Тёмный

Discovering Backdoor in Chinese Router Firmware Update Server - Hacking the Totolink WiFi Router 

Matt Brown
Подписаться 69 тыс.
Просмотров 15 тыс.
50% 1

Опубликовано:

 

11 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 112   
@88tx
@88tx 2 дня назад
Chinese iot companies: *pray that nobody discovers their vulnerabilities* matt: what's up everybody this is Matt Brown with another iot hacking video
@Rilch
@Rilch День назад
You know it's bad when it only takes Matt 15 minutes to explain it.
@mattbrwn
@mattbrwn День назад
brevity? what's that?
@machine_cow
@machine_cow 14 часов назад
@@mattbrwn I personally love how much detail you put into explaining your process in videos! Brevity sucks when it comes at the cost of information :))
@OnlyVoltsRT
@OnlyVoltsRT День назад
Ehy matt. Nice video as Always. I know that all of this is for educational purpose but using scanning tools like nuclei with default settings could lead to a very high number of requests to server, which can be detected by blue team. I know that security of this company is so bad but be careful using this tools , especially if it isn't in a bug bounty program
@mattbrwn
@mattbrwn День назад
Appreciate the comment :) I totally agree you need to be careful with a tool like this.
@henkslaaf3738
@henkslaaf3738 День назад
They do not have a blue team ;-)
@termnl9975
@termnl9975 2 дня назад
Tbh if you cant reach then, then do the right thing and rm -rf / that server to prevent carnage
@mattbrwn
@mattbrwn 2 дня назад
So the funny thing is that the server's disk space is full... So that might help things out 😁
@SeanBZA
@SeanBZA 2 дня назад
@@mattbrwn Probably full because the attacker is using it as a C&C server, and a data exfiltration server, and at the same time it is also being used as repository to store ransomware keys as well. Removing all that would probably be good, but easier is to first wipe all of that out, then reboot, after running an update on the server.
@mattbrwn
@mattbrwn День назад
actually they are taking daily backups of the database and not deleting them ;)
@SeanBZA
@SeanBZA День назад
@@mattbrwn So doing the rm -rf will be a service to them.......
@RickDkkrd
@RickDkkrd День назад
Going full Robin Hood would be to patch the current firmware to never request updates, push it to all the devices, and then wipe the server.
@Holycurative9610
@Holycurative9610 2 дня назад
I spend a lot of time in the Philippines, I'm in the UK, and when we're out there I love picking up the really dodgy Chinesium crap just to take it to bits and explore the software. You can buy some really interesting things for less than £5 or 600-700PHP, that's a days wages out there for a lot of people but it's pennies for us in the West.
@mattbrwn
@mattbrwn День назад
Yes! I came back from my trip to Asia with a suitcase full of random devices 🤣
@probablypablito
@probablypablito День назад
Wow this is straight out of a HTB CTF, good work as always!
@wasabinow
@wasabinow 2 дня назад
Matt, this is great info again! At first glance I was expecting to hear about net gear Cisco and kv bots. But after the first few minutes, it was all about the totolink. Thank you for sharing this vulnerability. Also, words of wisdom for you while you are recovering, a hack a day makes your problems go away, or is it an apple a day keeps the bugs away! 😂
@poweron3654
@poweron3654 2 дня назад
Another great video! Hope you start feeling better soon!
@makers_lab
@makers_lab День назад
This couldn't be any more perfect, and it's precisely why we developed a system that blocks execution of unknown PHP code within the PHP engine; detecting unknown files that appear is good to do but likely to be too late, so we focussed on the execution engine and blocking inside the engine itself. Were they using the system, they'd get a real time alert when attempting to execute the file, the malware wouldn't run, and they'd have a chance to unblock the file if it was a false positive. Mostly gone are the days of Apache letting you run PHP code hidden in exif tags of image files, but using exploits to plant arbitrary code onto PHP based systems is still incredibly common and widespread.
@neoish
@neoish День назад
Which system?
@VictorArrieta_Vzla
@VictorArrieta_Vzla День назад
Excellent as usual Matt! Thanks
@bdL91
@bdL91 16 часов назад
Your videos are so interesting. I'm still learning a lot of this stuff but you break it down really well.
