TR-069 remote maintenance hole in DSL routers: German internet providers call their networks secure
Summary
After Shahar Tal’s DEF CON talk about holes in TR-069 remote maintenance servers, heise asked German providers in 2014 how they were protected. Telekom, Vodafone, 1&1 and others considered their networks secure because their routers reject self-signed certificates or only contact preset servers. Tal had shown that a hijacked Auto Configuration Server can redirect or read out thousands of routers.
Ideas
- Providers use TR-069 to configure their customers’ routers remotely.
- A compromised configuration server controls all connected routers.
- Certificate checks and fixed server addresses protect the channel.
- With some providers, TR-069 could be switched off in the web interface.
Insights
- Central remote maintenance simplifies updates but creates a single point from which everything can be attacked.
- The security of the home router also depends on the provider’s infrastructure.
Facts
- Via the ACS of an Iraqi provider, Tal could have accessed over 7,000 routers.
- Some providers used the standard port 7547 for connection requests.
- According to Tal, the free ACS programs OpenACS and GenieACS had also had known holes for two years.
References
Critique
- The providers’ statements are self-assessments; an independent review is missing.
Remarks
- In November 2016 a Mirai variant knocked out around 900,000 Telekom routers via port 7547.
Recommendations
- Switch off TR-069 if you manage your own routers and do not need provider maintenance.
- Check whether remote maintenance ports on the router are reachable from the internet.
Links to the original source and the Web Archive open in a new tab.