Cisco routers in at least 4 countries infected by highly stealthy backdoor
arstechnica.com
arstechnica.com
Then you log in and install a patched firmware containing your backdoor.
It's hardly Cisco specific. Surely any router (or any device for that matter)that has a known default username and password can be exploited in this way?
Am I missing something here?
If your lab allows internet access, you would probably be exploited within seconds of booting for the first time.
There are sophisticated ways to employ very unsophisticated exploits.
A cisco router with a blank config will come up with all interfaces configured "shutdown" and with no passwords set. You access it via a serial port on the front, labeled "Console". It provides a command line almost, but not quite, entirely unlike a unix shell :-) where you enter commands (ping, show routing tables, ..) or configuration statements (config terminal // Interface FastEthernet 0/0 // ip address 10.1.1.1... // no shutdown).
If the only thing you do is to give it an ip-adddress on an interface and enable it, it will have a passwordless login via telnet.
Every ISP/network department not run by complete imbeciles will have a "standard config" regarding login and passwords: Ours back in the days was a TACACS server for running user authentication, setting access levels for particular users (and automated logins for configuration management) and logging of logins/executed commands. You can also configure access lists that logins are only allowed from specific IP addresses. Probably also have a hardcoded password as fallback when the authentication server isn't reachable, disable the console port for when your router isn't in a locked box, ...
http://www.cisco.com/c/en/us/support/docs/security-vpn/secur...
Chromebooks work like that, too. Like, if you want to change shit on it without verification (say, to install Linux), you need to switch to "Developer mode" which cannot be done remotely, you need to push a pencil into a hole on the Chromebook or something like that.
Routers usually sit outside the firewall in typical network designs. The backdoor listens to raw network traffic coming in for the trigger, before any firewall rules on the router itself are processed.
All in all, it is very well designed and part of an extremely advanced attack.
https://www.techdirt.com/articles/20140518/17433327281/cisco...
The person you were responding to had no evidence to back their claim (in this particular instance), but neither do you.
I'm not particularly a fan of the comment in question, it was a bit confrontational for my taste, but I also think evidence in support of a position should be relevant, and I view this evidence as only loosely relevant, if that, to the stated position. Whether it's from the source article or not is besides the (or at least my) point in this case.
If someone were to make a persuasive argument that the initial method of infection actually mattered to the NSA (which I haven't seen yet), I might change my position.
"Foiled again! We found this high value computer network, but using a default password to break in is too crude for our tastes."
I don't care where the facts take us, but that observation does nothing to tell us what is going on here.
You talked to him offline? Because he didn't actually write that.
What he said is "Probably not", in reference to the NSA being involved. He then quoted a line that doesn't support his "Probably not" assertion.
Rhetoric: language designed to have a persuasive or impressive effect on its audience. Casually: without definite or serious intention.
From a logical standpoint, that sentence fragment is a representation of cognitive dissonance given it states there is and is not intent to impress (raise interest). I'd consider rephrasing it.
The moral drama in this story is much less interesting than the technical phenomenon, especially when we barely have an inkling of what's happening technically.
I recall there was a Swede (the grue?) on the Pull the Plug IRC network who was cross-compiling and linking in backdoored object code in Cisco IOS images already back in 2000.
Also we need an inventory of where things can be hidden in devices. Are there embedded flash areas where are they?
A modern reinstall should:
1) Reinstall the operating system from a known good source 2) Flash all firmware and flash chips with known good code.
Both operating system and firmware should be open source so you can inspect the code.
I do not know of an open source router hardware that is available (at ISP scale)
Getting an X86 box and throwing freebsd and quagga on it might work for small amounts of traffic. But for ISP scale bandwidth your stuck with a few main vendors...
You're basically correct but it's worth remembering that it is possible to add a bunch of quad nics to whitebox and run bpf on it, courtesy of one of the BSDs and do real routing at an ISP scale.
That would be completely open source (and quite secure).
Probably pretty performant if you knew what you were doing.
Its never going to work in a core network routing 100s of gigs of traffic. So it's not going to work for ISPs
How so? Is there anywhere a list of hashes of software that multiple people independently from each other verified, compiled (and compared)? Because without that, "open source" adds 0 to security in the scenarios we are talking about here.
