News: 1637652672

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Infosec bods: After more than a year, Sky gets round to squashing hijacking bug in 6m home broadband routers

(2021/11/23)


In brief Sky has fixed a flaw in six million of its home broadband routers, and it only took the British broadcaster'n'telecoms giant a year to do so, infosec researchers have said.

We're told that the vulnerability could be exploited by tricking a subscriber into viewing a malicious webpage. If an attack was successful, their router would fall under the attacker's control, allowing the crook to open up ports to access other devices on the local network, change the LAN's default DNS settings to redirect browsers to malicious sites, reconfigure the gateway, and cause other general mischief and irritation.

This exploitation is non-trivial: it involves luring people to a webpage that uses JavaScript to cause the browser to first use an attacker-controlled DNS server to lookup the IP address for a subdomain to connect to an outside server, then the browser is encouraged to reconnect to the server, the IP address is looked up again, and this time, the subdomain resolves to the local IP address of the router rather than the outside server.

[1]

Now the browser starts talking to the router as if it's the remote server, and the JavaScript on the page can access the router's web configuration panel. The browser thinks it's still talking to the remote server and doesn't get in the way.

[2]

[3]

This will work reliably if the subscriber hasn't changed their router username and password from the default of admin and sky; if the credentials have been changed, they'll have to be brute-forced. It's not too easy to pull off, but not impossible. Pen Test Partners (PTP), which said it found and disclosed this DNS rebinding vulnerability to Sky, made this video demonstrating the hole:

[4]Youtube Video

[5]

The security firm said last week it told Sky about the issue in May 2020, and developed a proof-of-concept exploit. Sky, according to PTP, said it would fix the issue in a November software update that year for its routers, but this got pushed back to December and then "early 2021." It was only when the vulnerability researchers started to talk to the press that Sky got a wriggle on and issued the patch, PTP said.

"Sky's communications were particularly poor and had to be chased multiple times for responses," PTP's Rafael Fini [6]said .

Police are [7]investigating the ongoing and near-month-long IT breakdown at Simplify , which operates Premier Property Lawyers and other brands.

It's understood the UK conveyancing giant was hit by some kind of potentially criminal cyber-security drama, the end result of the tech outage being home buyers and sellers were, or still are, unable to complete transactions and move.

In a note on its website on Monday this week, Premier Property Lawyers noted: "We are pleased to report that by the end of today, the majority of our conveyancing colleagues will be back up and running on core systems, and actively working on cases.

"Our team, supported by external experts, has been working non-stop for the past two weeks to get our systems safely back up and running and to ensure we prioritise the most urgent cases, enabling clients to move."

Microsoft squashes Azure privilege-escalation bug

Microsoft has fixed a flaw in Azure that, according to the infosec firm that found and privately reported the issue, could be exploited by a rogue user within an Azure Active Directory instance "to escalate up to a Contributor role."

"If access to the Azure Contributor role is achieved, the user would be able to create, manage, and delete all types of resources in the affected Azure subscription," NetSPI [8]said of the vulnerability, labeled [9]CVE-2021-42306 .

Essentially, an employee at a company using Azure Active Directory, for instance, could end up exploiting this bug to ruin an IT department or CISO's month. Microsoft [10]said last week it fixed the problem within Azure:

Some Microsoft services incorrectly stored private key data in the (keyCredentials) property while creating applications on behalf of their customers.

We have conducted an investigation and have found no evidence of malicious access to this data.

Microsoft Azure services affected by this issue have mitigated by preventing storage of clear text private key information in the keyCredentials property, and Azure AD has mitigated by preventing reading of clear text private key data that was previously added by any user or service in the UI or APIs.

"The discovery of this vulnerability," said NetSPI's Karl Fosaaen, who found the security hole, "highlights the importance of the shared responsibility model among cloud providers and customers. It’s vital for the security community to put the world’s most prominent technologies to the test."

Oh look, it's a new way to poison Linux-powered DNS caches

It appears boffins have found a way to bypass some DNS cache poisoning defenses, and, in the right circumstances, trick a DNS cache into accepting the wrong IP address as the answer to a domain-name lookup query. Subsequent queries for this domain-name from the cache by clients will return the wrong IP address. This could be exploited to, for instance, redirect netizens to malicious websites that masquerade as legit sites to harvest login credentials.

It's said that 38 per cent of public-facing open resolvers are vulnerable to this latest attack. Whether or not a DNS cache is vulnerable depends on the version of the Linux kernel it is running on, and the software involved, be it BIND, Unbound, or dnsmasq. See table 1 in this [11]academic paper [PDF] on the attack to work out whether your service is at risk of poisoning.

[12]

You can also use the ID CVE-2021-20322 to track kernel-level patches to thwart the attacks: here's [13]Debian and [14]Red Hat 's pages for the flaw, for instance.

