Complete, Persistent Compromise of Netgear Wireless Routers
shadow-file.blogspot.com
shadow-file.blogspot.com
Right now, the best supported devices are ath9k's, so things like the Buffalo WZR-* models are ideal.
The WNDR 4700 model specifically doesn't have good support for 3rd party firmware [2] due to it's use of NAND flash in an unsupported manner, so if you have that model you're kind of sunk at this point.
I'm using an old mini-ITX IPC board from Jetway with one of the first dual core Atom cpus, 1GB of ram (overkill) and 4 x Gbit ethernet ports. With a slim case / power supply I think it was ~$250 about 5 years ago when I bought it.
Other than moving apartments it's only ever been rebooted once, to upgrade from pfsense 1.2 to 2.0. It's never crashed and never caused a problem, and I beat on my network connection. OpenVPN performance from outside is only limited by my WAN speed. It's been awesome.
I also use pfsense in a VM in front of a bunch of other VM's on a VMWare server and it works great for that as well.
I've used an old eMachines PC with a couple of network cards and a switch in the past. An order of magnitude better than the Linksys router from my ISP it replaced. Also never had to reboot until I moved.
Never tried it as a VM front before. Good to know it's another option.
That said, when you bring their strange "packages" into the mix, all hell can break loose. So be careful.
As for how this relates to the exploit discussed here, your only using it as an AP, you'll very rarely need to login after the first setup since it really isn't doing much, just Wifi <-> Ethernet bridging. If using a consumer router the WAN port isn't connected to anything, no outside access to worry about (unless you did some funky forwarding on the pfsense box). You should also disable management via Wifi. That limits any access to a wired connection to the network, meaning someone is already in your apartment to physically patch in with an ethernet cable. Any security bets are off at that point. If you want super extra special security you can setup firewall rules on the pfsense box that only make the AP's IP address accessible from a particular port.
As dumb as this exploit is on the part of netgear, remember that to exploit it the attacker had to have already broken the WPA2 security to access the wifi or physically plugged in with ethernet. The first vector can be avoided by simply turning off management via wifi.
Or accessed your router internally via JavaScript, img tag, or iframe hidden on a malicious or compromised page. XSRF is real.
Edit: granted, browsers limit what JavaScript can do across sites, but request-only access is enough to change DNS settings to something malicious, and if the attacker can inject unescaped content into the page in some way, then they can run JavaScript on the router page and send data back that way.
Edit2: I'm not certain, but I think the timing of image load events could be used to determine success/failure of router actions loaded through a hidden img tag.
Edit: oh hello downvote, I'm glad you think AC is worthless to note.
E.g. TP-Link's WR841N for 20 dollars:
http://www.amazon.com/dp/B001FWYGJS http://wiki.openwrt.org/toh/tp-link/tl-wr841nd
[1] http://store.netgate.com/Ubiquiti-EdgeMAX-EdgeRouter-Lite-P1...
[2] http://store.netgate.com/ALIX2D2-Kit-Black-Unassembled-P187C...
We use both, OpenWRT on cheap TPLink consumer routers as a VPN router in home and branch offices, and a bunch of virtualized pfsense firewalls for network security in our hq and datacenter rack.
If you're after real routers as in routing protocols like bgp and ospf and not security devices, both are not of much use. this is where vyatta, a open source Debian based router distribution is better suited.
Wireless performance of openwrt depends on the hardware it is running on, but It's generally not great compared to proprietary gear from ubiquity and mikrotik. Both make dirt cheap wireless gear and routers that can match and outperform Cisco routers that cost 10x more. Wireless ISPs everywhere rely on those vendors.
> If you're after real routers as in routing protocols like bgp and ospf
> and not security devices, both are not of much use. this is where vyatta,
> a open source Debian based router distribution is better suited.
Or BSDRP[1] or ZRouter[2]. [1]: http://bsdrp.net
[2]: http://zrouter.orgThe router admin interface only needs to check your password. It can do that by storing only a cryptographic hash, not the password itself.