@ggorg0
@ggorg0 День назад
Near my school, in Poland, I sometimes see a random wifi network just named "Totolink". Interesting 🤔
@Sar4h__32
@Sar4h__32 День назад
Great Video as always! Though one thing you should take a look at is your audio. In I think all of your videos, there's a crackling sound, which I don't get when watching other creators or playing games/listening to music.
@mattbrwn
@mattbrwn 12 часов назад
Working on debugging this. Is it constant? Or just at certain times?
@Sar4h__32
@Sar4h__32 8 часов назад
@@mattbrwn I think it's constant. If you don't hear it on your PC, maybe try to listen to your video on your phone? Or take some old headphones and try those
@playgame38
@playgame38 День назад
A reverse shell to investigate more is so tempting
@dingokidneys
@dingokidneys День назад
Fascinating stuff. No wonder botnets are the problem that they are.
@YanSummer-o6t
@YanSummer-o6t День назад
RU-vid recommended I am not dissapointed. Cool youtbe channel
@zapjunkie
@zapjunkie День назад
This is amazing. Thanks for sharing!
@idiotspieltminecraft1032
@idiotspieltminecraft1032 День назад
Could you please take a look at a FritzBox?
@hariranormal5584
@hariranormal5584 День назад
ah yes best german loved isp router
@idiotspieltminecraft1032
@idiotspieltminecraft1032 День назад
@@hariranormal5584 yeah, it is really good compared to a lot of other isp routers.
@ligius3
@ligius3 День назад
I think those are pretty well studied and the security and development for them are still going strong.
@hafo821
@hafo821 14 часов назад
@@hariranormal5584 the most hated one 🤣😅
@attribute-4677
@attribute-4677 День назад
There you go!! Expose that garbage. Thank you!!
@UNcommonSenseAUS
@UNcommonSenseAUS 2 дня назад
Keep up the great work bruv
@pauliusz
@pauliusz День назад
When you buy such router first task should be to install genuine OpenWRT (if possible)
@fuzzinn
@fuzzinn 2 дня назад
Nice work Mat
@johnhank6721
@johnhank6721 2 дня назад
Excited to watch this
@kaydog890
@kaydog890 День назад
Engagement Thanks, Matt
@angrydachshund
@angrydachshund 21 час назад
Well done
@bertblankenstein3738
@bertblankenstein3738 День назад
Patch the firmware to check for firmware on a server you control. From there you can have your way, for better or worse.
@braniak
@braniak 4 часа назад
Have you tried those Chinese pfsense pre-installed box already?
@AmCanTech
@AmCanTech День назад
Great video
@offensive-operator
@offensive-operator День назад
that was great. i dont have one of those but thank you for this video.
@XYZ56771
@XYZ56771 День назад
get well soon!
@stereosteve1
@stereosteve1 2 дня назад
Awesome video
@02ranger
@02ranger 19 часов назад
Unplugged my totolink router, now I can’t finish the video to see why I had to unplug it…..😅
@josh9761
@josh9761 День назад
Man this is perfect
@fnulnu5645
@fnulnu5645 День назад
This is nuts
@neoXXquick
@neoXXquick День назад
nice find...
@FreneticSynapses
@FreneticSynapses 2 дня назад
Ah PHP. Makes sense lol
@coolirc
@coolirc День назад
Maybe you should explain how to patch the device to not look for updates from the server
@7_of_9
@7_of_9 22 часа назад
I see name brand routers, Chinese of course, on Amazon for like $20, $40 USD. Are these routers running firmwares replaced by Chinese to get on your Network 🤔
@markramsell454
@markramsell454 День назад
Do a 'ps laxw' on the server and maybe a 'who -a' to see if there's any hacker remnants. Don't publish the output, maybe comment on suspicious things you note.
@7_of_9
@7_of_9 22 часа назад
Anything Chinese is hot trash! You that amazing smart plug transferring data at 3am when you are sleeping 😂😂
@309electronics5
@309electronics5 17 часов назад
Most things including phones are made in china lmao😂. Rather say "anything DESIGNED by the chinese is hot trash"
@Shinika01
@Shinika01 2 дня назад
Well pwned dude ;)
@Misimpa
@Misimpa 2 дня назад
Unbelievable 😂
@reset5899
@reset5899 День назад
update: the vuln has been "patched" (either updated their php framework or deleted the file) but the backdoor is still there ive removed it
@tetttettamilli6761
@tetttettamilli6761 2 дня назад
More vids please.
