[00:01.140 --> 00:03.000] Do you want to re-open it? [00:03.100 --> 00:03.400] Yeah. [00:16.580 --> 00:19.580] Almost, yeah. [00:20.380 --> 00:21.700] Do you get a... [00:22.760 --> 00:25.180] So, can you go into full screen from here now? [00:26.160 --> 00:26.300] No. [00:27.000 --> 00:29.380] Yeah, I mean, it wasn't full screen for a second. [00:30.680 --> 00:32.420] It didn't like the... [00:32.420 --> 00:34.400] Oh wait, did it restore the... [00:43.470 --> 00:45.920] It's like, it has f*cked up all the display. [00:52.080 --> 00:53.260] You want to... [00:53.260 --> 00:54.260] Screen mirror? [01:17.790 --> 01:19.310] Welcome to the future. [01:25.820 --> 01:26.820] Where's the... [01:30.560 --> 01:32.880] Yeah, I was just saying. [01:33.280 --> 01:34.820] Is there a fusion to... [01:34.820 --> 01:36.280] It's a fusion to honest, I should. [01:38.420 --> 01:39.340] Save that. [01:42.200 --> 01:43.640] Oh, um... [01:43.640 --> 01:46.500] Does anything have a mini port to VGA? [01:46.920 --> 01:47.820] We have a Max port. [01:48.080 --> 01:49.740] That was our first port to leave in the back. [01:50.180 --> 01:51.800] Do you feel too easy? [01:54.460 --> 01:55.640] It can't, I'm still... [01:58.630 --> 02:00.370] Did you just re-respond it? [02:03.790 --> 02:04.670] I got it. [02:06.110 --> 02:07.690] Why are you even leaving our office? [02:08.730 --> 02:10.270] Well, it's, uh... [02:10.270 --> 02:10.550] It's the... [02:10.550 --> 02:13.570] That's the spun-ed-do... [02:19.730 --> 02:20.930] I mean I like that. [02:21.290 --> 02:21.570] That's it. [02:22.990 --> 02:23.770] Wanna reboot? [02:24.110 --> 02:25.130] Yeah, I'm gonna reboot it. [02:25.310 --> 02:26.030] I'm sorry, man. [02:26.070 --> 02:26.430] You're sorry. [02:28.550 --> 02:30.670] Um, actually, can you leave it in during the reboot? [02:30.670 --> 02:31.210] It's a problem. [02:35.850 --> 02:36.310] It's what? [02:36.510 --> 02:37.130] It's taking a walk? [02:39.630 --> 02:40.570] No, it's not good. [02:43.070 --> 02:46.070] Sometimes if you leave it in the mood, it'd have a better negotiation. [02:52.230 --> 02:53.250] Day of my life. [02:53.570 --> 02:54.930] And this is my friend Chris. [02:55.330 --> 02:55.810] How's it going? [02:56.910 --> 02:57.610] All right. [02:58.730 --> 03:08.450] So the aristocrats, I came up with the name of this presentation because it's like a joke, an anti-joke that comedians tell each other. [03:08.930 --> 03:15.370] And my friend Chris discovered these vulnerabilities like in a DOCSIS cable modem slash router. [03:16.030 --> 03:18.850] And he thinks, you know, it's just lazy engineering. [03:18.850 --> 03:28.510] I think we're being trolled by elite hackers who put the worst possible security in just so this moment could happen where somebody would come talk about it. [03:29.550 --> 03:30.330] All right. [03:30.670 --> 03:32.950] So, um... [03:34.210 --> 03:38.210] The cable companies, the carriers, they don't really have a sense of humor. [03:39.870 --> 03:47.470] So, uh, try this stuff out, but do it on gear that you own, not the stuff you rent from them, and then don't f*ck with them, please. [03:47.850 --> 03:48.930] We own our own gear. [03:49.370 --> 03:49.650] Yes. [03:51.590 --> 03:52.050] All right. [03:52.110 --> 03:53.710] So this is the box we're talking about today. [03:54.990 --> 03:55.370] Um... [03:55.770 --> 03:59.730] And this is the box Chris moved to Brooklyn and got this with his cable service, right? [04:00.150 --> 04:00.390] Yep. [04:00.910 --> 04:01.550] All right. [04:01.690 --> 04:08.910] So it is a cable modem like you expect, but it's also a wireless router like you'd, uh, normally see from a Linksys box or a Necure box. [04:09.370 --> 04:13.130] And it's just a Linux box that's running, uh, 2.6 kernel. [04:15.490 --> 04:18.850] So, like Charlie said, it kind of all started when I moved to Brooklyn. [04:20.410 --> 04:20.890] Um... [04:20.890 --> 04:24.370] I got my Internet hooked up, and I got this shiny new device. [04:24.370 --> 04:30.050] And, um, they left me a little note saying, here's your, uh, WPA key. [04:30.210 --> 04:32.690] And it was really long and really annoying. [04:32.910 --> 04:35.830] I just wanted to change the password to something easy like my dog's name. [04:38.350 --> 04:38.770] Um... [04:38.770 --> 04:41.010] Turns out that wasn't really so simple. [04:41.430 --> 04:42.610] Uh, I couldn't figure it out. [04:42.670 --> 04:44.290] There wasn't a manual that came with the device. [04:44.950 --> 04:49.150] So, um, I just sat there and stared at it for a long time. [04:49.430 --> 04:50.390] It was really mad. [04:54.160 --> 04:56.340] By the way, can you guys see the WPA key? [04:56.660 --> 04:58.300] Is there, like, anything sketchy about that? [04:58.880 --> 05:00.060] It's the same as the name. [05:00.100 --> 05:00.900] Oh, my God. [05:01.880 --> 05:02.620] Thank you. [05:04.880 --> 05:06.280] Yeah, that's the model number. [05:08.160 --> 05:08.640] Um... [05:08.640 --> 05:10.780] And that should trigger some... [05:10.780 --> 05:12.080] No, we, we did not. [05:13.740 --> 05:14.220] Um... [05:14.220 --> 05:16.600] That should vaguely trigger some memories. [05:17.160 --> 05:18.520] You can't change it? [05:18.700 --> 05:20.560] It's, it's never happened before, ever. [05:24.900 --> 05:25.540] Does it? [05:25.760 --> 05:26.540] I didn't know that. [05:28.440 --> 05:28.880] Um... [05:28.880 --> 05:30.000] Yeah, so... [05:30.000 --> 05:34.220] The last six digits, you know, you could totally brute force that, right? [05:34.880 --> 05:38.360] But, but, like, what's