Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

doesn't appear to be a directly connected to the internet problem, even NAT'd stuff wiped data.


By definition "directly connected to the internet" means if a device can on its on accord, direct requests to an entity, ask it a question, and act upon it is true. From what I understand these WD boxes go to a management service in the cloud. and were told they should factory reset. Whether something is pull-only (as in this case) or push (say allows HTTP or SSH access from a random on the internet) is irrelavnt if either result in unauthorised activity on a box in your home.


In defense of the parent comment, there is a meaningful difference between a device acting as the terminating IP meaning any open services are directly probe-able and a device sitting behind a firewall.

For this particular attack (assuming c2 server compromise?) that might not matter, but ultimately there is a massive difference in attack surface when comparing “direct” with “NATed”


How good do you reckon a 6 years past EOL consumer linux device's defences against a browser running 3rd (or 1st) party javascript making http requests to http://192.168.0.1..254]/cgi-bin/factoryRestore.sh?

How much would you bet against that being an unauthenticated call or one with leaked hard coded reds?


Not sure this makes any sense, the 6 years past EOL consumer linux device isn't running a browser.

Or are you assuming the user's browser itself is compromised and is running random javascript hitting the NAS address? That would be unfortunate, but I'm not sure I'd blame it on the "6 years past EOL consumer linux device"


Doesn’t need any browser compromise as such, just a user on the same wifi network running a browser and visiting a site with malicious JavaScript (possible a malicious site, possible a benign site with us delivered by a shitty ad network, possible a poorly secured site with persistent xss flaws).

Classic old cross origin request forgery. It ranks #7 I owasp’s top 10 website security flaws, and they have this to say about it:

“XSS is the second most prevalent issue in the OWASP Top 10, and is found in around two thirds of all applications.“


I remember Opera showing an error when I tried to follow a link from Internet to a private addresses (192.168.0.0/16 and such). Don't browsers enforce that anymore?


My Firefox on ios crash with that link


That's kinda surprising it "crashes", but it's also kinda meta code... (and either i typed it or HN's formatter munged it...)

Assume some javascript that loops through:

http://192.168.0.1/cgi-bin/factoryRestore.sh

http://192.168.0.2/cgi-bin/factoryRestore.sh

http://192.168.0.3/cgi-bin/factoryRestore.sh

up to

http://192.168.0.254/cgi-bin/factoryRestore.sh

Those just give connection errors for me, but:

http://192.168.1.1/cgi/ACT_FACTORY_RESET

gives me a 403 Forbidden error, and if there was a known default password to my router - it'd try and do a factory reset on it. (It actually wouldn't, it'd send back a confirmation popup, but...)


Yeah difference in threat model of “evil internet can make tcp connection to me” vs “basically need a c2 compromise” is huge. Sucks for those that lost data either way.


That's not how C2 servers work. Connected to the internet means connected to the internet.


How did that work unless there was port forwarding?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: