8 ms·
D-Link patch doesn’t address all bugs listed in their own security advisory
- carey 11y agoI guess this is a reminder that writing secure C is actually really, really hard.
- maxk42 11y agoThese are not problems with C. These are problems with a shitty dev team.
- pyre 11y agoOr a reminder that when someone sends you a list of things wrong, maybe you should read and understand it rather than applying a 2 second fix that doesn't actually fix anything?
- psychometry 11y agoI don't write C at all but aren't there code analysis tools that catch things like this? Some kind of standard code linting library, maybe?
- andrewchambers 11y agoYes, the point is that these are obvious flaws, and dlink didn't even fix them. Someone from the dlink team just sucks. edit: And that someone may not even be the developer, at the end of the day, the company does not have the systems in place for quality control.
- jheriko 11y agoYes there are these things, although usually more focused on C++ these days. Compiling C as C++ with a C++ compiler is not a bad idea though... many compilers which will deal with both and tend not to care about pure C very much at all. Modern, extremely popular compilers may not even support C89 features yet... not to mention that lots will allow dangerous things like returning nothing from a function with a non void return type without even a compile error. Many tools can catch the bugs mentioned here though - things like PVS studio, cppcheck, or the built in visual studio or xcode analysers (I would never recommend pc-lint, sorry), and some of these things mentioned are compiler warnings in some cases (sprintf will trigger the endlessly annoying CRT_NO_SECURE_WARNINGS message from the ms compiler for instance).
- rpcope1 11y agoModern, extremely popular compilers may not even support C89 features yet... Citation needed please. Also, because C is not a true subset of C++, it has seemed that many big C projects will not compile on C++ compilers because of corner cases, so this may be something to watch for. Much of the incompatibility rises from additions in C99. References: (http://www.geeksforgeeks.org/write-c-program-wont-compiler-c/ http://www.geeksforgeeks.org/write-c-program-wont-compiler-c..., http://david.tribble.com/text/cdiffs.htm#C90-vs-CPP98 http://david.tribble.com/text/cdiffs.htm#C90-vs-CPP98)
- jheriko 11y agowell spotted, that should have been C99, of which many features are not supported with the ms compiler. i believe that the variable array thing was pulled in C11 because so few compilers ever bothered to support it... i see problems with it regularly where we use c code that goes through clang just fine, but cl complains. not putting declarations at the top of a file or scope is the obvious example that comes to mind and constantly snags people... that being said there are even C++ problems, although smaller. for instance, its impossible to use the preprocessor variadic macros across cl, clang, gcc without getting warnings from at least one of them. i like to run with warnings as errors and the highest warning settings possible. i'm not going to bother digging up references for informal conversation... but thanks for catching the mistake.
- comex 11y agoWriting completely secure C is hard, but this code is littered with extremely basic bugs like unchecked sprintf and not sanitizing arguments to system. Like, it's a basic rule that you should use snprintf instead of sprintf, possibly with exceptions for cases where you're absolutely sure the result fits in the provided buffer, and in this case there is sprintf everywhere and no checks on the input size whatsoever.
- cremno 11y agoI agree, but I don't think mentioning such an exception is a good idea. That's basically the same reason why gets() is part of ISO C90 and C99. Just call snprintf() even in such cases and forget about sprintf(). From http://www.open-std.org/jtc1/sc22/wg14/www/C99RationaleV5.10.pdf http://www.open-std.org/jtc1/sc22/wg14/www/C99RationaleV5.10..., PDF page 163: >The Committee decided that gets was useful and convenient in those special circumstances when the programmer does have adequate control over the input, and as longstanding existing practice, it needed a standard specification.
- comex 11y agoFair enough... it's not like snprintf has any noticeable overhead. Sometimes I use sprintf just to indicate to readers of the code that the output is not expected to be truncated, but that's probably too cowboy for my own good. For the record, when writing new code, I'd strongly recommend that people consider using asprintf instead of either function.
