bk99.de entertain the web since 1997

Blog 2014

19 posts

Projects, Linux, networks, systems, finds and internet standards from 2014.

Heartbleed and its aftermath

Zakir Durumeric examines Heartbleed with internet-wide measurements and shows its spread, key risks, speed of response and the vulnerable systems that remained. Small memory bugs can trigger global infrastructure crises through widely used libraries. An effective response needs inventory, patching, key changes and transparent communication together.

Read the full post

TR-069 remote maintenance hole in DSL routers: German internet providers call their networks secure

After Shahar Tal’s DEF CON talk about holes in TR-069 remote maintenance servers, heise asked German providers in 2014 how they were protected. Telekom, Vodafone, 1&1 and others considered their networks secure because their routers reject self-signed certificates or only contact preset servers. Tal had shown that a hijacked Auto Configuration Server can redirect or read out thousands of routers.

Read the full post

AVM routers: another hole in the FritzBox remote maintenance function

In 2014 heise Security found a hole in the MyFritz apps for Android and iOS through which attackers could access a FritzBox’s web interface without a password. The apps did not check the box’s SSL certificate sufficiently, so an attacker on someone else’s network could grab the session ID. AVM solved this with certificate pinning: the apps remember the certificate’s fingerprint on first contact and warn if it changes.

Read the full post

Masses of security holes in networked devices

In 2014 researchers at the French institute Eurécom automatically analysed 32,356 firmware files of networked devices. 693 images contained at least one hole, 38 of them previously unknown; more than 300 showed signs of backdoors, for example in a device from the Belkin Wemo series. They also collected 109 private RSA keys from more than 400 images.

Read the full post

How the immune system fights bacterial infections

KG explains the multi-stage immune defence as a coordinated interplay of barriers, phagocytes, messenger substances and specialised lymphocytes. Robust defence comes from overlapping layers rather than from a single perfect protective mechanism. Biological security has to remove intruders without excessively damaging its own organism.

Read the full post

Secure Boot in practice: How firmware bugs undermine the protection

Matthew Garrett summarises MITRE’s research from SyScan 2014: on many computers, Secure Boot can be bypassed from within the running operating system. The cause is not the cryptography but wrongly stored policies and missing lock bits in the chipset. Garrett still considers Secure Boot a real security gain whose obvious flaws will only disappear over several hardware generations.

Read the full post

OpenSSH 6.5 released

In January 2014 OpenSSH 6.5 brought key exchange with Curve25519 and signatures with Ed25519, both developed by Daniel J. Bernstein. One reason was the Snowden revelations, since the widely used NIST curves came from an NSA employee. Ed25519 replaces ECDSA, which is vulnerable when random number generators are weak.

Read the full post

Intelligence service ensured weak GSM encryption

According to the Norwegian newspaper Aftenposten, the British intelligence service pushed in the 1980s for GSM to be only weakly encrypted. Originally the standard was to offer 128 bits, but A5/1 ended up with an effective 54 bits; the British even wanted only 48 bits. Germany, fearing espionage by the Eastern Bloc, pushed for stronger encryption.

Read the full post

Backdoor discovered in Wi-Fi routers

Around the turn of 2013/2014, Eloi Vanderbeken discovered a backdoor on port 32764 on a Linksys WAG200G router. A script made it possible to execute commands and read out the configuration including passwords. Numerous models from Linksys, Netgear, Cisco and Diamond were apparently affected, presumably because of shared DSL modems from the Taiwanese manufacturer Sercomm.

Read the full post