This Week In Security: VPN Gateways, Attacks In The Wild, VLC, And An IP Address Caper

We’ll start with more Black Hat/DEFCON news. [Meh Chang] and [Orange Tsai] from Devcore took a look at Fortinet and Pulse Secure devices, and found multiple vulnerabilities. (PDF Slides) They are publishing summaries for that research, and the summary of the Fortinet research is now available.

It’s… not great. There are multiple pre-authentication vulnerabilities, as well as what appears to be an intentional backdoor.

CVE-2018-13379 abuses an snprintf call made when requesting a different language for the device login page. Snprintf is an alternative to sprintf, but intended to prevent buffer overflows by including the maximum string length to write to the target buffer, which sounds like a good idea but can lead to malicious truncation.

The code in question looks like snprintf(s, 0x40, "/migadmin/lang/%s.json", lang);.
When loading the login page, a request is made for a language file, and the file is sent to the user. At first look, it seems that this would indeed limit the file returned to a .json file from the specified folder. Unfortunately, there is no further input validation on the request, so a language of ../../arbitrary is considered perfectly legitimate, escaping the intended folder.  This would leak arbitrary json files, but sincesnprintf doesn’t fail if it exceeds the specified length, sending a request for a lang that’s long enough results in the “.json” extension not being appended to the request either.

A metasploit module has been written to test for this vulnerability, and it requests a lang of /../../../..//////////dev/cmdb/sslvpn_websession. That’s just long enough to force the json extension to fall off the end of the string, and it is Unix convention is to ignore the extra slashes in a path. Just like that, the Fortigate is serving up any file on its filesystem just for asking nice.

More worrying than the snprintf bug is the magic value that appears to be an intentional backdoor. A simple 14 character string sent as an http query string bypasses authentication and allows changing any user’s password — without any authentication. This story is still young, it’s possible this was intended to have a benign purpose. If it’s an honest mistake, it’s a sign of incompetence. If it’s an intentional backdoor, it’s time to retire any and all Fortinet equipment you have.

Pulse Secure VPNs have a similar pre-auth arbitrary file read vulnerability. Once the full report is released, we’ll cover that as well.

Exploitation in the Wild

But wait, there’s more. Hide your kids, hide your wife. Webmin, Pulse Secure, and Fortigate are already being exploited actively in the wild, according to ZDNet. Based on reports from Bad Packets, the Webmin backdoor was being targeted in scans within a day of announcement, and exploited within three days of the announcement. There is already a botnet spreading via this backdoor. It’s estimated that there are around 29,000 vulnerable Internet-facing servers.

Both Pulse Secure and Fortinet’s Fortigate VPN appliances are also being actively targeted. Even though the vulnerabilities were reported first to the vendors, and patched well in advance of the public disclosure, thousands of vulnerable devices remain. Apparently routers and other network appliance hardware are fire-and-forget solutions, and often go without important security updates.

VLC is Actually Vulnerable This Time

The VLC media player has released a new update, fixing 11 CVEs. These CVEs are all cases of mishandling malformed media files, and are only exploitable by opening a malicious file with VLC. Be sure to go update VLC if you have it installed. Even though no arbitrary code execution has been demonstrated for any of these issues, it’s likely that it will eventually happen.

Gray Market IP Addresses

With the exhaustion of IPv4 addresses, many have begun using alternative methods to acquire address space, including the criminal element. Krebs on Security details his investigation into one such story: Residential Networking Solutions LLC (Resnet). It all started with an uptick in fraudulent transactions originating from Resnet residential IP addresses. Was this a real company, actually providing internet connectivity, or a criminal enterprise?

Kilopower: NASA’s Offworld Nuclear Reactor

Here on Earth, the ability to generate electricity is something we take for granted. We can count on the sun to illuminate solar panels, and the movement of air and water to spin turbines. Fossil fuels, for all their downsides, have provided cheap and reliable power for centuries. No matter where you may find yourself on this planet, there’s a way to convert its many natural resources into electrical power.

But what happens when humans first land on Mars, a world that doesn’t offer these incredible gifts? Solar panels will work for a time, but the sunlight that reaches the surface is only a fraction of what the Earth receives, and the constant accumulation of dust makes them a liability. In the wispy atmosphere, the only time the wind could potentially be harnessed would be during one of the planet’s intense storms. Put simply, Mars can’t provide the energy required for a human settlement of any appreciable size.