What would actually work I guess would be storing a hash of <the password, a unique string provided through https auth>. So for the first time the browser would hash the pass and afterwards just provide the pass to the server as a hash without requiring input, acting as a normal pass to the server. However, that would either require some sort of universal agreement among browsers to work, which is tricky to require, or some browser-server protocol in which the browser would only carry such procedure to supported servers. If a supported server is accessed through a non-supported browser, the server itself would perform the hash.
Probably too much of a hassle just in name of abolishing plaintext passwords on browsers, but I couldn't think of anything simpler. However, fun to imagine :)
Obs: This would have the extra bonus of depriving knowledge of plaintext passwords to servers (in case they are compromised, the attacker would not get to try the pass across other services) and preventing password extraction through impersonation of webpages (although this is already guaranteed by https to some extent).
Therefore, this is no different than storing them in plaintext. Furthermore, it would mean that if the hashes got stolen because a server was compromised those could be used as passwords and that would make it pointless to hash them in the first place.
In other words, no, that wouldn't work.
All you are suggesting is replacing one password with another, harder to remember password. The system where the server only stores salted hashes and hashes your password server-side every time you log in is called "good practice". If you're allowing dedicated protocols and hard-to-remember keys, just use public/private keys.
Any ideas on the best way of tackling that? Perhaps I'm using it incorrectly?
Really, PCs need something like TouchID. Or something like pairing to your phone, and then detecting it in proximity and prompting a TouchID confirmation from it. Phone goes out of proximity = computer locks.
⇧⌃⏏ is insufficient?
Auto-lock/"screensaver mode" (wow, remember when computers had screensavers?) sort of does this, but the time the computer is most vulnerable (especially in any semi-public setting) is right after you dash away, not after it's been sitting idle for 15 minutes. When a computer's owner could come back at any minute, the best time for a social engineer to strike is the moment the owner leaves.
The last case especially (watching a marathon of some show with some friends) reveals an interesting bit of etiquette: it's rude to lock your computer in front of friends--it implicitly suggests they're likely to mess with it, and that you don't trust them enough to mess with it in a way that's merely funny, rather than potentially harmful. The great thing about an automatic proximity-based lock would be that, in going to the bathroom or whatever, the computer would always lock--so there'd be no decision to make which could be read into. (This is oddly similar to rhetoric regarding the incentive-structures of birth control pills vs. condoms.)
I don't wish to encourage to culture of phone over-attachment.
I am not tethered to my phone, and I don't wish to be. It's always around here, somewhere, but not on my person unless I'm out of the house. If I get up, it is going to usually stay on the table. If I go upstairs, unless I'm using it, I'll probably leave it downstairs. I am not going to worry about keeping it in close proximity to keep my computer unlocked.
I hopped onto the Admin page for the router. Had a password, which make sense. I submitted a test password, and there was no page-refresh or network activity... hm. Must be just in the Javascript...
Sure enough, it was obfuscated, but the password was in the damned HTML and easy enough to find. I got $50, and the priceless look of horror on my uncle's face.
I then explained to him that physical access to a computer usually equals "Game Over" ;)
I was looking into running an ADSL modem in full-bridge mode (you'd be surprised how many of these modems don't support that anymore) + a routerboard or mirotik product, but when you add up the cost and configuration time it just wasn't worth it.
I'm currently running a Billion 7800VDPX, which I now have the GPL sources to (after some prodding). When I finally have some time to sit down and risk bricking my device, I'll have a look at getting OpenWRT working (although at last glance they were never going to support ADSL).
tl;dr: open hardware alternatives aren't easy enough to drop in yet, or they're not really open - http://wiki.mikrotik.com/wiki/Manual:License
I do scans from cellular devices (Fing on Android and iOS, is passable for popular ports) and my laptop (nmap) when out and about.
So, lets assume I don't trust this AP and Modem to be secure (fair enough assumption in my opinion) -- the best way would be to perhaps build my own Wireless AP running pfsense, on a BeagleBone Black or similar?
Cable -> Telstra Modem w/out Wireless -> pfsense AP -> Network
Would that be the most secure way to handle that situation?