the deal with the number 12? [05:39.680 --> 05:44.940] Uh, it, it's in the SSID and it's in the password, so it must be significant. [05:44.940 --> 05:48.240] It, it, it could be the MAC address. [05:54.100 --> 05:54.620] Uh... [05:54.620 --> 05:55.220] Bail! [05:59.440 --> 06:11.900] Okay, so, um, the other thing about this is beyond what you can see from your living room, there's lots of services that have gone and, um, gathered SSIDs and BSSIDs, the MAC addresses. [06:12.580 --> 06:13.000] Google. [06:13.000 --> 06:15.780] Yeah, Google, for one, knows all about this. [06:15.980 --> 06:18.100] And there's, uh, another one, Weigl, that has. [06:18.520 --> 06:22.840] And you can search for this, for this particular device and find lots of them. [06:23.380 --> 06:29.220] Um, so if you want to start your WordDrive in a particularly, uh, fruitful place, the Internet will tell you how to. [06:30.400 --> 06:32.340] I was way too lazy to WordDrive. [06:34.360 --> 06:40.480] But, so if you search Wiggle, one of the things you'll find is that, um, there's a lot of similar SSIDs. [06:40.800 --> 06:50.180] Um, if you just search for the manufacturers, um, you know, it's, it's not necessarily the same mile number, but you start seeing the same pattern. [06:51.600 --> 06:59.440] Oh, and that's a good point, Chris, because there's a number here that are very similar to the, the box we're talking about today that we haven't looked at, uh, because we don't own them. [06:59.800 --> 07:01.920] But if you own one of these, you should take a look. [07:02.480 --> 07:07.120] So that was the DG950 and the WTM and the TG862. [07:09.060 --> 07:11.840] So, yeah, so we haven't really done any hacking yet, have we, Charlie? [07:12.400 --> 07:12.880] That's right. [07:13.580 --> 07:14.300] But, wait. [07:15.380 --> 07:19.720] Yeah, so if we want to fix it, so, how, how do you think we should fix this? [07:19.860 --> 07:31.080] Like, what do you guys think we should do to, uh, like, generate a PSK, uh, PSK that could be printed on a sticker and that the, the router from the firmware can generate on boot. [07:31.400 --> 07:33.360] So, from information it has. [07:34.180 --> 07:44.420] So, like, the MAC addresses seem like a good source of entropy because, you know, there's the 24 bits that are manufacturer ID and 24 bits that should be more or less unique to your vice. [07:44.660 --> 07:48.020] But, like, they're not built with random numbers. [07:48.020 --> 07:59.600] They're gonna be sequential numbers and likely if you find one, uh, at your house and go a few, uh, a few thousand numbers each direction, you're gonna find your neighbors have similar MAC addresses. [08:00.500 --> 08:04.780] So, does anybody have any ideas on, uh, what you would do? [08:04.880 --> 08:11.520] If you, you need to print PSKs on stickers and you also need the, the router to boot up and generate a PSK that matches that. [08:25.600 --> 08:26.710] Just hash it? [08:27.580 --> 08:28.450] No way. [08:30.900 --> 08:34.300] Yeah, so you end up with the same brute force possibilities if you just hash it. [08:34.520 --> 08:36.360] But, yeah, I mean, those are good ideas. [08:36.860 --> 08:40.000] And the W, the WPS pin is another idea. [08:40.330 --> 08:51.620] WPS itself has been broken, but there's that eight-digit number, seven of which are supposed to be unique, that may be another source of entropy that you can tap into to, um, make a... [08:51.620 --> 08:53.660] Allow the customer to be able to change that stuff. [08:53.860 --> 08:54.120] Yeah. [08:54.640 --> 08:56.780] If we had prizes, you, sir, would win it. [09:00.060 --> 09:03.360] So, meanwhile, I decided to stop staring. [09:03.380 --> 09:13.840] So, I, I called up my provider and I said, hey, I really want to get the password so I can log into this thing and change my WPA password because I, I'm not happy with it. [09:14.460 --> 09:21.700] Um, so, they typically don't allow customers to do that, um, unless the customer is under attack. [09:22.460 --> 09:23.480] That's good, good to know. [09:24.220 --> 09:30.780] Um, so I asked, what if I want to change it, um, every now and then for security reasons? [09:31.300 --> 09:34.220] So, uh, unfortunately we don't provide access to the router. [09:34.420 --> 09:34.720] Okay, fine. [09:34.960 --> 09:36.140] So, it goes on and on. [09:36.660 --> 09:39.400] Um, ask a couple more questions. [09:39.780 --> 09:46.420] And eventually it came down to, well, you can purchase your own router and we'll choose just put this router in bridge mode and you can put yours behind it. [09:46.600 --> 09:47.740] And, okay. [09:48.040 --> 09:49.460] I think I might do that soon actually. [09:54.490 --> 10:03.010] So, how do we log in to this shiny new router which has a nice web interface but we don't have the password to it? [10:04.130 --> 10:11.830] A little Googling discovered that, well, there's a guy out there in South America who had a different model from the same manufacturer. [10:11.830 --> 10:14.610] And he found out that there's like this thing called the password of the day. [10:14.930 --> 10:16.890] It's really convenient if you're a technician. [10:18.130 --> 10:20.450] So, I was like, okay, there's no way that works for mine. [10:20.710 --> 10:21.470] Well, it turns out it does. [10:22.350 --> 10:26.430] Um, and that, that's been out there since August 29th, 2010. [10:26.890 --> 10:31.190] So, um, worked back then on a different model, two different models. [10:31.390 --> 10:32.230] Works on our model. [10:33.090 --> 10:35.710] Um, hope it doesn't work for many other