got in early that morning ...
- Zenst 7y agoWhich would save HR doing it and sending a memo about health and safety and asthma can kill due to these, possible.... Yeah, that is exactly how that would play out in many companies. At least in the UK.
- r00fus 7y agoWithout ruining the main use case - is there some way to sterilize or nuke things like a basic cell phone charger when it should have no radio-frequency capability?
- Avamander 7y ago> is there some way to sterilize or nuke things like a basic cell phone charger when it should have no radio-frequency capability? If you want Fast Charging, short circuit protection or similar, then no, it has to have ICs and those could do a lot of things that are hard to detect.
- Polylactic_acid 7y agoYou have to open it up and inspect the hardware.
- trevyn 7y agoIncluding de-capping the chips and having a look at the floorplans.
- RL_Quine 7y agoNope. Even USB cables now have active electronics and a microprocessor in them.
- outworlder 7y agoBatteries too.
- BubRoss 7y agoThey don't have to. USB is four wires.
- Piskvorrr 7y ago...and 500 mA maximum. Anything above that, and things get Complicated.
- Zenst 7y ago> A simple cell phone charger becomes a listening device that could have an LTE modem hiding in it. You can already get USB cables that have a hidden mic and sim, so if powered you can phone up and listen in. Those a very cheap and google shows this, but this is more adventurous. As for targeting hardware and security - how many people would question a fancy free mouse or keyboard arriving in the internal post as it happened to of been dropped of at reception. Great pentesting trick btw. As for chips with `hidden/undocumented` remote activated features. If it was documented, would it be bad or something you can use or actively block off. When they are undocumented, well - hard not to think the worst. But then, CPU's today, not fully documented when you can't hack away at the microcode and management and whatever else is DRM'd out of your reach. If Intel was a Chinese company instead of American - how would Americans feel about Intel chips? That is an interesting thought exercise.
- ta999999171 7y agoExactly the same, because citizens in US don't understand technology - just enough to do the books.
- big_chungus 7y ago> citizens in US I don't think this is any better elsewhere. If anything, the higher concentration of tech in America might make some of her citizens better prepared. But most everyone doesn't care beyond "making the darn box work."
- sgt 7y agoAgreed. People in the US are generally more tech aware than most other nations on Earth.
- c0restraint 7y agoYup -- these already exist. I can't find the 6-port commodity surge protector implant (I've seen it before), but these are the other relevant tools you're thinking of: https://shop.hak5.org/collections/network-implants https://shop.hak5.org/collections/network-implants
- msh 7y agoDo you have links to any of the devices? There are no pictures in the article.
- tryptophan 7y agoI wonder what the solution to this sort of thing is. Open source hardware maybe? Force publication of firmware for all hardware sold?
- Avamander 7y agoFOSS firmware would be a nice, but unless someone verifies that firmware (could be maliciously a spaghetti), then it doesn't have much use.
- roel_v 7y agoWho says the hardware doesn't have a separate IC overriding the ostensibly clean firmware? So you need not only verified hardware schematics, but also verification that the hardware you're running is actually based on that verified design. For which there is currently no way of doing that, as far as I know. You need to either trust the vendor at some level, or treat every device as hostile - while still getting its intended use out of it.
- Avamander 7y agoTrue, but having to only trust hardware being correctly made is already an improvement over having to trust both software and hardware to be made correctly.
- eeZah7Ux 7y ago> Who says the hardware doesn't have a separate IC overriding the ostensibly clean firmware? Cost, space on the PCB or on the die, additional complexity, and it's a very big thing to keep secret. And if it's found it becomes impossible to deny or chalk up as an innocent mistake.
- eeZah7Ux 7y agoNo. FOSS firmware immediately makes backdoors thousand times more risky to implement.
- somurzakov 7y ago
- easytiger 7y agoWhy is the title sensationalised. There is no "injects backdoor into their chips". It's a debug console on a busybox build. One would have to be on the same lan to exploit it.
- crooked-v 7y agoThough, "on the same LAN" becomes much more of a problem when you consider insecure 'smart' lightbulbs and appliances everywhere.
- Polylactic_acid 7y agoYep, how many people actually have a lan where every single device that ever connects is fully secure and trusted.
- jay_90 7y agoThe US Govt?
- marta_morena 7y agolmao
- kevin_thibedeau 7y agoTheir contractors. The government itself can't be bothered to follow its own security policies.
- kryogen1c 7y agovLAN segmentation is a best practice for this exact reason
- dahfizz 7y agoEveryone savvy enough to browse HN ought to, at the very least...