@njmust
@njmust 2 дня назад
I have Huawei router like hg8245 or hg8247 u-boot of these devices are uninterruptabe so how i can extract or flash firmware on these devices.. Plz help...
@csgultekin
@csgultekin 2 дня назад
chip off
@309electronics5
@309electronics5 17 часов назад
Just take the chip off, or if it has exposed pins try to do the glitching method to prevent uboot from loading the kernel
@oktaneak4259
@oktaneak4259 День назад
Idumped the firmware from nor spi flash for Huawei dg8045 with customized firmware by vodafone the webpage login interface has admin and user permissions the user one is printed on the back of the router the admin has fully control on the router I tried to investigate the firmware the kernel extracted them and tried using ghydra but nothing even the Cfg file is encrypted i tried to decrypt some info but nothing even the when i tried to gain access through uart shell the router boots up and the shell stops on starting kernel i interrupted the the 2 bootloaders first is bootrom the second is hiboot to manipulate loading kernel process the common bootargs doesn't work
@harrytsang1501
@harrytsang1501 День назад
my Huawei HG8045 is a lot less secure than yours. can download a backup config, copy my user password hash to admin, restore backup and I have admin access. The config is encrypted but there's also a git repo with documentation on how to decrypt Also, the admin password is the same default one that you can find online once you know the hash. In my case the username is "r&duser"
@lethal_larry
@lethal_larry 15 часов назад
lmao 10:00 *insert pop goes the weasel soundclip*
@trioharsanto5257
@trioharsanto5257 19 часов назад
sir f663na cant flash via urat
@UCcdTp7XpCkVLkaRCsDcifFg
@UCcdTp7XpCkVLkaRCsDcifFg 6 часов назад
gg bro
@fiskebent
@fiskebent День назад
Just out of curiosity, is what you show legal to do in the US? Where I am, in Denmark, it's illegal to access systems without authorization. IANAL, but I think what you did would be deemed hacking and illegal.
@bertblankenstein3738
@bertblankenstein3738 День назад
One might agree with what you say, IF, some effort was put in to securing the server. They provided the ability to enter commands through an http post to everyone without requiring authorization. So one could argue that there is no authorization requirement. Matt didn't alter anything on the server, someone else already did that.
@HenryWu-rc5gw
@HenryWu-rc5gw День назад
Take care of yourself
@jitukhatri5807
@jitukhatri5807 2 дня назад
please share this firmware link..
@ChickenPermissionOG
@ChickenPermissionOG День назад
I can never run wireshark without turning off my routers security.
@BrAiNeeBug
@BrAiNeeBug День назад
the server got cleaned from internet
@matthewthomas7220
@matthewthomas7220 2 дня назад
I'm curious who the maniacs buying chinese IoT devices in the first place are
@88tx
@88tx 2 дня назад
poor people from asia. source: am asian
@mattbrwn
@mattbrwn 2 дня назад
This device is for the Asian market.
@SeanBZA
@SeanBZA 2 дня назад
Everybody in the world buying any router or smart device from a unbranded (or even well known brand name that is now merely a marketing name put on the cheapest stuff they can find) store, or if you get any ISP or telco supplied equipment, which is the cheapest thing they can get, with the firmware often only changed to put a branding on the screens, nothing else, and relying on the OEM to do upgrades if ever.
@TradieTrev
@TradieTrev День назад
Don't you judge my Aliexpress purchases haha!
@crashowerride
@crashowerride 2 дня назад
You left the host exposed for a frame in 5:05. Everyone can see it. You should probably fix that 🙂
@mattbrwn
@mattbrwn 2 дня назад
Thanks :) fixed. but now you get the free shell!!
@crashowerride
@crashowerride День назад
@@mattbrwn thanks China! 😀 Great video as always man, keep it up!
