News: 1712694607

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

D-Link issues rip and replace order for besieged NAS drives

(2024/04/09)


D-Link is telling owners of expired NAS devices to pack them away and replace them with newer kit following the publication of security vulnerabilities that together are now being actively exploited.

It doesn't help that the devices, that reached their end-of-service (EOS) date years ago, have a backdoor (CVE-2024-3272, CVSS: 9.8 - critical) enabled by hardcoded credentials (username: messagebus, plus an empty password field).

This, combined with a command injection bug (CVE-2024-3273, CVSS: 7.3 - high) means attackers can remotely execute code (RCE) on the device, and with that do all manner of follow-on activities. User data is believed to be at risk.

[1]

The issues were first published by a researcher who uses the alias "netsecfish" on March 26, who at the time could only recommend applying vendor patches that would never arrive.

[2]WD My Cloud NAS devices have hard-wired backdoor

[3]D-Link router riddled with 0-day flaws

[4]D-Link resolves enterprise switch hacker risk

[5]D-Link FINALLY slams shut 'Joel's backdoor'

"Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the system, potentially leading to unauthorized access to sensitive information, modification of system configurations, or denial of service conditions," they [6]said .

At the time the research went out, more than 92,000 vulnerable devices were facing the internet, the majority of which were based in the UK, although thousands were also vulnerable in Thailand, Italy, Germany, and more.

[7]

[8]

The following models are vulnerable:

DNS-340L (reached EOS in 2019)

DNS-320L (reached EOS in 2020)

DNS-327L (reached EOS in 2020)

DNS-325 (reached EOS in 2017)

D-Link has held firm in its EOS assessment, reiterating that no firmware updates will be released for the affected devices, regardless of the latest security holes.

"This exploit affects legacy D-Link products and all hardware revisions, which have reached their End of Life /End of Service Life-Cycle," it said in an advisory.

"Products that have reached their EOL/EOS no longer receive device software updates and security patches and are no longer supported by D-Link.

[9]

"D-Link US recommends that D-Link devices that have reached EOL/EOS be retired and replaced."

The vulnerabilities lie in the nas_sharing.cgi CGI script which can be targeted by a malicious HTTP GET request that includes the hardcoded credentials, plus a malicious command string.

As of Monday, both GreyNoise and Shadowserver both reported seeing active scans and exploit attempts of CVE-2024-3273.

[10]

"Exploit and PoC details are public," Shadowserver [11]xeeted after confirming attacks from multiple IPs. "As there is no patch for this vulnerability, these devices should be taken offline/replaced or at least have their remote access firewalled."

GreyNoise observed attacks in which miscreants were attempting to deploy a variant, skid.x86, of the [12]Mirai botnet on devices. Mirai is routinely used to carry out [13]distributed denial of service (DDoS) attacks.

D-Link was approached for additional comment but it didn't immediately respond. ®

Get our [14]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZhW6hCI47O4KquZoqiJ44gAAAMQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.theregister.com/2018/01/08/wd_mycloud_nas_backdoor/

[3] https://www.theregister.com/2017/09/12/dlink_router_security_fail/

[4] https://www.theregister.com/2017/02/27/dlink_router_flaw/

[5] https://www.theregister.com/2013/12/04/dlink_finally_slams_shut_joels_backdoor/

[6] https://github.com/netsecfish/dlink?tab=readme-ov-file

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZhW6hCI47O4KquZoqiJ44gAAAMQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZhW6hCI47O4KquZoqiJ44gAAAMQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZhW6hCI47O4KquZoqiJ44gAAAMQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZhW6hCI47O4KquZoqiJ44gAAAMQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[11] https://twitter.com/Shadowserver/status/1777303656096039386

[12] https://www.theregister.com/2023/11/23/zeroday_routers_mirai_botnet/

[13] https://www.theregister.com/2024/03/24/loop_ip_vulnerable/

[14] https://whitepapers.theregister.com/



Great business plan!

may_i

1. Make something useful

2. Put lots of security holes in it

3. Stop updating it and fixing the holes

4. Offer a new version with new holes

5. Profit!

I have a similar, cheap as chips, Zyxel NAS. It was also full of holes plus some spyware that tried to download everything I uploaded to it.

It runs Debian now. It can't be reached from the Internet and doesn't open any external connections either. It's a great backup device for my real NAS. No replacement needed!

Enabled by hardcoded credentials

abend0c4

Not a flaw caused by the ageing of the hardware - or indeed the software - so I'm not sure why supposed life-expiry is relevant.

You can "TRY" patching that NAS with ALT-F

williamyf

ALT-F Provided ALTernative-Firmware for D-Link NASes, many of which are the subject of this CVE. AS an added bonus, said updates provided support beyon the SMB1 only support D-Link provided.

I do not have a D-Link NAS, and heard about ALT-F thanks to user jm1 over at Ars

I say "provided" because the last major firmware they provided is dated 2017, and the last patch of said FW was a few months latter. But still, better than nothing, I guess, doubly so if it plugs this particular hole.

A little more time to save up for a newer NAS from a reputable source, and with a decent CPU, so it gets a long support window

Other than that, you know the ussual routine: block acess to the NAS to and from the internet, harden the NASs security configuration, etc...

Link: https://sites.google.com/site/altfirmware

Re: You can "TRY" patching that NAS with ALT-F

may_i

Just don't make your NAS accessible from the Internet. Even if you *think* it is fully patched. Is anything really that important that you're prepared to make your NAS a honeypot?

Even if your shiny new NAS is from "a reputable source", it isn't suitable for putting on the Internet.

A long time ago, I had a QNAP NAS. I used their service which functioned as a proxy so that I could access my NAS when I was away from home. It was only when I heard the NAS running its fan at full speed when it wasn't supposed to be doing anything that I found out I had been owned. Some enterprising people had broken in to QNAP's proxy and planted their Monero miner on tens of thousands of customer machines.

I was lucky this was before the ransomware gangs got started.

IN MY OPINION anyone interested in improving himself should not rule out
becoming pure energy.
-- Jack Handey, The New Mexican, 1988.