- 7y ago
- inetknght 7y agoIs this Bloomberg and SuperMicro all over again?
- gen3 7y agoNo, there is proof of concept code. from the article: https://github.com/Snawoot/hisilicon-dvr-telnet https://github.com/Snawoot/hisilicon-dvr-telnet
- LatteLazy 7y agoIsn't this just telnet? Like last time people claimed huawei "injected back doors", nothing is being injected by them, and these are not backdoors, they are front doors, standard festures etc? But dressed up in a way to make it look scarey to someone non-technical? Sorry if I'm missing something here...
- taneq 7y agoA hidden door that nobody but the installer of the door knows about is generally referred to as a back door. If it was without the knowledge of the main device manufacturer, then it was injected.
- vectorEQ 7y agoits a telnet but you need to activate it first. often backdoors are simple shells like telnet or such services. but it usually requires some 'magic packets' or such things to open the port to it or start the service. if you look at the POC you see it's not simply making a telnet connection to a port, but it does some other stuff first to prepare for it.
- lifeisstillgood 7y agoI know I am probably too forgiving (and generous and honest https://www.pinterest.co.uk/pin/439593613603376622/ https://www.pinterest.co.uk/pin/439593613603376622/) but dumb companies have left backdoors in everything from heart monitors to factory equipment. I understood that the Huawei threat is not "dumb shit" but "clever shit we don't notice until the cyber portion of the combined arms full scale attack is launched" If we cannot trust one hardware company we cannot trust any of them. Open source hardware seems like the Nash Equilibrium for this problem - everyone finds a way to make sure everyone can verify the hardware in their network...
- gnfargbl 7y agoIt is both of those things. And why wouldn’t it be? Huawei is a large organization and, like all large organizations, will consist of a multitude of different groups all trying to achieve the same goal in different ways. Some will want to rob the bank by tunnelling quietly into the vault at night, some will want to walk through the front door with a sawn-off shotgun.
- lifeisstillgood 7y agoFair enough - see my edit above. The only protection against dumb or clever shit is some means to verify SoCs are what they claim to be (yes very hard, but a future with Open source SoCs, and supply chains where you can inspect enough to be confident - that future can be glimpsed from here and it's a future where everyone wins)
- yetihehe 7y ago> The only protection against dumb or clever shit is some means to verify SoCs are what they claim to be That's only protection from clever shit. Dumb shit will have security vulnerabilities due to being made by programmers who don't care, pushed to do it faster by managers who don't care.
- therealx 7y agoI disagree; have you not seen the obfuscated C contest? Any smart malicious actor will do what they want, given minor access.
- bitanarch 7y agoThe title is misleading. HiSilicon is responsible for the SoC, but the backdoor is part of the Linux-based device firmware made by another company called Hangzhou Xiongmai Technology Co. There is no clear connection between Huawei and Xiongmai. You can find the clarification about the firmware maker (Xiongmai) towards the end of the article.
- yorwba 7y ago> There is no clear connection between Huawei and Xiongmai. If Xiongmai firmware runs on HiSilicon SoCs, there must be some kind of connection, even if just via a third party that paid HiSilicon for the hardware and Xiongmai to write the firmware for it. Unfortunately, the writeup doesn't clearly identify who that could be.
- kanox 7y ago> If Xiongmai firmware runs on HiSilicon SoCs there must be some kind of connection. Everybody can buy HiSilicon SoCs and run a backdoored linux distro on them, the only relationship required is "customer". You can buy a hisilicon-based devboard running linux for 100$: https://www.96boards.org/product/hikey/ https://www.96boards.org/product/hikey/
- yorwba 7y ago> the only relationship required is "customer" That's what I meant by "third party". Do you have an idea who that is in this case?
- elipsey 7y agoThis argument proves too much. By this reasoning, "Qualcomm-owned Cisco" is "injecting backdoors" into their chips as well.[1] The real title of the article is "0day vulnerability (backdoor) in firmware for HiSilicon-based DVRs, NVRs and IP cameras" and the word Huawei doesn't even appear in it. If OP wants to claim that Huawei are involved, maybe they should write their own article. :/ [1]https://www.zdnet.com/article/cisco-weve-killed-another-critical-hard-coded-root-password-bug-patch-urgently/ https://www.zdnet.com/article/cisco-weve-killed-another-crit... Edit: the title changed. criticism retracted.
- exabrial 7y ago> Full disclosure format for this report has been chosen due to lack of trust to vendor. Proof of concept code is presented below.
