Backdoor discovered in Wi-Fi routers
Summary
Around the turn of 2013/2014, Eloi Vanderbeken discovered a backdoor on port 32764 on a Linksys WAG200G router. A script made it possible to execute commands and read out the configuration including passwords. Numerous models from Linksys, Netgear, Cisco and Diamond were apparently affected, presumably because of shared DSL modems from the Taiwanese manufacturer Sercomm.
Ideas
- An undocumented service on an unusual port gave full access.
- Firmware analysis uncovered the backdoor.
- A shared supplier component spread the backdoor across many brands.
- The response “ScMM” gave away the manufacturer Sercomm.
Insights
- A device’s security depends on suppliers the buyer does not know.
- Whoever can examine firmware themselves finds what manufacturers keep quiet about.
Facts
- The backdoor listened on port 32764.
- Vanderbeken documented the find on GitHub.
- Via Shodan, almost 3,000 IP addresses responded on port 32764, around 60 of them from Germany.
References
Critique
- The list of affected models comes from user reports and has not been confirmed by the manufacturer.
Remarks
- In April 2014 Vanderbeken showed that an “update” had only hidden the backdoor and that it could be reactivated with a special packet.
Recommendations
- Scan your own routers from inside and outside for open ports, including unusual ones.
- Where possible, replace manufacturer firmware with OpenWrt.
Links to the original source and the Web Archive open in a new tab.