bk99.de entertain the web since 1997

AVM routers: another hole in the FritzBox remote maintenance function

Summary

In 2014 heise Security found a hole in the MyFritz apps for Android and iOS through which attackers could access a FritzBox’s web interface without a password. The apps did not check the box’s SSL certificate sufficiently, so an attacker on someone else’s network could grab the session ID. AVM solved this with certificate pinning: the apps remember the certificate’s fingerprint on first contact and warn if it changes.

Ideas

  • Encryption without certificate checking does not protect against man-in-the-middle attacks.
  • An intercepted session ID replaces the password.
  • Every FritzBox runs its own certificate authority called localhost.
  • Certificate pinning replaces the missing trusted CA.

Insights

  • Self-signed certificates need a different trust anchor, otherwise HTTPS is ineffective.
  • The first connection is the critical moment with the trust-on-first-use principle.

Facts

  • With web access, an attacker could create their own user accounts and misuse telephony.
  • The hole had nothing to do with the TR-069 problems being discussed at the same time.
  • In early 2014 criminals had already exploited another FritzBox hole to make expensive phone calls via hijacked routers.

References

Critique

  • The report comes from the discoverer itself and does not assess how many users actually administered their router from other people’s Wi-Fi networks.

Recommendations

  • Set up pinned connections to your own infrastructure for the first time on your own trusted network.
  • Reach router management remotely via a VPN rather than via an open web interface.

Read the original article

Search the Web Archive