- userbinator 11y agoI wonder where this "length blindness" comes from, since it certainly leads to a lot of vulnerabilities. Are these programmers who started with a higher-level language than C, one with dynamically sized strings that automatically expand? Do they even know how big the buffer is, or how long the input string could conceivably be? Did they ever consider the case where the input is very, very long? A funny analogy I've heard is "programmers who don't know the size of their buffers are like drivers who don't know the size of their cars."
- kabdib 11y agoWell, maybe just one "really" What is really hard is finding decent firmware engineers. Ones who care, and who can write secure code. Even harder, finding a management chain that values security and that is willing to pay for it, and its continual upkeep (because security is a process, not a feature that you can complete and move on from).
- fnordfnordfnord 11y agoThings like this make me so happy to have things like DDWRT, OpenWRT, et al.
- scott_karana 11y agoWhy would you still be comfortable using an incompetent company's hardware, even if you fixed the software issue? Does anyone do meticulous teardowns of routers, much less documenting what silicon is present?
- simcop2387 11y agoThe OpenWRT wiki pages for the routers usually has some detailed info about the hardware. That won't tell you about hardware problems they might have that they didn't investigate but you can usually find photos of the boards to see what's there. [1][2][3] [1] http://wiki.openwrt.org/toh/tp-link/tl-mr3040#photos_v10 http://wiki.openwrt.org/toh/tp-link/tl-mr3040#photos_v10 [2] http://wiki.openwrt.org/toh/linksys/wrt610n#opening_the_case http://wiki.openwrt.org/toh/linksys/wrt610n#opening_the_case [3] http://wiki.openwrt.org/toh/netgear/wndr3700#photos http://wiki.openwrt.org/toh/netgear/wndr3700#photos
- wtallis 11y agohttps://wikidevi.com/ https://wikidevi.com/ also has detailed information about what chips are used, often gathered from FCC filings. Atheros, Broadcom, etc. are a lot more trustworthy than D-Link and Netgear. Once you've identified a router as having an Atheros SoC and a firmware update format supported by OpenWRT, you really only need to worry about it having bad power supply and antennas.
- rpcope1 11y agoYes, typically home routers tend to use pretty industry standard chips like Broadcom chips (like the BCM5357 in my home router). D-Link, Linksys, and crew don't usually roll their own SoCs, but just seem to throw off the shelf stuff in there. These chips tend to be SoCs, and while I can't be totally sure that there isn't a weirdo NSA backdoor on it (probably just as likely as any other router, residential or commercial), most of the meat lives in the chip, and with good open source firmware (DD-WRT et al.) it's probably just about as reasonable as anything else coming and going. I certainly have far more faith in a regular off-the-shelf SoC + open source firmware tuned to my own needs (and believe or not thisn't hard at all) than anything with propriety firmware, including (and especially, to me) Apple. Maybe the next best thing to do is to build your own WiFi router from totally off the shelf parts (not so hard to get into a small form factor any more). As to inspecting the SoC itself, that would be certainly interesting. Most of them are just ARM SoCs; this might make for an interesting blog post looking at the silicon.
- sdrinf 11y agoMirror for Database Error'd: https://archive.today/D33zV https://archive.today/D33zV
- deleted 11y ago[deleted]
- Havoc 11y agoI've just accepted that residential routers are full of assorted orifices (security holes, backdoors & holes in functionality). Then again I'm not hiding anything dubious - if I was I'd install a firewall box asap. (And yes I know the "nothing to hide" slippery slope etc argument)
- wlesieutre 11y agoI'm guessing that Apple's are better than average, since they have two versions (the built in HD on a time capsule doesn't make it appreciably different) and maintain them for long periods between upgrades. Asus/Netgear/D-Link/etc follow the "If we don't release an 802.11ac router every week, we won't get enough press releases out!" model, and their firmware suffers as a result. I'm not touching those unless I can wipe the stock firmware and replace it with Tomato or DD-WRT.
