5 ms·
Complete, Persistent Compromise of Netgear Wireless Routers
- Glyptodon 13y agoI have a WNDR 4700 and I can't replicate as described. However, I've also never trusted the stupid thing since it stores passwords in clear text (or at least is happy to display them in clear text on one of its admin pages).
- dgesang 13y agoEven major browsers store/show passwords in clear text, can it be that wrong? ;)
- graue 13y agoThat's different. Browsers need to show your password to external websites to prove to others that you're you. This requires storing the actual password. They expose saved passwords in the UI because if they didn't, it would create a false sense of security. There's always going to be some way to get the saved passwords, or the feature wouldn't work. The router admin interface only needs to check your password. It can do that by storing only a cryptographic hash, not the password itself.
- darkmighty 13y agoI think they could however, as a default behavior, store each password encrypted individually using itself as a key, that way no plaintext passwords would need to be stored at all.
- kcorbitt 13y agoThen you would have to type in the password each time you wanted to use it anyway. Not much sense in storing anything in that case. :)
- dgesang 13y agoIt does make a lot of sense, actually, as you need to remember only one master key instead of multiple login-password combinations.
- derefr 13y agoThat's different from "using itself as a key", which is what the GGP said.
- darkmighty 13y agoYup that's right, my bad. I were thinking of a way of somehow not requiring input yet providing passwords without plaintext storage. What would actually work I guess would be storing a hash of <the password, a unique string provided through https auth>. So for the first time the browser would hash the pass and afterwards just provide the pass to the server as a hash without requiring input, acting as a normal pass to the server. However, that would either require some sort of universal agreement among browsers to work, which is tricky to require, or some browser-server protocol in which the browser would only carry such procedure to supported servers. If a supported server is accessed through a non-supported browser, the server itself would perform the hash. Probably too much of a hassle just in name of abolishing plaintext passwords on browsers, but I couldn't think of anything simpler. However, fun to imagine :) Obs: This would have the extra bonus of depriving knowledge of plaintext passwords to servers (in case they are compromised, the attacker would not get to try the pass across other services) and preventing password extraction through impersonation of webpages (although this is already guaranteed by https to some extent).
- entropy_ 13y agoIf servers accepted a hash of a password instead of the actual password then the hash becomes the password. Ie, possession of the hash is equivalent to possession of the password since it can be used to authenticate. Therefore, this is no different than storing them in plaintext. Furthermore, it would mean that if the hashes got stolen because a server was compromised those could be used as passwords and that would make it pointless to hash them in the first place. In other words, no, that wouldn't work.
- xtreme 13y agoBrowsers need to store the passwords in plaintext, because they need to populate the password field when you visit that website. However, you can store them encrypted using a master password and decrypt them once per session.
- derefr 13y agoAnd, on OSX at least, every browser does this anyway, since the Keychain is right there to make use of and unlocking it is built into the OS. I'm really surprised Windows has no equivalent to this.
- girvo 13y agoMy issue with Keychain is that unlocking it once keeps it unlocked, and my sessions on my iMac last forever (I rarely turn it off or log off) Any ideas on the best way of tackling that? Perhaps I'm using it incorrectly?
- derefr 13y agoYou're using Keychain correctly, but using your computer's authentication system incorrectly. Desktop environments in general (in Windows, OSX, Linux, etc.) assume that you will lock your session whenever you are not present and in control of the computer. (Thus, Keychain locks when the session is locked.) This is currently a big hassle to do, but all other security on the system is built up around that concept. Really, PCs need something like TouchID. Or something like pairing to your phone, and then detecting it in proximity and prompting a TouchID confirmation from it. Phone goes out of proximity = computer locks.
- reginaldjcooper 13y ago> This is currently a big hassle to do ⇧⌃⏏ is insufficient?
- derefr 13y ago
- bigiain 13y agoA browser has to be able to supply clear-text passwords to websites, so strong hashing and discarding the clear-text won't work in their use-case. Your router only need to authenticate your password, so it _should_ be using bcrypt/scrypt/pbkdf2 to hash the password and not storing it anywhere in clear-text.