models. [10:39.550 --> 10:41.650] So, one, one password to roll them all. [10:42.010 --> 10:43.410] You know the day, you know the algorithm. [10:43.710 --> 10:45.450] You know the password today, right? [10:46.430 --> 10:49.970] Um, you could probably start thinking about some attacks at this point. [10:50.970 --> 10:54.490] Um, but we wanted to just confirm this with our model. [10:54.690 --> 11:00.470] So, um, aside from the couple of ones that, that we purchased and we wanted to just go out there and ask some people. [11:00.690 --> 11:05.930] And it turns out that other folks that have this model were able to, to get in with that password of the day. [11:07.630 --> 11:08.410] So that's great. [11:08.550 --> 11:10.830] So now I could change my, uh, WPA key. [11:15.030 --> 11:17.970] So, thinking about some of the, you know, attacks. [11:19.010 --> 11:26.310] I could board drive around New York City and find these models and log into the router and reconfigure them and own the world. [11:26.630 --> 11:27.810] But that's really annoying. [11:29.070 --> 11:36.550] Um, we could possibly do some click jacking or cross-site request voideries and do some spear phishing or something like that. [11:36.550 --> 11:40.290] But we really need to know more about the device before, before we do any of that. [11:40.910 --> 11:46.150] Um, so, let's actually log in. [11:46.670 --> 11:48.370] Because we still haven't logged in at this point. [11:53.620 --> 11:55.740] So, top left is the log in page. [11:56.000 --> 11:59.080] Um, just a quick view source. [12:01.160 --> 12:03.260] Bottom right, there's the JavaScript. [12:05.840 --> 12:14.020] Turns out that, you know, it does kind of post some authentication credentials to the device. [12:14.140 --> 12:15.160] The device does respond. [12:15.620 --> 12:18.300] But then the JavaScript makes sure that it's actually valid. [12:20.440 --> 12:32.260] And it turns out that if you actually remove everything else, um, out of the cookie that is being set, and just put valid equals true, you can log in. [12:37.930 --> 12:40.290] So, you don't need a password to access this web interface. [12:40.290 --> 12:42.130] Just the cookie. [12:44.370 --> 12:50.770] So, if the management interface doesn't require a password, how is it handling configuration changes on the box? [12:51.630 --> 12:53.730] Um, let's find out. [12:56.550 --> 12:57.030] Okay. [12:57.230 --> 12:58.750] So, at this point, we've logged into the box. [12:59.010 --> 13:04.890] And, um, uh, we're using, like, uh, intercepting proxy like burp or zap. [13:05.330 --> 13:07.930] And we're looking at what happens when we make configuration changes. [13:07.990 --> 13:13.410] And we see these calls to SNMP set and SNP get functions in JavaScript. [13:14.690 --> 13:19.850] Um, so SNMP is a service that's commonly deployed to manage network gear. [13:21.590 --> 13:34.030] Um, this tells us some more about how the, uh, essentially they have sort of like a, uh, HTTP to SNMP proxy running through the web interface. [13:34.350 --> 13:49.450] So, um, we see these examples here of the SNP set, the SNP get, the walk, which is SNP walk, um, which just steps through, uh, sequentially through a bunch of get next statements. [13:50.430 --> 13:53.530] And we haven't done any hacking yet because we're just looking at JavaScript. [13:54.190 --> 13:54.670] Yes. [13:56.310 --> 14:01.930] Um, so there's an enterprise, enterprise identifier for Eris. [14:02.110 --> 14:03.130] We take a look at that. [14:04.290 --> 14:14.470] And if you just, this is really hard to read, but essentially it's just the, the IP address of the router, slash walk, question mark, void, and then the, that enterprise ID. [14:14.890 --> 14:23.230] And it, essentially it just dumps the whole configure the router, including the passwords, which are admin and password and technician and technician in my case. [14:23.590 --> 14:30.470] His, his passwords on his device were slightly different, but they can still be grabbed through this call without any authentication. [14:30.490 --> 14:34.270] So that whole thing we had about bypassing authentication, you don't even need that. [14:34.390 --> 14:39.730] You just need to, uh, open your web browser and navigate to this URL and you get all that information. [14:39.730 --> 14:41.050] Setting a cookie is way too high tech. [14:41.310 --> 14:41.670] Yeah. [14:46.910 --> 14:47.310] Okay. [14:47.470 --> 14:54.970] So what you can do through this SNMP interface, some examples are you can get the admin password in case, um, you wanted to see it. [14:55.070 --> 14:57.390] You can reboot the router, which would be great for trolling. [14:57.870 --> 14:59.530] You can disable the firewall. [15:00.030 --> 15:04.010] Um, you can change their DNS servers or you can change their password. [15:07.800 --> 15:10.920] And all of these, again, don't require any authentication at all. [15:11.140 --> 15:11.880] Not even the cookie. [15:12.980 --> 15:15.750] So you can really pick any OID and change it. [15:16.880 --> 15:19.100] So what's kind of the worst case scenario here? [15:20.640 --> 15:22.620] Let's say it was exposed on the WAN port. [15:22.820 --> 15:24.080] I'm not saying that it is. [15:28.500 --> 15:28.940] Possibly. [15:33.750 --> 15:44.050] Assuming that it was exposed on the WAN port, um, you could, of course, just broadcast some of these get requests all over the web and start aggregating devices. [15:45.190 --> 15:55.570] Um, you know, you could change somebody's DNS to your DNS and now you could, um, start manning, you know, doing a man in the middle