- rosser 11y agoI recently bought an Asus AC-1900 router (the RT-AC68W) after a long search, specifically for its supporting DD-WRT.
- lstamour 11y agoI would trust Apple's even more if the firmware releases were as regular as iOS updates. And the same goes for AirPort Utility releases, especially on Windows.
- 13 11y agoI have to run the configuration tool in a windows VM because on 10.10 they removed the frameworks it uses to run. I wish they weren't so complacent as to turn my hardware into bricks.
- ssmoot 11y agoMaybe you just need to reinstall it? I just took a peek at it on my new laptop (which has never had anything but Yosemite installed on it) and it worked fine.
- kkl 11y agoInteresting. The D-Link security advisory (http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10054 http://securityadvisories.dlink.com/security/publication.asp...) states that the issue was only partially resolved. What was changed (aside from adding an additional buffer overflow) in the patch that attempted to alleviate these issues?
- Buge 11y agoLike the article says, they make sure the command to system is one of their php files before running the system command.
- ariendj 11y agopfsense on a thin client = 40$ OpenWRT on a home router as AP = 30$ Not getting pwned = priceless
- Narkov 11y agoThe problem is that mom and pop can't possibly be expected to do this. They are trusting that the device they buy or the device their ISP provides, is secure.
- serve_yay 11y agoIndeed, but I don't think ariendj was talking to mom or pop.
- joejoebob 11y agoWhat are you running pfSense on for $40?
- un1xl0ser 11y agoI think that he means per month in electricity costs. ;)
- joejoebob 11y agoSeems a little high to me, but it does make more sense.
- ariendj 11y agoIt's the HP T5735. It's second hand from ebay. I got the fat version that has an extra PCI slot and I put a Realtek gigabit NIC in there. It's fast enough for home use, it does not saturate with my 200 megabit link. I use a TL-WR1043ND as an access point and VLAN-capable switch.
- un1xl0ser 11y agoI switched from OpenWRT to pfsense a while back and I am never going back. It runs great in a virtual machine, if that's your thing and you already have a need for VMs.
- TheCowboy 11y agoI inherited an office with a D-Link router being used that kept misbehaving. I tried upgrading the firmware as a last resort, since DDWRT and the others don't work on it. Digging around I found a thread where customers were wondering what happened to bridge mode and why it had been removed. An obdurate admin informs everyone that D-Link decided it wasn't needed as a feature, so they removed it. The admin is very coarse and ends up locking the thread. It seems ridiculous that, for a hardware product, a company would decide to remove features in a firmware upgrade. There is a work around, but even if it is a legitimate thing to do, it seems like a terrible product and engineering culture to be this condescending to customers. Relevant thread: http://forums.dlink.com/index.php?topic=4542.0 http://forums.dlink.com/index.php?topic=4542.0 End of story: The router ended up going in the trash after other issues, along with two different D-Link models. It's not the best idea to use consumer grade gear in an office, but then I replaced it (as a temporary fix) with an even older Linksys WRT54GL flashed with DDWRT with no problems.
- FireBeyond 11y agoI had that router. To be clear, when they "removed bridging" they "removed, via adding a CSS 'display:none;' block to the radio button", and the workaround was inspecting the HTML and removing the CSS. NOT that you should have to, by any means whatsoever.
- UnoriginalGuy 11y agoI used to own a D-Link DIR-655. It had a hilariously terrible bug: It had a scheduler built in, so you could set WiFi to turn off overnight, amongst other things. The scheduler web interface would only accept a range in the same 24 hr day, if you tried to set it to e.g. start (WiFi off) at 11 pm and stop (WiFi on) at 5 am, it refused with an error (paraphrasing) "end time must be after begin time." It was ONLY a JavaScript issue. You could trivially bypass it using a developer bar, and it worked perfectly. But they never fixed the JavaScript in all the years I owned it (and I doubt it is fixed right now today).
