bk99.de entertain the web since 1997

TR-069 remote maintenance hole in DSL routers: German internet providers call their networks secure

Summary

After Shahar Tal’s DEF CON talk about holes in TR-069 remote maintenance servers, heise asked German providers in 2014 how they were protected. Telekom, Vodafone, 1&1 and others considered their networks secure because their routers reject self-signed certificates or only contact preset servers. Tal had shown that a hijacked Auto Configuration Server can redirect or read out thousands of routers.

Ideas

  • Providers use TR-069 to configure their customers’ routers remotely.
  • A compromised configuration server controls all connected routers.
  • Certificate checks and fixed server addresses protect the channel.
  • With some providers, TR-069 could be switched off in the web interface.

Insights

  • Central remote maintenance simplifies updates but creates a single point from which everything can be attacked.
  • The security of the home router also depends on the provider’s infrastructure.

Facts

  • Via the ACS of an Iraqi provider, Tal could have accessed over 7,000 routers.
  • Some providers used the standard port 7547 for connection requests.
  • According to Tal, the free ACS programs OpenACS and GenieACS had also had known holes for two years.

References

Critique

  • The providers’ statements are self-assessments; an independent review is missing.

Remarks

  • In November 2016 a Mirai variant knocked out around 900,000 Telekom routers via port 7547.

Recommendations

  • Switch off TR-069 if you manage your own routers and do not need provider maintenance.
  • Check whether remote maintenance ports on the router are reachable from the internet.

Read the original article

Search the Web Archive