The poisoning technique builds upon last year's [15]SADDNS approach. First, understand that DNS cache poisoning, as pointed out by the late [16]Dan Kaminsky , was possible by waiting for a DNS cache to query another server for a domain-name lookup, and replying to that query from another machine before the server. If you managed to guess, or brute force, the correct transaction ID in the reply in time, your answer would be accepted over the server, allowing you to poison the cache with a bad IP address.

To counter this, a randomized UDP port would be used for the query, meaning the attacker would have to brute-force guess the 16-bit transaction ID and the correct UDP port, making poisoning infeasible. Last year, SADDNS showed it was possible to figure out the UDP port, reducing the attack complexity and prompting [17]various patches .

This latest technique, devised by Keyu Man, Xin'an Zhou, and Zhiyun Qian at the University of California Riverside, is a side-channel attack: it involves spraying the cache with ICMP errors to determine the UDP port to use. The trio wrote the aforementioned paper, which was presented at the ACM Conference on Computer and Communications Security this month.

"This paper presents novel side channels during the process of handling ICMP errors, a previously overlooked attack surface," they wrote.

"We find that side channels can be exploited to perform high-speed off-path UDP ephemeral port scans. By leveraging this, the attacker could effectively poison the cache of a DNS server in minutes. We show that side channels affect many open resolvers and thus have serious impacts."

FBI warns of FatPipe zero-day exploit

In a flash notice

[18]PDF

the FBI has warned that criminals have been able to hijack FatPipe VPN devices using a zero-day bug since May.

[19]Will they try it for 30 days first? McAfee goes private again in $14bn cash deal

[20]Android has its head in the sand with AbstractEmu malware rooting phones

[21]If you're using this hijacked NPM library anywhere in your software stack, read this

[22]NFTs not annoying enough? Now they come with wallet-emptying malware

The Feds said they had conducted forensic analysis into an attack and found the exploited vulnerability in all FatPipe WARP, MPVPN, and IPVPN device firmware prior to the latest versions, 10.1.2r60p93 and 10.2.2r44p1. An attacker could use the security hole to upload a web shell on the equipment that would provide root access to the device. The FBI said this was used to commandeer VPN boxes and route malicious traffic to target parts of the US infrastructure.

Finding out if you're one of the victims could be tricky, however, since the attackers frequently used cleanup scripts to hide evidence of their activities. If you do find any evidence of an attack, please preserve it as the FBI would like to hear from you.

The US government wants you! If you do security

As part of its ongoing efforts to modernize and skill up in cybersecurity, the US Department of Homeland Security has unveiled new methods for finding and keeping talent.

Dubbed the Cybersecurity Talent Management System (CTMS), the framework may make it easier for Uncle Sam to recruit infosec types by allowing recruiters to hire people based on "demonstrated competencies" rather than holding industry certificates, streamlining the hiring process so candidates aren't waiting months, and enabling pay rates more in line with private-sector positions.

"The DHS Cybersecurity Talent Management System fundamentally re-imagines how the Department hires, develops, and retains top-tier and diverse cybersecurity talent," [23]said Secretary of Homeland Security Alejandro Mayorkas. "As our Nation continues to face an evolving threat landscape, we cannot rely only on traditional hiring tools to fill mission-critical vacancies."

For once, WordPress users not hit with ransomware

Over the past week or so, hundreds of WordPress users were greeted with a sight every webmaster dreads: their websites replaced with a message demanding 0.1 Bitcoin to decrypt and restore the sites' data.

Sucuri was called into one such case and had some good news. It's not actually ransomware.

The site content isn't actually encrypted: it's just hidden. A rogue plugin called directorist was generating the messages and hiding the posts. See [24]here for more info on which plugin to remove, and how to restore the vanished content with an SQL database command. ®

Get our [25]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YZzJ5Q54LWOOmkr8gVCl9QAAABA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YZzJ5Q54LWOOmkr8gVCl9QAAABA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YZzJ5Q54LWOOmkr8gVCl9QAAABA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.youtube.com/watch?v=M7liKMFw8Uk&t=2s

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YZzJ5Q54LWOOmkr8gVCl9QAAABA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.pentestpartners.com/security-blog/skyfail-6-million-routers-left-exposed/

[7] https://thenegotiator.co.uk/police-called-in-to-investigate-criminal-attack-on-simplify-it-systems/

[8] https://www.netspi.com/news/netspi-uncovers-critical-azure-vulnerability-credmanifest/

[9] https://www.netspi.com/blog/technical/cloud-penetration-testing/azure-cloud-vulnerability-credmanifest/

[10] https://msrc-blog.microsoft.com/2021/11/17/guidance-for-azure-active-directory-ad-keycredential-property-information-disclosure-in-application-and-service-principal-apis/