Additionally, how many packages/firmwares have you inspected the last, let's say, decade? If I were a betting man, I'd put my money on 'less than I can count on one hand' (well maybe you're in infosec and get paid for audits...)
Which open source projects have deterministic builds, with a verifiable source of signature information - be that concensus or a source of truth that is verfied by concensus, so that I can be sure that either a) the binary I download has a very high certainty of being correct, or b) the source code I downloaded and compiled from has a very high certainty of being un-modified.
With a vendor, they don't need deterministic builds so badly, as they push a single file, and an authoritative source of signatures.
I have an example of a binary where the difference between a remotely exploitable service and a fixed version of the same service is a single bit. That bit (or some other bit that also changes the code's functionality in an important way) can be changed by any person or (potentially compromised) computer in the chain of compilation, packaging, and distribution unless someone has a way to tell whether what those people and computers assert is "correct". If the binaries routinely change appreciably every time someone cuts a software release, it's going to be expensive to go back and check whether there's also a malicious change, bearing in mind that the person whose computer made the change doesn't have to have been malicious.
And in the mean time, a million monkeys have social-engineered your secretary's machine through a Farmville js trick and pwned your network 3 ways from Sunday.
The point is that should be able to read the source code like a recepie for your cake. If someone hides the recepie and tells you its a yummy cake but you know its full of exploits its not.
Main point is, if it can be hacked it will be hacked. It´s better that we can read the source code and verify that the software in our devices has not been tampered with.
What I am confused about is that I assumed IOS images were signed. How are people creating backdoored IOS images without failing signature checking? Maybe they patched rommon?
> In an interview with Reuters, FireEye CEO Dave DeWalt said, "That feat is only able to be obtained by a handful of nation-state actors." In any event, there's no doubt that the devices were infected by a professionally developed and fully featured backdoor.
http://www.phenoelit.org/stuff/FX_Phenoelit_25c3_Cisco_IOS.p...
N.B.: I'm referring to BFRs running IOS. I have no idea how the SMB series are configured by default.
Whatever negative impact this has on their own business is fully deserved at this point.
Yet one more reason to say that rms right was right all along.
http://www.cisco.com/c/en/us/tech/security-vpn/lawful-interc...
Those features are disclosed to the customers and are meant to be used with their knowledge, if at all. It might be easy to confuse this with other spying features that Cisco could include in routers that are meant to be used without customers' knowledge.
The information that I've seen about U.S. government attacks against Cisco customers would be consistent with the hypothesis that Cisco is unaware of the details of these attacks and doesn't intentionally facilitate them, but maybe there's other information out there.
Just as the allegations that Huawei is collaborating with the Chinese spy agencies are unfounded, there is no evidence that Cisco has collaborated with American spy agencies.
Cisco has been the victim of espionage, however (and the theft has been remedied). [6][7]
[1] http://alcatel-lucent.com/wps/DocumentStreamerServlet?LMSG_C...
[2] http://www.cisco.com/c/en/us/tech/security-vpn/lawful-interc...
[3] http://www.ericsson.com/us/ourportfolio/telecom-operators/la...
[4] http://enterprise.huawei.com/ilink/enenterprise/download/HW_...
[5] http://www.juniper.net/documentation/en_US/junos12.2/topics/...
[6] http://archive.arstechnica.com/news/posts/1084683212.html
[7] http://blogs.cisco.com/news/huawei-and-ciscos-source-code-co...
According to Snowden's files, Cisco is among those companies that have strategic partnership with NSA http://revolution-news.com/strategic-partnerships-new-snowde...
Plus, this http://electrospaces.blogspot.gr/2015/04/some-equipment-that...
Your second source shows a slide that has a picture of some networking equipment, which the website claims is manufactured by Cisco. Presumably I could "collaborate" with Whole Foods by buying some mangoes, if I use your definition of "collaborate".
Please use factual premises to support your assertions. Some HN commenters actually critically review sources! I'm not claiming that no malicious collaboration exists, just that there's no evidence.
The focus on the "Revolution-news" site (Btw It's NOT the source of the said slides) and your godawful example about the mangoes speak for itself.