on all their traffic. [15:55.810 --> 16:00.050] You could, like, port scan a whole apartment building that uses Comcast to, like... [16:00.610 --> 16:01.050] Yeah. [16:01.290 --> 16:04.510] Or you could, like, go on Aaron and just get all their subnets. [16:08.570 --> 16:09.010] Um... [16:14.000 --> 16:14.760] Yeah, I do. [16:15.160 --> 16:16.800] So, I... [16:16.800 --> 16:21.260] We've got to, like, clarify that we did this on equipment we own. [16:21.780 --> 16:22.300] Oh, okay. [16:23.660 --> 16:29.760] Um, and that we did not try this against anybody else in my apartment building or in New York City or anywhere else in the world, for that matter. [16:30.340 --> 16:31.380] Uh, but... [16:32.480 --> 16:36.020] Should this be exposed on the WAN, it would be a significant problem. [16:36.020 --> 16:40.760] It would be really, really, ridiculously easy to take control of these devices. [16:42.340 --> 16:42.820] Um... [16:42.820 --> 16:44.720] I hope somebody hasn't already done it. [16:47.420 --> 16:47.900] If... [16:51.740 --> 16:52.220] If... [16:52.220 --> 16:55.580] They weren't exposed on the WAN, it would be just as bad. [16:55.740 --> 16:56.760] It would be a little harder. [16:57.520 --> 17:04.620] Um, you'd actually have to trick somebody into opening up some HTML or going to a link or something like that or sending them an HTML email. [17:04.920 --> 17:06.000] It would be a little tougher. [17:06.280 --> 17:08.260] You'd have to actually target some of these people. [17:09.320 --> 17:10.680] Um, but... [17:10.680 --> 17:13.960] Of course, that's not necessarily that difficult. [17:15.200 --> 17:15.680] And... [17:18.970 --> 17:23.410] We tried really hard to figure out a way to tell you guys today, how do we fix this? [17:25.450 --> 17:25.930] Um... [17:25.930 --> 17:26.810] Because... [17:26.810 --> 17:28.830] I wouldn't be able to use my Internet connection. [17:29.790 --> 17:31.870] Without worrying about it being hijacked today. [17:33.710 --> 17:34.150] Um... [17:34.150 --> 17:36.670] So, the easiest fix would be, of course, for... [17:36.670 --> 17:37.830] For, um... [17:38.370 --> 17:41.110] Some sort of server-side authentication to be implemented. [17:41.490 --> 17:44.870] I mean, even basic auth would be better than what's going on right now. [17:47.030 --> 17:47.470] Um... [17:47.470 --> 17:56.870] You know, using real session cookies, not hex-encoded session cookies that have the credentials built in, which is also happening. [17:58.470 --> 17:58.910] Um... [17:58.910 --> 18:02.430] Removing this whole backdoor password of the day would be a good start, as well. [18:03.610 --> 18:04.050] Um... [18:04.050 --> 18:07.630] And, of course, removing those technician accounts. [18:08.010 --> 18:09.250] I'm not sure why they're there. [18:13.700 --> 18:19.060] And, of course, if that WAN port was exposed, it would be good if it were not exposed. [18:22.900 --> 18:31.340] So, full disclosure, we have actively pursued conversations with carriers, manufacturers, about this for months. [18:32.880 --> 18:33.360] Um... [18:33.360 --> 18:34.540] Thanks to Forbes on Friday. [18:35.160 --> 18:36.440] Somebody finally called us. [18:40.340 --> 18:42.920] So, we wanted to give a little proof of concept demo. [18:44.200 --> 18:44.680] Um... [18:44.680 --> 18:46.580] There really isn't anything magical about this. [18:46.660 --> 18:49.140] You don't have to be, like, some crazy elite hacker to do what we did. [18:49.940 --> 18:50.540] Um... [18:50.540 --> 18:51.960] There's no cool, like, shellcode. [18:52.940 --> 18:57.440] It's just a fundamental lack of basic security, basic authentication. [18:58.290 --> 19:03.580] And the fact that it's 2012 and we're still doing this is a little bit scary. [19:04.620 --> 19:04.940] Um... [19:04.940 --> 19:05.280] It's... [19:05.280 --> 19:08.680] It's happened many times before with other manufacturers. [19:09.220 --> 19:10.700] And it continues to happen. [19:10.940 --> 19:13.220] So, um... [19:13.960 --> 19:17.720] We need to start thinking about a better way to deploy cable modems. [19:19.780 --> 19:20.360] Oh, shoot. [19:21.040 --> 19:21.640] Do you have your phone? [19:21.800 --> 19:22.780] I do have my phone. [19:23.600 --> 19:24.280] Close your eyes. [19:26.740 --> 19:27.760] Should I unplug it? [19:29.380 --> 19:30.020] Yeah, whatever. [19:31.620 --> 19:32.000] Sorry. [19:37.900 --> 19:38.660] Oh, shit. [19:38.860 --> 19:39.300] Do you know what? [19:39.780 --> 19:40.220] There you go. [19:41.080 --> 19:41.900] No, it wasn't up. [19:42.220 --> 19:42.460] Okay. [19:43.360 --> 19:43.880] So, what is it? [19:43.900 --> 19:45.320] He was just doing that to throw you off. [20:20.110 --> 20:20.870] It's Windows. [20:21.110 --> 20:21.730] It does it automatically. [20:28.390 --> 20:28.890] Sure. [20:29.490 --> 20:30.370] How did you get... [20:30.370 --> 20:34.910] You got a modem that you currently use for Comcast and you have that you personally own? [20:35.070 --> 20:36.290] I didn't say Comcast. [20:39.750 --> 20:40.270] I... [20:40.270 --> 20:41.290] So, I... [20:41.290 --> 20:42.290] We have a... [20:42.290 --> 20:42.850] We... [20:42.850 --> 20:44.170] I had gotten this modem... [20:44.170 --> 20:44.850] What about cable means? [20:45.050 --> 20:45.690] Time Warner? [20:46.370 --> 20:47.230] Time Warner? [20:47.370 --> 20:49.600] Time Warner? [20:50.800 --> 20:52.280] Time Warner or Comcast? [20:52.540 --> 20:53.120] No comment. [20:53.480 --> 20:53.980] No comment. [20:54.840 --> 20:55.980] So, we... [20:55.980 --> 21:00.020] I got one of these devices from my provider