@mytube7473
@mytube7473 16 часов назад
but... i came for my free shell ? >:)
@BjornTheF3llHanded
@BjornTheF3llHanded День назад
Never buy CN made critical netowrk devices, and moreover, when you buy USB cables etc made in CN,. dont leave them plugged in :D
@hedgehogform
@hedgehogform 2 дня назад
I'm also sick lol.
@mnageh-bo1mm
@mnageh-bo1mm День назад
damn
@livius09
@livius09 День назад
is what you did cross site scripting or how did you get these responses. can someone explain.
@ligius3
@ligius3 День назад
No, it's remote code execution. The PHP module in apache (I assume) is an old version and configured in a wrong way. If you send a special string you can add (bash) commands to it that will be executed on the remote server.
@livius09
@livius09 16 часов назад
@@ligius3 thanks
@ThaFuzzwood
@ThaFuzzwood День назад
Not a backdoor, made mandatory by Xi pp
@mjmeans7983
@mjmeans7983 День назад
How do you know that the update server vulnerability you've shown isn't a honeypot?
@mattbrwn
@mattbrwn День назад
because its the server that my wifi router connects to?
@FLECOM
@FLECOM 17 часов назад
any of these cheap devices from overseas are only useful if they can run openwrt or similar open source firmware... would never trust firmware from even "reputable" brands as most never get updated since these devices are all treated as disposable anyway
@jpphoton
@jpphoton День назад
who the F would buy a fkn TOTO router
@itstheweirdguy
@itstheweirdguy День назад
Why don't you take on devices from major supposedly trusted brands like ASUS, Netgear, Linksys, and TP-Link and hack those? That would be cool! Of course you aren't supposed to buy chinese junk. Instead of this which was already hacked for you by both the manufacturer and someone online.
@soneomeelse
@soneomeelse День назад
A ThinkPHP RCE bug on manufacturers' firmware hosting site is very different from what implies in video title. On the contrary, they are the victim to this incident as well, even they do want a backdoor they dont implement it this way. Ironically, aint you conducting an unauthorised penetration scan cross border and making an irresponsible vulnerability disclosure ? Imagine it is other way around, "Chinese hacker compromises US tech companies."
@schlickit628
@schlickit628 День назад
He said he tried to contact them. I agree it’s not exactly what we think of as a hardware backdoor, but I still don’t like your framing. It suggests you have to have some special credentials to do a security audit of hardware you own.
@soneomeelse
@soneomeelse День назад
@@schlickit628 You do, theoretically. CISCO switches/routers put these warning messages in telnet/ssh banner. They claim to preserve the rights to sue anyone reverse engeering their firmware without authorization, though they rarely exercise them. (probably for a PR reason) However, what he's done is way above passive/static rev engineering some files he 'own', he conducted an active intrusive URL scan against a live production backend owned by a foreign commercial entity presumably through home Internet and made an irresponsible vuln disclosure, I dont see any element of this is compliant at all, as I said if it is the other way around, the narrative would be Chinese hacking US tech companies. Pure hypocrisy, if you compare what the clickbaity title implies to his actual behaviour.
@soneomeelse
@soneomeelse День назад
@@schlickit628 You do, theoretically. Switches/routers put warning messages in telnet/ssh banner claiming they preserve rights sueing anyone reverse engineers their intellectual property protected firmware without authorization, though they rarely exercise them, probably for a PR reason. However, what he's done is way above passive/static rev engineering some files he 'own', he conducted an active intrusive URL scan against a live production backend owned by a foreign commercial entity presumably through home Internet and made an irresponsible vuln disclosure, I dont see any element of this is compliant at all, as I said if it is the other way around, the narrative would be -youtube deletes my comment-. Pure hypocrisy, if you compare what the title implies to his actual behaviour.
@ItsCrossshield45
@ItsCrossshield45 День назад
Pls a video about unlocking jiofi m2s. I will post the same in your videos until you see this❤. Counter : 2
@kerbalette156
@kerbalette156 2 дня назад
1st
Далее
Satisfying DIY Earing for the Little Ones! 😲
00:33
I built a retro Mac from BRAND NEW parts!
32:18
Просмотров 257 тыс.
How to Actually Escape the Botnet
32:17
Просмотров 525 тыс.
Building a Tiny Office Pod Under My Stairs
51:47
Просмотров 3,1 млн