VPNFilter malware infecting 500K devices is worse than was thought
arstechnica.com
arstechnica.com
That sounds as sophisticated as a drug dealer calling their pills “beans” or “almonds”. Like, it’s intelligent, but it’s just 1 step removed from just coding in the IP directly.
Personally, I'd have said "clever" and "probably indicative of a trend, which is going to continue" and "don't assume wiping EXIF headers stops this, because a bunch of meta data is out there in ways you don't yet understand"
hiding things in meta data, is why IP over ICMP works.
That way, destructive updates could be blocked for as long as possible. Or save you from having to re-flash your receiver through desoldering a TSOP.
Perhaps we need the same thing on routers.
Or a group to run a “honeypot” of routers with a sensor on this EEPROM pin to identify when unauthorized updates have been installed and need investigation.
This won’t work for non-persistent hacks. But for anything that wants to last longer than a reboot...
Looking quickly on a random manuacturer’s 93 series, I don’t see such a line, BUT, programming operations are blocked when the voltage is below a certain level. A couple diodes on the Voltage line could be put in séries (via switch) to prevent writes unless desired.
Of course, if writes are required at some level for normal operation, your chip firewall strategy works much better.
The paytv providers actually implemented a flash writeability check (without trIggerinf a write) upon bootup. One of my ideas was to emulate the 24-series eeprom entirely. For the bigger “TSOP” chips, someone devised a high-speed logic gate that was fast enough to allow the check to pass, but still prevent actual writes.
Anyone else having fun with the minor panic attacks incited by slow page-loads?
So unless you were capturing incoming packets at that time, we may not know.
it mentions snort rules for detection and protection for VPNFilter and ClamAV Signatures.
But it didn't explain how to use them.
The way I understand SNORT after googling it, I need to able captures the traffic (wan port) and feed that to SNORT for analysis, is that correct?
Also for ClamAV, do I need to clone/mount the rootfs from the wifi router to Linux and use ClamAV to scan that rootfs for those signatures?
The URL mentions the infested device have /var/run/vpnfilterm, /var/run/vpnfilterw. I checked they are not in my wifi router's fs.
The URL also mentions it modified/insert entry the crontab, but I can't find what exe name, possible file locations I should search in my router. Do anyone else know such info?
Some were due to vulnerabilities in the router's web admin. Mikrotik routers were compromised in this way. In this case, it was not a default password issue (as their is no default password on Mikrotiks), but an attack that would work regardless of credentials. Anyone running firmware older than March 2018 who was not smart enough to block port 80 on their public interface likely got owned. Mikrotik is not a consumer router, but they are cheap and powerful, and thus attractive to end users, many of whom don't know what they are doing. Thankfully, the Mikrotiks are easily fixable. Upgrade the firmware, and stage 1 gets wiped out.
But most consumer routers, by default, do not expose the web admin in this way, and were compromised by some other vector, and we have yet to get to the bottom of all of them. Many of these routers, due to their architecture, cannot be fixed with a firmware upgrade.
Obviously the idea is to make sure the image in ROM is simple enough that it's really damn unlikely that it can be attacked, or attacked before the correct and intended firmware is downloaded and installed.
(I’m on my phone or else I’d look into this more and give you more specific info instead of vague recollections but, if you (or anyone else here) are interested, this should at least give you somewhere to start.)
It’s almost like no one considers it worth the effort.
Then they got rid of that, even though most people that bothered with BIOS updates could be directed to switch a jumper around...
About the only thing I would trust without updates is a bsd box. And even that, may eventually fall victim.
[1] https://github.com/mirror/dd-wrt/blob/master/src/router/http...
[2] https://github.com/mirror/dd-wrt/blob/master/src/router/http...
You just reminded me that some of the more obscure dd-wrt bins (for not so popular routers) and might be dangerous stuff.
> Williams said he has seen no evidence VPNFilter has infected devices running Tomato, Merlin WRT, and DD-WRT firmware, but that he can't rule out that possibility.