when I got my cable service. [21:00.160 --> 21:02.380] And as I went through in the beginning, we... [21:02.380 --> 21:05.500] You know, I stared at the WPA key a really long time. [21:05.840 --> 21:15.360] And when I realized that I couldn't get in and that I really was kind of scared about the security of this device, we decided to order our own and test this out. [21:15.520 --> 21:19.680] So, what we're showing you is our own devices and our own test environment. [21:22.080 --> 21:37.280] So, right now, you're staring at a part of the admin login router config area where we have just like the regular DNS settings set on the router. [21:37.460 --> 21:45.460] So, what we're going to do is we're going to show you a little exploit which, you know, by going to our little website, changes all the configs on the router. [21:51.060 --> 21:55.320] And one second, because I'm sure this session is timed out and I'm going to need to find the password again. [21:56.580 --> 21:56.780] Anybody? [21:57.060 --> 21:58.300] Is the same if bridge mode is enabled? [21:58.580 --> 22:01.460] Like, when the tech enables bridge mode, the same is still open? [22:03.160 --> 22:09.800] It's one thing we didn't have time to test whether or not the device is still enables the web interface when bridge is enabled. [22:12.020 --> 22:12.500] It'd [22:20.550 --> 22:21.030] be... [22:21.030 --> 22:21.570] I think so. [22:21.590 --> 22:22.230] Mine was also. [22:22.230 --> 22:23.010] Yeah, I think so. [22:23.230 --> 22:23.350] Yeah. [22:25.170 --> 22:28.030] From the test set of two, we can confirm yes. [22:30.490 --> 22:31.870] It's a big sample size. [22:36.510 --> 22:36.990] Sorry? [22:40.450 --> 22:41.170] I don't know. [22:48.010 --> 22:49.370] I think that's something else. [22:50.150 --> 22:51.010] I'm not sure. [22:51.230 --> 22:54.410] The resolution's a little off, so I'm not able to scroll over. [22:57.730 --> 22:58.610] Oh, yeah. [23:04.140 --> 23:05.160] It's off the screen. [23:05.620 --> 23:06.500] I wish I knew. [23:08.720 --> 23:10.180] There's the address of the router. [23:11.380 --> 23:13.060] I think that's the DHCP range. [23:13.180 --> 23:13.740] Oh, that's the range. [23:14.120 --> 23:14.380] Yeah. [23:22.020 --> 23:22.780] That's a good point. [23:28.940 --> 23:29.880] Wait, did it go? [23:31.220 --> 23:33.180] So we ran this little script real quick. [23:33.400 --> 23:33.760] Oh, wait. [23:33.840 --> 23:34.440] It didn't refresh. [23:35.600 --> 23:37.280] It's showing the wrong DNS settings. [23:37.300 --> 23:37.880] It did not refresh. [23:38.440 --> 23:39.840] This is a problem with live demos. [23:44.030 --> 23:45.910] I think it did refresh, so let's go back. [23:45.990 --> 23:48.690] Let's go back here and redo this. [23:49.890 --> 23:50.450] Oh, God. [23:50.650 --> 23:51.690] Now I've got to remember the password. [24:06.690 --> 24:07.110] Shoot. [24:07.430 --> 24:07.850] Shoot. [24:15.290 --> 24:17.130] If this doesn't work, we'll just set a cookie. [24:20.370 --> 24:22.470] I don't have a reception in here. [24:22.590 --> 24:23.090] This is failing. [24:24.190 --> 24:27.130] It was like Motorola with some sort of... [24:27.130 --> 24:28.530] What was your technically? [24:28.550 --> 24:28.610] I don't have a reception in here. [24:28.610 --> 24:29.010] You mentioned one. [24:29.130 --> 24:30.350] Was it the same Motorola last one? [24:30.350 --> 24:30.450] No. [24:30.730 --> 24:30.910] Yeah. [24:31.010 --> 24:31.810] It was like something crazy. [24:33.590 --> 24:34.510] We're going to look it up. [24:35.810 --> 24:37.030] Since we have some time to kill. [24:38.090 --> 24:39.310] Oh, we do have time to kill. [24:39.490 --> 24:40.970] Talk amongst yourselves, please. [24:43.590 --> 24:44.890] How much is one of these revenues? [24:46.550 --> 24:49.210] I believe they're around 80 to 100 bucks around there. [24:52.260 --> 24:53.760] Do you buy it on eBay? [24:54.440 --> 24:54.940] eBay. [24:55.940 --> 25:01.060] Do you know what sort of vendor qualification program they have for these devices? [25:01.280 --> 25:02.300] I do not, no. [25:09.240 --> 25:09.740] Correct. [25:10.880 --> 25:11.380] Yeah. [25:14.550 --> 25:24.210] We had a cool demo going that's not working right now, but basically it was taking a screenshot of the device after it was being phished and sending that screenshot back to us. [25:24.910 --> 25:26.070] Too bad it doesn't work right now. [25:27.670 --> 25:28.070] Yeah. [25:31.770 --> 25:32.870] It should be in there somewhere. [25:33.070 --> 25:34.130] Well, there was that one. [25:34.350 --> 25:35.250] That's the technician one. [25:35.370 --> 25:36.350] So let's try that one. [25:36.670 --> 25:40.890] And just put the cap in the thing and you'll be fine. [25:42.450 --> 25:42.850] Yeah. [25:43.050 --> 25:43.850] I'm better than expected. [25:44.210 --> 25:44.390] Yeah. [25:48.090 --> 25:49.490] I got a first page. [26:07.330 --> 26:09.970] So you'll see the top DNS server has changed. [26:12.650 --> 26:14.550] We had it on the AT&T one before. [26:17.990 --> 26:20.630] Luckily that's open DNS, not my DNS server. [26:22.270 --> 26:22.550] But... [26:31.920 --> 26:32.480] So... [26:32.480 --> 26:33.560] Yeah, yeah, yeah. [26:36.460 --> 26:37.680] There's bigger problems. [26:44.870 --> 26:46.010] We haven't tried. [26:51.630 --> 26:54.390] We kind of slacked off on this because it was just so easy. [27:07.670 --> 27:17.390] So the one fix, somebody kind of alluded to it here, is if this kind of disables itself when you put the device in bridge mode, it would probably be the easiest fix. [27:17.390 --> 27:22.670] And you could just put your own router firewall behind it, something nice and secure and open-source. [27:26.310 --> 27:37.270] But, as of right now, the only way to really fully test that would be to test it on my actual provider-issued device. [27:37.270 --> 27:39.290] And I'm not willing to do that, so... [27:39.290 --> 27:47.080] Can your provider's cable line come into your apartment and get to speak to Mac all the time? [27:47.080 --> 27:50.400] Yeah, I believe they have some sort of, like, Mac... [27:50.400 --> 27:51.440] There was no, right? [27:51.680 --> 27:52.340] Yeah, yeah, yeah. [27:52.440 --> 27:53.340] Can't work on it? [28:08.810 --> 28:09.510] That's for Mac. [28:09.690 --> 28:10.730] That was Time Warner. [28:12.390 --> 28:15.390] Supposedly, you can only put your device behind their device. [28:16.050 --> 28:16.490] Well... [28:16.490 --> 28:17.430] At least that's what I was told. [28:18.230 --> 28:19.330] I used to have... [28:19.330 --> 28:20.750] I used to have... [28:20.750 --> 28:25.470] I used to have Verizon DSL, and I had purchased a different DSL mode on eBay. [28:25.770 --> 28:28.610] You could figure to put it on another thing and it was fine. [28:28.850 --> 28:29.870] But that's a completely different thing. [28:29.930 --> 28:30.610] Don't you have the difference? [28:30.610 --> 28:30.910] Yeah. [28:32.410 --> 28:33.590] Can we turn up the lights? [28:33.750 --> 28:35.310] It's kind of creepy talking to y'all with... [28:35.310 --> 28:36.990] Yeah, I feel like I'm talking to, like... [28:41.260 --> 28:45.600] The people who contacted you, were they with ARRIS or with your cable provider? [28:46.300 --> 28:55.000] So, the people that contacted me were the manufacturer as well as one of the other providers that may have been affected by this. [29:01.010 --> 29:05.090] One other interesting fact is we went out on Shodan. [29:05.490 --> 29:10.690] If you guys aren't familiar with it, it's a great repository for seeing what's out there on the web. [29:11.270 --> 29:13.690] It's like a constant NMAP scan. [29:13.750 --> 29:15.290] I guess that's a good way to explain it. [29:15.410 --> 29:16.770] It's like one big computer database. [29:18.070 --> 29:21.990] And so, if you search for just this particular manufacturer, you can... [29:22.290 --> 29:24.190] I think we found like 160,000 devices. [29:25.670 --> 29:38.750] The interesting thing about that was that the only way that Shodan was able to find the devices was by actually querying a native SNMP, doing a native SNMP trap. [29:38.750 --> 29:49.810] So, ours, the way ours shipped, they didn't have SNMP enabled, but it seems as though there's a hundred some thousand devices that just have native SNMP enabled. [29:52.710 --> 30:05.250] I had hoped that, you know, maybe they're not all wide open to being exploited through SNMP, the way that this web service is, but it certainly could be a problem. [30:07.250 --> 30:20.550] So, I'm wondering if it turns out that the worst case scenario, the bridge mode, doesn't turn, make the device more secure, and it is exposed on the WAN port. [30:22.230 --> 30:35.930] If you can't secure the device that the cable company has given you, would you at least be able to detect that someone is messing with your router from the equipment behind it? [30:38.090 --> 30:49.450] That's a hard question to answer, because you could... one of the things you could do is you could set a L2TP tunnel to your own service somewhere, and just tunnel all the traffic on that device out. [30:49.690 --> 30:53.710] If it's in bridge mode, probably, I doubt that would work. [30:53.710 --> 31:04.890] But if you just placed your device behind it without a bridge mode, I'm not sure you would know unless you were checking your device every day to make sure settings hadn't been altered. [31:05.150 --> 31:15.870] Especially on the DNS side, that might... that exploit might not work so well if you're hard coding your DNS on your endpoint devices. [31:17.750 --> 31:24.350] But certainly with the tunneling, it would... it would just pass on all your traffic onto the malicious server. [31:26.830 --> 31:39.090] And I guess as a side note to that, is there any way that someone who's compromised this device could actually enlist the... basically root the device, as opposed to just changing the settings? [31:43.620 --> 31:47.720] We... we haven't found a way to put a new firmware on the device yet. [31:48.260 --> 31:49.300] We haven't tried that. [31:51.500 --> 31:53.420] I guess, theoretically, maybe. [31:56.860 --> 31:57.980] Providers do it all the time. [31:58.140 --> 31:58.300] Yeah. [32:00.200 --> 32:09.480] So one of the local cable companies gives this... gives the non-Wi-Fi version to the customer that paid for the high-speed service. [32:10.180 --> 32:12.140] And I was playing with mine this morning. [32:12.680 --> 32:15.440] I didn't know the password of the day, but was looking at other settings. [32:15.440 --> 32:17.140] And of course, it has its DNS server. [32:17.740 --> 32:18.920] And it's just a number. [32:19.620 --> 32:24.680] And I have no idea, as a customer, what the correct DNS server number is. [32:24.720 --> 32:25.700] Because it's just a number. [32:26.260 --> 32:33.240] So how would people ever really figure out if they've had this changed on them for a man-in-the-middle attack? [32:33.440 --> 32:37.360] Because the cable companies don't even tell you what these settings are supposed to be. [32:37.820 --> 32:39.620] So how do you know you got the legit one? [32:40.400 --> 32:45.740] I think the average