- dgesang 13y agoAnyone noticed the smiley? Still, not protecting user passwords with a master-key makes it way too easy to read them. B2T now.
- girvo 13y agoI had fun freaking out my not-so-tech-savvy-but-exceedingly-paranoid (tin foil paranoid) uncle: He bet me $50 I couldn't crack his WiFi password. He let me use his iMac that was already connected. I hopped onto the Admin page for the router. Had a password, which make sense. I submitted a test password, and there was no page-refresh or network activity... hm. Must be just in the Javascript... Sure enough, it was obfuscated, but the password was in the damned HTML and easy enough to find. I got $50, and the priceless look of horror on my uncle's face. I then explained to him that physical access to a computer usually equals "Game Over" ;)
- MichaelGG 13y agoBut you didn't have physical access to the router. Setting aside that you could probably dump it out of memory if you had root on the OSX box, the router shouldn't have coughed it up so easily if it was supposed to be secure.
- girvo 13y agoOh, that was supposed to be my point if I didn't make it clearly enough: a router should NEVER have been programmed to do that.
- uptown 13y agoExploit doesn't appear to work on a WNDR3700v2. I'm hoping it doesn't, as this has been the only router I've ever liked after years of dealing with complete garbage.
- zdw 13y agoThis, along with bufferbloat [1], is why you run OpenWRT or another similarly modern, fully open source distro on your home routers. Right now, the best supported devices are ath9k's, so things like the Buffalo WZR-* models are ideal. The WNDR 4700 model specifically doesn't have good support for 3rd party firmware [2] due to it's use of NAND flash in an unsupported manner, so if you have that model you're kind of sunk at this point. 1. http://www.bufferbloat.net http://www.bufferbloat.net 2. http://wikidevi.com/wiki/Netgear_WNDR4700 http://wikidevi.com/wiki/Netgear_WNDR4700
- mbell 13y agoIf you want a more hardened setup I recommend pfsense, a freeBSD based firewall/router disto [0]. It'll run on any number of mini/nano boards and several companies sell prebuilt boxes. It can run as a wifi AP as well but I find that a separate AP works best. [0] http://www.pfsense.org/ http://www.pfsense.org/
- eksith 13y agoI've found pfSense really shines on old PC hardware since the embedded boxes I've tried it on tend to slow a bit. Something with a still functioning HD and at least 256Mb memory does pretty well with it.
- mbell 13y agoI haven't tried it on an embedded platform, e.g. a Geode or Via CPU. I'm using an old mini-ITX IPC board from Jetway with one of the first dual core Atom cpus, 1GB of ram (overkill) and 4 x Gbit ethernet ports. With a slim case / power supply I think it was ~$250 about 5 years ago when I bought it. Other than moving apartments it's only ever been rebooted once, to upgrade from pfsense 1.2 to 2.0. It's never crashed and never caused a problem, and I beat on my network connection. OpenVPN performance from outside is only limited by my WAN speed. It's been awesome. I also use pfsense in a VM in front of a bunch of other VM's on a VMWare server and it works great for that as well.
- 13y ago
- ChuckMcM 13y agoSo has anyone used any of the open hardware alternatives, like routerboard.com ? Seems like having the schematics and the firmware would be a reasonable place to be.
- voltagex_ 13y agoI looked into these kind of things but I'm in an odd position where I need an ADSL2+ chipset of a certain kind (Broadcom with good noise filtering) because of the state of my phonelines. I was looking into running an ADSL modem in full-bridge mode (you'd be surprised how many of these modems don't support that anymore) + a routerboard or mirotik product, but when you add up the cost and configuration time it just wasn't worth it. I'm currently running a Billion 7800VDPX, which I now have the GPL sources to (after some prodding). When I finally have some time to sit down and risk bricking my device, I'll have a look at getting OpenWRT working (although at last glance they were never going to support ADSL). tl;dr: open hardware alternatives aren't easy enough to drop in yet, or they're not really open - http://wiki.mikrotik.com/wiki/Manual:License http://wiki.mikrotik.com/wiki/Manual:License
- jasiek 13y agoAh, this just illustrates how much hardware companies suck at building software.
