bk99.de entertain the web since 1997

Masses of security holes in networked devices

Summary

In 2014 researchers at the French institute Eurécom automatically analysed 32,356 firmware files of networked devices. 693 images contained at least one hole, 38 of them previously unknown; more than 300 showed signs of backdoors, for example in a device from the Belkin Wemo series. They also collected 109 private RSA keys from more than 400 images.

Ideas

  • Automated firmware analysis finds security problems on a large scale.
  • Preset user accounts with weak passwords were widespread.
  • Private keys in public firmware render the encryption of all devices worthless.
  • A Wemo device executed commands as root when sent certain multicast packets.

Insights

  • Manufacturers use the same keys and components across many devices.
  • What is in public firmware is no longer a secret.

Facts

  • Almost 700 images contained preset user accounts; in 58 cases the hashes were cracked.
  • Popular passwords were pass, logout, helpme and none at all.
  • In 41 cases the researchers found the private key and certificate together.

References

Critique

  • The report hardly names any manufacturers, so readers cannot match their own devices.

Recommendations

  • Put IoT devices in a separate network segment without access to other systems.
  • Where possible, replace manufacturer firmware with maintained open alternatives such as OpenWrt.

Read the original article

Search the Web Archive