- coliveira 7y agoThe company in question, Xiongmai, is not owned by Huawei as stated. This is probably a clickbait article trying to link Huawei with some kind of backdoor.
- derision 7y agoThanks Sino. As we all know all Chinese companies are completely independent and free from all communist party influence
- Trias11 7y agoSo if device is behind firewall - attacker cannot sent TCP request to it?
- pbalau 7y agoBeing behind a nat, without any firewall, is more than enough to protect against this. In other words, you need to work hard to be affected by this "backdoor".
- vageli 7y ago> Being behind a nat, without any firewall, is more than enough to protect against this. In other words, you need to work hard to be affected by this "backdoor". So long as the device does not utilize UPnP and get the gateway to forward traffic to it.
- deleted 7y ago[deleted]
- ummonk 7y agoFlagged for misleading title.
- pbalau 7y ago> Client opens connection to port TCP port 9530... Good thing they are not opening a connection to UDP port 9530. Imagine the horror...
- garaetjjte 7y agoNothing surprising about it. These cheap Chinese cameras are just like that: buggy, default telnet passwords, silly vulnerabilities, crashing ActiveX plugins. Dahua/Xiongmai/Herospeed/whatever doesn't matter, everything is awful. Using these devices outside isolated VLAN with only RTSP tunneled to trusted client is just bad idea.
- buran77 7y ago> These cheap Chinese cameras People want dirt cheap stuff that has a Bible's worth of advertised features. Amazon's Ring (which is an order of magnitude more expensive than the regular cheap Chinese crap) is a dumpster fire of security and privacy to rival any Chinese brand, yet it consistently gets 4/5 stars in any review, none of which even bothers to mention the litany of findings or the fact that for the price they are unacceptable. But they are acceptable because it's not Chinese. It's the "Made in" label that counts. People will accept more garbage for a higher price if it has a local label, and will criticize foreign things more for the exact same issues. And that's valid basically almost everywhere in the world.
- close04 7y ago> buggy, default telnet passwords, silly vulnerabilities, crashing ActiveX plugins This pretty much happens with any equipment. If it's very cheap there's no reasonable expectation that they put too much effort into building and maintaining it. If it's expensive there may be other interests involved. The difference is what your nationalism dictates: When you hear of a Huawei vulnerability you think "spying", and when you hear of a Cisco one (or five [0]) you think "bug". In the end the choice is to buy cheap and have all the careless bugs, or to buy expensive and only have the by design ones. And whether you think they are malicious or not depends on where you come from relative to the product. [0] https://www.tomshardware.com/news/cisco-backdoor-hardcoded-accounts-software,37480.html https://www.tomshardware.com/news/cisco-backdoor-hardcoded-a...
- therealx 7y agoOr the semi-third option; firewall the living hell out of everything with something you either wrote yourself or can read yourself. No guarantee there either but you can avoid the garbage fire that is a lot of this. I'm sure the NSA has exploits for everything tho.
- mavhc 7y agoSomeone should just sell a camera and make the code open source, they'd quickly eat all the market
- solarkraft 7y agoI wish. In hacker circles they definitely would, but to reach a broader audience they'd definitely have to do some education. But maybe ...
- PragmaticPulp 7y agoOpen source has near-zero appeal outside of the hacker niche. The vast majority of people only care about price and maybe customer support. Open source isn't feasible for any of the mainstream systems anyway. It's not up to the camera makers. The silicon vendors would have to open-source license their chipset drivers and firmware source, which isn't going to happen any time soon.
- davidzweig 7y agoI think some Allwinner SOCs have blob-free mainline linux. If there are solid drivers for everything (camera, ISP etc.), not sure. V3s is even QFN with onboard ram, so easy to make a board for. Or use a board like this: https://licheepizero.us/ https://licheepizero.us/ But, yeah, I think you're right, you'd struggle to compete on cost and features with mass-market players. You could offer open source firmware for some existing cameras.. I think some people do do this.
- onesmallcoin 7y agoI love these HiSilicon boxes, take a look at the OpenIPC project if you want to secure your device. It's open source firmware for these boxes, I want to give a big shoutout to Igor Zalatov and Flyrouter for all their support when working on these boxes http://openipc.org http://openipc.org
- buran77 7y ago> UPDATE (2020-02-05 17:28+00:00): Other researchers and habr users had pointed out such vulnerability is restricted to devices based on Xiongmai (Hangzhou Xiongmai Technology Co, XMtech) software, including products of other vendors which ship products based on such software. At this moment HiSilicon can't be held responsible for backdoor in dvrHelper/macGuarder binary. This was an interesting update, especially the last sentence.