The situation on the Moon isn’t much better. Sunlight during the lunar day is just as plentiful as it is on Earth, but night on the Moon stretches for two dark and cold weeks. An outpost at the Moon’s South Pole would receive more light than if it were built in the equatorial areas explored during the Apollo missions, but some periods of darkness are unavoidable. With the lunar surface temperature plummeting to -173 °C (-280 °F) when the Sun goes down, a constant supply of energy is an absolute necessity for long-duration human missions to the Moon.

Since 2015, NASA and the United States Department of Energy have been working on the Kilopower project, which aims to develop a small, lightweight, and extremely reliable nuclear reactor that they believe will fulfill this critical role in future off-world exploration. Following a series of highly successful test runs on the prototype hardware in 2017 and 2018, the team believes the miniaturized power plant could be ready for a test flight as early as 2022. Once fully operational, this nearly complete re-imagining of the classic thermal reactor could usher in a whole new era of space exploration.

Continue reading “Kilopower: NASA’s Offworld Nuclear Reactor”

Following Pigs: Building An Injectable Livestock Tracking System

I’m often asked to design customer and employee tracking systems. There are quite a few ways to do it, and it’s an interesting intersection of engineering and ethics – what information is reasonable to collect in different contexts, anonymizing and securely storing it, and at a fundamental level whether the entire system should exist at all.

On one end of the spectrum, a system that simply counts the number of people that are in your restaurant at different times of day is pretty innocuous and allows you to offer better service. On the other end, when you don’t pay for a mobile app, generally that means your private data is the product being bought and sold. Personally, I find that the whole ‘move fast and break things’ attitude, along with a general disregard for the privacy of user data, has created a pretty toxic tech scene. So until a short while ago, I refused to build invasive tracking systems – then I got a request that I simply couldn’t put aside…

Continue reading “Following Pigs: Building An Injectable Livestock Tracking System”

The Amazon Dash Button: A Retrospective

The Internet of Things will revolutionize everything! Manufacturing? Dog walking? Coffee bean refilling? Car driving? Food eating? Put a sensor in it! The marketing makes it pretty clear that there’s no part of our lives which isn’t enhanced with The Internet of Things. Why? Because with a simple sensor and a symphony of corporate hand waving about machine learning an iPhone-style revolution is just around the corner! Enter: Amazon Dash, circa 2014.

The first product in the Dash family was actually a barcode scanning wand which was freely given to Amazon Fresh customers and designed to hang in the kitchen or magnet to the fridge. When the Fresh customer ran out of milk they could scan the carton as it was being thrown away to add it to their cart for reorder. I suspect these devices were fairly expensive, and somewhat too complex to be as frequently used as Amazon wanted (thus the extremely limited launch). Amazon’s goal here was to allow potential customers to order with an absolute minimum of friction so they can buy as much as possible. Remember the “Buy now with 1-Click” button?

That original Dash Wand was eventually upgraded to include a push button activated Alexa (barcode scanner and fridge magnet intact) and is generally available. But Amazon had pinned its hopes on a new beau. Mid 2015 Amazon introduced the Dash Replenishment Service along with a product to be it’s exemplar – the Dash Button. The Dash Button was to be the 1-Click button of the physical world. The barcode-scanning Wands require the user to remember the Wand was nearby, find a barcode, scan it, then remember to go to their cart and order the product. Too many steps, too many places to get off Mr. Bezos’ Wild Ride of Commerce. The Dash Buttons were simple! Press the button, get the labeled product shipped to a preconfigured address. Each button was purchased (for $5, with a $5 coupon) with a particular brand affinity, then configured online to purchase a specific product when pressed. In the marketing materials, happy families put them on washing machines to buy Tide, or in a kitchen cabinet to buy paper towels. Pretty clever, it really is a Buy now with 1-Click button for the physical world.

There were two versions of the Dash button. Both have the same user interface and work in fundamentally the same way. They have a single button (the software can recognize a few click patterns), a single RGB LED (‘natch), and a microphone (no, it didn’t listen to you, but we’ll come back to this). They also had a WiFi radio. Version two (silently released in 2016) added Bluetooth and completely changed the electrical innards, though to no user facing effect.