customer has a very hard time even grasping that concept. [32:46.140 --> 32:49.380] How about if you grasp the concept, but you still want to know how you'd ever figure it out? [32:49.380 --> 32:53.960] I don't... you know, I don't... I think that's a common problem, you know, Internet-wide. [32:53.960 --> 33:01.520] But certainly, you know, the average consumer would not be aware that this was going on. [33:01.820 --> 33:03.200] They wouldn't log in. [33:04.920 --> 33:05.200] Yeah. [33:05.800 --> 33:09.040] So for, like, for my particular provider, they couldn't even log in. [33:09.600 --> 33:12.220] Because there's no credentials given. [33:15.400 --> 33:28.360] So, you know, even with the very first exploit that we started with, not really an exploit, but with the weakness in the WPA password, you know, the average customer couldn't even change that on my provider. [33:28.840 --> 33:36.940] Actually, I don't remember whether this was the case or whether I did it for my camera, but I just basically said I have a problem and I need the password. [33:37.340 --> 33:38.900] And they gave me the password. [33:40.940 --> 33:43.060] But now that I have that, I still don't know. [33:47.320 --> 33:54.000] So at home, I have my router in bridge mode from Comcast because I just want to use my own router anyways and want to deal with their crap. [33:55.800 --> 34:04.580] It seems like in this situation, if you go into bridge mode, they're going to have to have the web interface on because how would you take it back out of bridge mode if there's no interface to manage that? [34:04.580 --> 34:06.560] Yeah, that brings a good point. [34:06.820 --> 34:11.780] When I talked to my provider, they said that they would enable the bridge mode for me. [34:11.880 --> 34:12.200] Oh, okay. [34:12.440 --> 34:16.160] So I would assume that they must have some way to disable it again. [34:16.400 --> 34:17.360] Mine was through the web UI. [34:17.580 --> 34:27.140] Well, so if they turn on bridge mode for you, if I had one of these moments, I would probably try and set up my home network so I use a different subnet than whatever their default address is. [34:27.280 --> 34:32.700] So none of my machines can even talk to it and so no one can ever do the XSRF to me or whatever. [34:32.700 --> 34:33.160] Yeah. [34:33.340 --> 34:36.880] And if you want to actually manage it, then just set the IP one off and do it and go back. [34:39.200 --> 34:39.600] Thanks. [34:41.520 --> 34:46.720] They said that they would do certain things for you if you were under attack. [34:47.500 --> 34:48.840] It was a really weird comment. [34:53.160 --> 34:55.720] He also said that all my ports were open by default. [34:57.940 --> 35:01.960] Did you ever try telling them you were under attack and seeing what happened? [35:02.340 --> 35:03.080] No, I did not. [35:04.880 --> 35:06.740] I wasn't under attack as far as I knew. [35:08.360 --> 35:08.880] But... [35:10.740 --> 35:12.900] No, I'm the researcher, I'm not the attacker. [35:19.670 --> 35:35.490] My experience is somewhat contrary to yours in that many of these providers allow you to install your own DOCSIS compatible device or to buy a device which is identical to the one that they ship you and then they tell you exactly how to configure it in terms of, [35:36.150 --> 35:38.790] you know, where their DNS servers are and... [35:38.790 --> 35:39.370] Correct. [35:40.090 --> 35:40.870] Yeah, I think there's... [35:40.870 --> 35:41.910] You just have to tell them the MAC address. [35:42.410 --> 35:53.410] Sometimes they, you know, reflash it for you over the wire so that they can put in capacity limiting code of their own, you know, so you won't overuse their precious bodily fluids. [35:56.050 --> 36:14.550] But, and in response to the person who didn't know what that IP address meant, there is who is, there is, you know, traceroute and you can figure out if that machine is in their cloud and if it's in their infrastructure and you can generally look at their website and figure out how to configure your device. [36:14.810 --> 36:18.610] But if you're being attacked by someone in the same city or block, you won't... [36:18.610 --> 36:20.690] It's still all of them the same... [36:20.690 --> 36:29.690] Yeah, I mean, if one of their infrastructure machines is running rogue DNS, then you might find it hard to distinguish between that and what's in your... [36:29.690 --> 36:32.430] And you can always point it at 8888 or open DNS. [36:32.790 --> 36:33.110] Correct. [36:33.110 --> 36:34.770] If you want a trustworthy DNS. [36:35.270 --> 36:36.790] If you could log into the device. [36:37.030 --> 36:37.130] Yeah. [36:39.490 --> 36:39.990] Right. [36:43.930 --> 36:47.110] Well, essentially, you now have an untrusted device in your network. [36:47.110 --> 36:50.670] So, don't point anything that you have to that device. [36:50.950 --> 36:51.410] Since it's untrusted. [36:51.810 --> 36:52.550] We'd use VPN. [36:53.070 --> 36:55.570] We'd use other alternative services. [36:57.790 --> 37:00.650] It's hard to get to the Internet without pointing at your modem. [37:10.130 --> 37:13.750] If you can't trust it, you don't pass stuff through it. [37:13.850 --> 37:15.110] If you don't want it, you don't have to. [37:15.110 --> 37:17.610] You don't have to pass stuff through it. [37:17.770 --> 37:18.470] You can encrypt it. [37:19.230 --> 37:20.410] We're rolling on DNS. [37:25.450 --> 37:28.210] I know a really good VPN service, but I won't talk about it. [37:39.950 --> 37:44.370] The question is, can the cable company detect whether