6 ms·
TCP backdoor 32764 – how we could patch the Internet (or part of it)
- tdmule 13y agoThe direct source of this information is the github page mentioned in the article, https://github.com/elvanderb/TCP-32764 https://github.com/elvanderb/TCP-32764
- lotsofcows 13y agoAnyone played with this? term1$ tcpdump -i en1 -X -n port 32764 term2$ telnet 192.168.0.1 32764 Output doesn't show the expected hex code. Is this naive?
- ancarda 13y agoYeah, I tried but with my external IP: $ telnet [redacted] 32764 Trying [redacted]... telnet: connect to address [redacted]: Connection refused telnet: Unable to connect to remote host Does this mean my router has no backdoor? Is it clever enough to avoid detection?
- mhurron 13y agoAre you running one of the affected hardware models?
- ancarda 13y agoNo, but I have a fairly uncommon router (not ISP supplied) so I was curious if it also had a backdoor. It doesn't respond on LAN so it seems my DrayTek Vigor 2750N is backdoor-free for now...
- sil3ntmac 13y agoCheck your internal IP as well, some models are only vulnerable on the LAN. Metasploit has a check module for this, and will also get you a shell: https://community.rapid7.com/community/metasploit/blog/2014/01/17/news-on-the-embedded-systems-land https://community.rapid7.com/community/metasploit/blog/2014/...
- deleted 13y ago[deleted]
- eschulte 13y agoThe use of the vulnerability to repair the vulnerability is very cool. I've done some related work, which may be of interest when one wants to patch a bad binary on the router (instead of simply removing a bad binary as done in this article). http://eschulte.github.io/netgear-repair/pub/netgear-repair.html http://eschulte.github.io/netgear-repair/pub/netgear-repair....
- dlitz 13y agoI guess this is yet another reason not to rely on firewalls and outdated notions of "internal" and "external" networks for any kind of real security. Increasingly, it seems that firewalls are doing less to improve actual security, while continuing to hinder legitimate network connectivity and the deployment of new protocols.
- gnu8 13y agoI think you're conflating firewalls and NAT. The idea of "internal" and "external" networks still apply in a non-NAT environment but what takes some getting used to is that with full end-to-end connectivity, you're back to an implicit "default-allow" policy where NAT created an implicit "default deny". The answer is to have a default deny firewall rule on your border router (your home gateway appliance), and then allow services as needed.
- zurn 13y agoEverything he said applies to a typical legacy corporate network that has a centralised default-deny firewall on front of it (but no NAT). Host-based firewalls are much more flexible and have many security advanteges.
- nmc 13y agoCorresponding shodan search: http://www.shodanhq.com/search?q=port%3A32764 http://www.shodanhq.com/search?q=port%3A32764 Edit: search directly for the vulnerability http://www.shodanhq.com/search?q=port%3A32764+ScMM http://www.shodanhq.com/search?q=port%3A32764+ScMM http://www.shodanhq.com/search?q=port%3A32764+MMSc http://www.shodanhq.com/search?q=port%3A32764+MMSc
- squigs25 13y agocool article - I do think the easy fix is port forwarding?
- matt_kantor 13y agoI'm disappointed that this wasn't taken to its logical conclusion: use the backdoor to remote-patch affected routers.
- jonalmeida 13y agoReminds me of the backdoor in D-Links routers: http://www.devttys0.com/2013/10/from-china-with-love/ http://www.devttys0.com/2013/10/from-china-with-love/
- wcdolphin 13y agoCan we use the exploit to actually apply this patch?
- TwoBit 13y agoI'm hoping that some day a lawsuit is successfully taken against a device maker who does this.