Reverse Engineering the TP-Link HS110
softscheck.com
softscheck.com
The tdpServer binary regularly get abused to root TP-link devices for Pwn2Own Tokyo : https://www.thezdi.com/blog/2020/4/6/exploiting-the-tp-link-...
Also :
- https://mjg59.dreamwidth.org/51672.html - https://www.coresecurity.com/core-labs/advisories/tp-link-td... - https://medium.com/@CoreSecurity/a-story-about-tp-link-devic...
This part I don't get. Do they mean the firmware verifies the CA but NOT that the cert is actually for the domain/CN they want? If they made such a glaring mistake I would expect the write up to say it explicitly.
The way this is written seems to imply that all you need to impersonate a server is to buy a cert from the same CA it uses, which is obviously not the case.
Basically you can change cloud server address, but it will still check for symantec root, so you need to buy EV certificate from them.
edit
I’m not buying his argument that because the root certificate is on the image, that’s the only thing the script checks.
I have the HS100 which I use for occasional/seasonal automation (Christmas lighting etc).
I don’t like that all :(
I've come across a few other projects, but haven't written the links down. Here are some:
http://benlo.com/esp8266/KankunSmartPlug.html
https://tasmota.github.io/docs/Tuya-Convert/
And similar to the last one, there is the esphome project: https://esphome.io/index.html
That lets you do OTA upgrades to a basic tasmota firmware. Once that is done it's trivial to load full tasmota on there which gives you a MQTT interface & a basic webserver
> Phones home even if set up as local-only
This ought to be illegal.
If they don't, you imported and got what you paid for.
The article casually mentions
> After decompiling the Kasa app
How does one do that ?
I can get to the ARM dissasembly, but my disassemby reading skills are a bit poor. Is there an ARM decompiler I could use, that gives me some sort of C-like code? I found the Radare project, but I'm a bit stuck there.
The only line of defense the developers have is to obfuscate the code, but that only means that you will get access to a version of the source code where the original name of the variables, functions, classes was changed to abstract names so that code is harder to read. Even so, you are in much better state that going through disassembling an ELF binary.
On the reverse engineering side, is it... Legal?
I tried the script on one of my HS105's and noticed I had a location in there. Promptly removed it using the app, and it was gone from the next call of the script.
I think it's good I set those up on a separate very limited VLAN...