or not you've made changes to the device? [37:46.090 --> 37:51.730] I would say possibly, if they have any sort of remote management facility. [37:51.730 --> 37:52.950] I did change your settings. [37:54.530 --> 38:01.550] So, we logged into a test environment and are doing this in the lab with our own equipment. [38:02.310 --> 38:08.350] If they set it up properly, you can get an SNMP trap sent up to the cable company on a config change, right? [38:08.510 --> 38:08.850] Correct. [38:09.210 --> 38:09.310] Yeah. [38:20.440 --> 38:22.500] I think MAC addresses were in there. [38:23.200 --> 38:24.980] I mean, the worst was the DNS. [38:25.240 --> 38:26.860] The reboot was the most fun one. [38:27.780 --> 38:31.880] The admin passwords, you could change the technician password, I guess. [38:32.440 --> 38:32.920] Yeah, you could. [38:33.060 --> 38:34.000] Yeah, that was nice. [38:34.100 --> 38:36.840] You could just query the password in clear text and see. [38:36.840 --> 38:50.420] So, theoretically, if you, you know, if you were a provider and you had some additional accounts in there for technicians or whatnot, you could query these accounts, get their passwords, and hopefully those passwords are different on different devices. [38:50.980 --> 38:51.440] Have [38:54.460 --> 38:54.840] you... [38:54.840 --> 38:55.780] We did. [38:55.840 --> 38:57.160] We have a discrepancy in that. [38:57.340 --> 39:00.900] So, Charlie's shipped with Telnet enabled. [39:02.740 --> 39:04.980] Mine shipped with only the web interface. [39:15.020 --> 39:15.680] No comment. [39:17.620 --> 39:19.240] It appears to be Linux-based, yeah. [39:19.800 --> 39:21.660] So, you didn't make it clear in the talk. [39:21.820 --> 39:31.320] You said that, you know, the worst case scenario and the second worst case scenario, but in your experience with these devices, was this interface actually available on the public IP or was it only available on the LAN? [39:31.620 --> 39:37.000] Obviously, you know, they're both problems, but one is a much bigger problem, right, because it requires no interaction from the user. [39:37.000 --> 39:37.140] Correct. [39:38.860 --> 39:40.920] I'm going to refrain from answering that question. [39:41.020 --> 39:41.200] Okay. [39:42.700 --> 39:44.240] Because we were in Forbes yesterday. [39:48.640 --> 39:50.660] Is the system running Linux inside? [39:51.440 --> 39:52.900] Yeah, 2.6.18. [39:53.140 --> 39:53.420] Correct. [39:53.820 --> 39:57.040] Does that mean they have to release their changes via GPL? [39:58.880 --> 40:00.480] You can ask ARRIS about that. [40:00.760 --> 40:01.320] That would be nice. [40:08.110 --> 40:13.250] You said you kept it in a test environment, so is it possible they release a new firmware? [40:15.530 --> 40:16.010] Sure. [40:17.070 --> 40:18.730] I'm hoping so, since yesterday. [40:18.730 --> 40:19.310] It would be great. [40:20.730 --> 40:22.910] I'd really like to turn my Internet connection back on. [40:33.340 --> 40:33.820] Bye. [40:34.140 --> 40:34.500] Yesterday? [40:34.500 --> 40:36.680] I wasn't informed of anything. [40:36.860 --> 40:45.820] No, actually, I should clarify the folks we spoke with were extremely friendly and cooperative, and were truly concerned about the problem. [40:48.080 --> 40:56.200] But the, you know, not all the providers have been in contact with us who, that may be affected by this. [41:07.160 --> 41:14.600] So, we tried a really long time to get in contact with people, and it proved to be really difficult. [41:16.180 --> 41:37.560] So, kind of the number one lesson learned from this for both manufacturers and providers is that it would be really helpful if there was a place on your website for security researchers to submit vulnerabilities, to work with you directly, to be able to facilitate a community that made more secure computing for just the general public. [41:38.220 --> 41:43.880] Making it impossible to get to somebody, just, it's not the greatest practice. [41:43.880 --> 41:51.070] And maybe we're just not skilled enough in getting through to the people that need to listen to us, but it certainly wasn't easy. [41:51.260 --> 41:55.520] We tried scouring the web for, you know, internal email addresses. [41:55.720 --> 41:56.850] We called the support lines. [41:57.110 --> 42:01.310] We sent mail to standard abuse at and security at. [42:04.060 --> 42:24.420] You know, if you take the model of a lot of web companies, you know, whether it be the hacking competition or whether it be the, I think PayPal has something like a bounty program where you can test in their sandbox environment and report vulnerabilities very easily. [42:24.760 --> 42:30.730] If that same mentality existed, it would be, I think, beneficial to everybody. [42:30.730 --> 42:40.150] Did you try to contact SERPT or DHS because other researchers have said that going through that must be helpful to some of the, you know, stuck to that type of situations? [42:41.440 --> 42:44.000] No, we do not, but maybe we will. [42:44.960 --> 42:49.060] So I guess the question is, did Forbes call you or did you call Forbes? [42:49.540 --> 42:50.400] They called us. [42:51.600 --> 42:53.230] How did they find out about this? [42:53.400 --> 42:54.000] The talk? [42:54.190 --> 42:54.480] I hope. [43:01.090 --> 43:02.250] Is Forbes in the room? [43:13.810 --> 43:14.510] I think we're done. [43:14.510 --> 43:14.670] I think we're done. [43:14.930 --> 43:15.690] No more questions? [43:16.330 --> 43:16.950] Thanks, everybody. [43:17.130 --> 43:17.250] Thank you. [43:19.710 --> 43:20.950] Please don't try to...