- losethos 13y agoYou would think notarized random numbers would be enough, but the faggots prefer tin-foil hats. God says... spunky huh whoo_whoo scum Catastrophic_Success kick_back You_get_what_you_pray_for obviously Shalom climate Boo theres_no_place_like_home lust I_see_nothing okay I_didn't_see_that I_donno you_know_a_better_God play Yo
- camkego 13y agoThis post, and other recent ones like it, indicate to me the importance of running a port scan and making sure no management abilities are exposed over the WAN side of these devices. Any suggestions on good, fast online port scanners?
- hughesey 13y agoThere's one at http://viewdns.info/ http://viewdns.info/ if you're only after common ports.
- rogerbinns 13y agoIn addition to management, a bunch of these can serve up files to the WAN side. On Netgear devices it is in a USB storage section. I do scans from cellular devices (Fing on Android and iOS, is passable for popular ports) and my laptop (nmap) when out and about.
- diminoten 13y agoA port scan won't pick this up, if you're coming in from the Internet. This is still behind the firewall, and even if it did pick up that, on your internal network, your router had an open port, that'd not be new information, as all routers have a web configuration interface.
- nwh 13y agohttp://portscan.me/ http://portscan.me/ will execute an nmap scan on the request address and print it back. Even works fine with curl.
- greglindahl 13y agoOne alternative to underpowered routers running OpenWRT or pfsense is to use a beaglebone black as your router. It's got well-supported wifi devices with antennae available, and you're not compromising on clock or ram.
- tux1968 13y agoExcept the BBB only does 10/100 Ethernet so can't really operate as a modern router. The advantage of say an OpenWRT modded D-Link DIR-825, is it includes a gigabit router that handles internal traffic while the cpu handles the firewall and vpn to the outside world. Because local traffic is handled by completely separate silicon inside the router, CPU and ram is not a constraint.
- greglindahl 13y agoI live in a small apartment surrounded by neighbors with wifi networks. 100mbit is plenty for the wireless portion of my network, and the wired portion doesn't need a firewall. Sounds like your constraints are very different.
- lmz 13y agoDoesn't that separate silicon handle switching, not routing?
- tux1968 13y agoyes you're right, thanks for the correction.
- ce4 13y agoWell, there are also more powerful options, e.g Buffalo's WZR-HP-AG300H, which has 128MB RAM / 32MB flash / Gigabit Ethernet and two radios. Not to forget: Power consumption is should also be taken into consideration for an always on device.
- holyjaw 13y agoI like that this was technical and informative, but still talked down to people like me who aren't at all knowledgable with how infosec works. Great read; wish I could find more like it.
- sillysaurus2 13y agoWhich part did you feel was talking down to you? I need to know in order to improve my own writing.
- LukeShu 13y agoI don't think he meant "talk down" in a negative way. I think he was trying to say that it clearly explained things to someone who doesn't know about the topic (while still being full of details to someone who does).
- girvo 13y agoQuestion: I have Cable internet here in Aus (100mb/10mb) and I like my connection, but we have to use Telstra's silly modem, and they refused to activate any other one on the network. So, lets assume I don't trust this AP and Modem to be secure (fair enough assumption in my opinion) -- the best way would be to perhaps build my own Wireless AP running pfsense, on a BeagleBone Black or similar? Cable -> Telstra Modem w/out Wireless -> pfsense AP -> Network Would that be the most secure way to handle that situation?
- tedunangst 13y agoSince pfsense won't run on a beaglebone, that's a non starter. I also have my doubts as to a beaglebone's ability to reliably push 100mb of traffic.
- girvo 13y agoAh, that was just an admittedly poorly-researched example. I basically just meant a board that'll run open-source code.
- cbrauchli 13y agoIf you have a Netgear WNDR3700v2 or a WNDR3800, check out Cerowrt [1]. The latest stable build, 3.7.5-2, has been exceptionally stable for me, and fast. I would highly recommend it. 1. http://www.bufferbloat.net/projects/cerowrt http://www.bufferbloat.net/projects/cerowrt
- chojeen 13y agoDo companies like Netgear not have a team whose only purpose is to try to break their own products? I thought that was a primary source of employment for infosec types.