In February 2019, Amazon stopped selling the Dash Buttons. Continue reading “The Amazon Dash Button: A Retrospective”

The Satellite Phone You Already Own: From Orbit, UbiquitiLink Will Look Like A Cell Tower

For anyone that’s ever been broken down along a remote stretch of highway and desperately searched for a cell signal, knowing that a constellation of communications satellites is zipping by overhead is cold comfort indeed. One needs specialized gear to tap into the satphone network, few of us can justify the expense of satellite phone service, and fewer still care to carry around a brick with a chunky antenna on it as our main phone.

But what if a regular phone could somehow leverage those satellites to make a call or send a text from a dead zone? As it turns out, it just might be possible to do exactly that, and a Virginia-based startup called UbiquitiLink is in the process of filling in all the gaps in cell phone coverage by orbiting a constellation of satellites that will act as cell towers of last resort. And the best part is that it’ll work with a regular cell phone — no brick needed.

Continue reading “The Satellite Phone You Already Own: From Orbit, UbiquitiLink Will Look Like A Cell Tower”

Echos Of The Cold War: Nuclear-Powered Missiles Have Been Tried Before

On August 8th, an experimental nuclear device exploded at a military test facility in Nyonoksa, Russia. Thirty kilometers away, radiation levels in the city of Severodvinsk reportedly peaked at twenty times normal levels for the span of a few hours. Rumors began circulating about the severity of the event, and conflicting reports regarding forced evacuations of residents from nearby villages had some media outlets drawing comparisons with the Soviet Union’s handling of the Chernobyl disaster.

Today, there remain more questions than answers surrounding what happened at the Nyonoksa facility. It’s still unclear how many people were killed or injured in the explosion, or what the next steps are for the Russian government in terms of environmental cleanup at the coastal site. The exceptionally vague explanation given by state nuclear agency Rosatom saying that the explosion “occurred during the period of work related to the engineering and technical support of isotopic power sources in a liquid propulsion system”, has done little to assuage concerns.

The consensus of global intelligence agencies is that the test was likely part of Russia’s program to develop the 9M730 Burevestnik nuclear-powered cruise missile. Better known by its NATO designation SSC-X-9 Skyfall, the missile is said to offer virtually unlimited flight range and endurance. In theory the missile could remain airborne indefinitely, ready to divert to its intended target at a moment’s notice. An effectively unlimited range also means it could take whatever unpredictable or circuitous route necessary to best avoid the air defenses of the target nation. All while traveling at near-hypersonic speeds that make interception exceptionally difficult.

Such incredible claims might sound like saber rattling, or perhaps even something out of science fiction. But in reality, the basic technology for a nuclear-powered missile was developed and successfully tested nearly sixty years ago. Let’s take a look at this relic of the Cold War, and find out how Russia may be working to resolve some of the issues that lead to it being abandoned. Continue reading “Echos Of The Cold War: Nuclear-Powered Missiles Have Been Tried Before”

Apollo’s PLSS And The Science Of Keeping Humans Alive In Space

Ever since humans came up with the bright idea to explore parts of the Earth which were significantly less hospitable to human life than the plains of Africa where humankind evolved, there’s been a constant pressure to better protect ourselves against the elements to keep our bodies comfortable. Those first tests of a new frontier required little more than a warm set of clothes. Over the course of millennia, challenging those frontiers became more and more difficult. In the modern age we set our sights on altitude and space, where a warm set of clothes won’t do much to protect you.

With the launch of Sputnik in 1957 and the heating up of the space race between the US and USSR, many firsts had to be accomplished with minimal time for testing and refinement. From developing 1945’s then state-of-the-art V-2 sounding rockets into something capable of launching people to the moon and beyond, to finding out what would be required to keep people alive in Earth orbit and on the Moon. Let’s take a look at what was required to make this technological marvel happen, and develop the Portable Life Support System — an essential component of those space suits that kept astronauts so comfortable they were able to crack jokes while standing on the surface of the Moon.

Continue reading “Apollo’s PLSS And The Science Of Keeping Humans Alive In Space”