[11] https://www.cs.ucr.edu/~zhiyunq/pub/ccs21_dns_poisoning.pdf

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YZzJ5Q54LWOOmkr8gVCl9QAAABA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://security-tracker.debian.org/tracker/CVE-2021-20322

[14] https://access.redhat.com/security/cve/cve-2021-20322

[15] https://www.saddns.net/

[16] https://www.theregister.com/2021/04/25/dan_kaminsky_obituary/

[17] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25705

[18] https://www.ic3.gov/Media/News/2021/211117-2.pdf

[19] https://www.theregister.com/2021/11/08/in_brief_security_mcafee/

[20] https://www.theregister.com/2021/11/01/in_brief_security/

[21] https://www.theregister.com/2021/10/25/in_brief_security/

[22] https://www.theregister.com/2021/10/17/in_brief_security/

[23] https://www.dhs.gov/news/2021/11/15/dhs-launches-innovative-hiring-program-recruit-and-retain-world-class-cyber-talent

[24] https://blog.sucuri.net/2021/11/fake-ransomware-infection-spooks-website-owners.html

[25] https://whitepapers.theregister.com/



Oh, ther joys of running unverified code ...

Mike 137

" luring people to a webpage that uses JavaScript to cause the browser to first use an attacker-controlled DNS server [...] the browser starts talking to the router as if it's the remote server, and the JavaScript on the page can access the router's web configuration panel "

When will we finally catch on (after more than three decades now) that running unverified code from unknown sources is not a brilliant idea?

Re: Oh, ther joys of running unverified code ...

Warm Braw

Given that almost all the software that's written these days contains swathes of unverified code from unknown sources we need to get better at managing the consequences.

In this particular case, the fundamental flaw would seem to be that the Sky router has well-known access credentials on the assumption that everyone and everything on the LAN side can be trusted. That would seem to be poor reasoning as it means any person or any code with access to the local network can reconfigure the router.

Software protection mechanisms historically were there to deal with accidental programming errors: they need to be more robust in the face of deliberate malevolence. Knowing the source of code doesn't tell you much - it's easily disguised. And exactly what is 'verified' code? Do you run some sort of static analyzer? Do you have it reviewed by GCHQ? To the extent there is an answer, it's that we need to trust all code less, but there is a price to be paid in lack of convenience, which is where manufacturers, in particular, start to get cold feet.

Re: Oh, ther joys of running unverified code ...

gryphon

Even BT is slightly better in this regard which is unusual.

Default admin password on the latest home hub is about 12 characters semi-complex.

i.e. Numbers, caps, lowercase but no special characters as far as I remember

Re: Oh, ther joys of running unverified code ...

Al fazed

And you can't change the default password in another, very widely distributed home router, one which I am still waiting on the ISP's advice on how it can be changed, if at all.

ALF

Re: Oh, ther joys of running unverified code ...

Doctor Syntax

"Given that almost all the software that's written these days contains swathes of unverified code from unknown sources we need to get better at managing the consequences."

We also need to get better at not containing swathes of unverified code from unknown sources. The two approaches are complementary.

Does your website (a) complain or (b) fail to do anything at all when it finds a visitor running NoScript? If so, you're part of the problem.

Re: Oh, ther joys of running unverified code ...

Al fazed

The fact that any User can write html via a WordPress/GoDaddy/et/al App, without having any knowledge of object oriented programming etc. is leading to a majority of business web sites - which in the main - do not work. Or in other cases are working fine, BUT in ways that the creator never intended and FFS - the "owner" is totally unaware of any unwanted activity, because they are a CEO's of small business/charity/notforprofit/educational/health organisation etc., and have many other pressing CEO type issues to deal with day to day.

Which means that - we are going to be subjected to more and more of this zzz.zombieware.html as time goes by.

A computer driving licence was touted once in the UK - in the days of yore, but I've heard nothing more about it.

I mean, what is the difference between a "radio button" and a "tick box" when you are throwing together a Googledocs "form" in your tea break ? Which is of course vitally important to business knowledge and is going to be circulated amongst your actual Subscribers. You are asking them to complete said webform by clicking on the link in the eMail message .................... sent from a person who doesn't know how to "correctly" use the "form fields" provided in the eMail client and so compounds their meagre attempt at clusterfucking - and sends VIP message - from their private mobile phone eMail App.

I could go on - but what is the point ?

This point is that this issue is not going to go away or get any better is it ? When anyone and everyone can circulate really crap code at the drop of a hat, we'll carry on getting everything that we really really really deserve.

ALF

Man 1: Ask me the what the most important thing about telling a good joke is.

Man 2: OK, what is the most impo --

Man 1: ______TIMING!