- machinesofn 11y agoTCP did that with their smart bulbs. They removed the local web interface in a silent update, bricking the bulbs for a lot of users. It's really bad manners, and I wish they would at least have options to re-add the missing features. It ultimately just alienates customers.
- shmerl 11y agoIt's better to stick with OpenWRT or DD-WRT.
- click170 11y agoCare to share your opinion of why that is? Have you compared Tomato? What problems or deficiencies did you identify? More detail would be helpful.
- tdicola 11y agoIsn't Tomato way out of date? Wikipedia shows the last stable release was almost 5 years ago, and the website shows no dates on its releases (not a good sign). I ran Tomato for a long time and loved it, but I just got too nervous running such old software as the gateway to my network. Ended up upgrading to a cheap TP-Link router, switching to the latest and greatest OpenWRT release, and haven't had any complaints at all.
- ramidarigaz 11y agoThere are forks of Tomato that have been updated much more recently. I'm running the "Toastman" build of Tomato.
- tdicola 11y agoAh, I wonder why doesn't the original project just fold up and point people at the currently maintained version. I'd still be very nervous about trusting my network to a random fork of mostly unmaintained software. At least with OpenWRT there's a very clear view into the (quite active) development, roadmaps to next releases, etc: https://dev.openwrt.org/roadmap https://dev.openwrt.org/roadmap
- simon_vetter 11y agoYou can disable their http/https/telnet interfaces and stick to ssh with key auth for administrative tasks. That alone should help. Also, they come with upnp and other unnecessary daemons disabled which greatly reduces their attack surface.
- eyeareque 11y agoCheap SOHO routers: Sadly, you get what you pay for.
- wtallis 11y agoPaying more gets you better radios and more GigE ports. It doesn't get you less-stupid software. "Friends don't let friends run factory firmware" applies regardless of the price.
- aioprisan 11y agoI can't believe how laughably bad router security still is. It's fascinating how these exploits came to light. Where do you even start to map to the related system calls?
- deanstag 11y agoI was in a dev team for a network security appliance. It is really sad they way they treat vulnerabilities and security advisories. There were very few people who know what the actual vulnerability was.The vulnerability would be listed as one of the last items in a release checklist. Gets assigned to a guy who has no clue whatsoever. The guy fixing the issue would google a patch. apply it. has no way of testing it comprehensively. He will run a basic test case. He will make up a report with a lot of security jargon for the managers and advisory team. And the next release would list the vulnerability as fixed.
- jheriko 11y agothis guy clearly has a passion for security. d-link could do well by firing whatever uncaring 9-to-5 programmers they have and hiring him. part of the problem is that people with this kind of passion and skill are few and far between... is very rare that good people want to work for a company like d-link on something like drivers or router software.
- deleted 11y ago[deleted]
- marcosdumay 11y ago> d-link could do well by firing whatever uncaring 9-to-5 programmers they have and hiring him. That's a great experiment to discover how long somebody can can stay passionate inside an uncaring corporation. I give him 2 years to become an uncaring 9-to-5 programmer.
- jheriko 11y agogood point... i do think it is pretty hard to stop caring though, what happens generally is that if you start to get that demoralised you will leave and find something else. :)
- yuhong 11y agoI wonder which vendors have the best firmware.
- deleted 11y ago[deleted]
- zurn 11y agoAre there any left that are owned by semi-reputable big companies? Back when Cisco had Linksys there was some hope that they'd at least look after the vulnerability handling and patching process in a grown up way.
- otterley 11y agoThe Apple Airport Express is reasonably cheap, has a great range, is easy to configure, and doesn't have a reputation for being insecure.
- Osiris 11y agoFactory firmware on SOHO routers is notoriously terrible. You'd think that this would be a good place for a startup to disrupt. The hardware is basically off-the-shelf components. It would be an easy sell to experts, but maybe harder to get traction with most people.