Showing posts with label denial of service. Show all posts
Showing posts with label denial of service. Show all posts

Saturday, April 9, 2016

Vulnerability Note VU#643049 Motorola Surfboard cable modem cross-site request forgery vulnerability

Vulnerability Note VU#643049

Motorola Surfboard cable modem cross-site request forgery vulnerability

Original Release date: 29 Apr 2008 | Last revised: 07 Apr 2016

Overview

Motorola Surfboard cable modems may contain a cross-site request forgery vulnerability that allows an attacker to cause an affected modem to reboot or reload its configuration.

Description

Cable modems are designed to deliver broadband Internet access via unused bandwidth on a cable television network. Some models of Motorola Surfboard cable modems have a web interface that can be used to view log files, check signal levels, restart the modem, and reload the modem's configuration. This web interface listens on a private (RFC 1918) IP address, and can not be accessed via the Internet. Users connected to the modem's LAN interface access the interface via a web browser.
Because the interface uses no authentication, other than binding to a private IP address, the Motorola Surfboard may be vulnerable to various cross-site request forgery (XSRF) vulnerabilities. Note that to exploit these vulnerabilities, an attacker would need to convince a user to visit a specially crafted web page or open an HTML formatted email.

7 April 2016 update: these vulnerabilities have been found to affect more recent and rebranded ARRIS SURFboard SB6141 cable modem gateway products.

Impact

A remote, unauthenticated attacker may be able to take any action that an authorized user can including restarting the cable modem, or forcing it to reload its configuration file. While a cable modem is rebooting systems that rely on the affected modem will have limited ability to access the Internet.

Solution

We are currently unaware of a practical solution to this problem.
Restrict access

Restricting access to the Surfboard's web interface by using proxy filtering rules, router access control lists or firewall rules will mitigate this vulnerability. To effectively block access, the rules must prevent users on the LAN side of the cable modem from connecting to the web interface's IP address (usually 192.168.100.1).

Systems Affected (Learn More)

VendorStatusDate NotifiedDate Updated
ARRISAffected-07 Apr 2016
Motorola, Inc.Affected-29 Apr 2008
If you are a vendor and your product is affected, let us know.

CVSS Metrics (Learn More)

GroupScoreVector
Base6.8AV:N/AC:M/Au:N/C:P/I:P/A:P
Temporal6.5E:F/RL:U/RC:C
Environmental6.5CDP:N/TD:H/CR:ND/IR:ND/AR:ND

References


Credit

Thanks to Michael Brooks for information that was used in this report.
This document was written by Ryan Giobbi.

Other Information

  • CVE IDs: Unknown
  • Date Public: 17 Apr 2008
  • Date First Published: 29 Apr 2008
  • Date Last Updated: 07 Apr 2016
  • Severity Metric: 13.50
  • Document Revision: 21

Feedback

If you have feedback, comments, or additional information about this vulnerability, please send us email.


- wong chee tat :)













Over 135 million modems vulnerable to denial-of-service flaw

Over 135 million modems vulnerable to denial-of-service flaw
Updated: The flaw lets an attacker cut off an entire network from the internet until the owner calls their provider to restore it.
 Zack Whittaker
By Zack Whittaker for Zero Day | April 8, 2016

More than 135 million modems are said to be vulnerable to a flaw that can leave users cut off from the internet -- just by someone clicking on a trick link.

The vulnerability, found in a modem used in millions of US households, can allow an attacker with access to the network to remotely reset the device, which wipes out the internet provider's settings and causing a denial-of-service attack. Every person and device on the network will permanently lose access to the internet until the modem owner contacts their internet provider.

Arris (formerly Motorola) said that it has sold more than 135 million of the Surfboard SB6141 modems, but an Arris spokesperson disputed that the figure was "not an accurate representation" of the units impacted and that only a "subset" of Surfboard devices were affected.

Millions of Comcast, Time Warner Cable, and Charter customers (and more) were shipped one of these modems when they first subscribed.

The flaw is so easy to exploit that anyone on an affected network can be tricked into clicking on a specially crafted web page or email.

Security researcher David Longenecker, who found the flaws and posted the write-up on the Full Disclosure list earlier this week, released the "exploit" link after Arris stopped responding to emails he sent as part of the responsible disclosure process.

In fact, the flaw goes back at least eight years earlier prior to Arris' acquisition of Motorola's networking unit, according to a CERT vulnerability note dated April 2008.

There's no practical fix for the flaw, according to Longenecker.

"The simplest solution would be a firmware update such that the web [user interface] requires a username and password before allowing disruptive actions such as rebooting or resetting the modem, and that validates that a request originated from the application and not from an external source," he said.

Arris said that it recently addressed the access issue with a firmware update.

"We are in the process of working with our Service Provider customers to make this release available to subscribers," said the spokesperson. "There is no risk of access to any user data and we are unaware of any exploits."

"We take product performance very seriously. We work actively with security organizations and our service provider customers to quickly resolve any potential vulnerabilities to protect the subscribers who use our devices," the spokesperson added.

Updated with details from Arris and corrected throughout the story that the Surfboard device is a modem, not a router.



- wong chee tat :)

Thursday, December 9, 2010

MasterCard SecureCode service impacted in attacks over WikiLeaks

MasterCard SecureCode service impacted in attacks over WikiLeaks

The attacks may have caused more disruptions than earlier thought

By Jaikumar Vijayan
December 8, 2010 07:30 PM ET
 
 

Computerworld - The attacks against MasterCard by WikiLeaks supporters that knocked the credit card 
company's Web site offline today may have caused more problems than previously thought.

MasterCard itself has so far said publicly only that its corporate Web site experienced availability issues as a result of a sustained distributed denial of service (DDoS) attack against the site. In a statement this afternoon, the company said that it was making progress addressing the issue and that no customer transactions had been affected.

It now appears that the company's Securecode service for secure online transactions was also affected. It's not clear, however, whether the SecureCode problems were caused by Anonymous, the group that knocked MasterCard's corporate site offline after the attacks began about 4 a.m. ET.

In multiple bulletins to transaction processing companies, the company said that MasterCard and Maestro transactions could not be processed via SecureCode because of a service disruption to the MasterCard Directory Server.

The server has been since failed over to a secondary site, but customers could still experience intermittent connectivity issues, MasterCard said. It did not offer a timetable for when it hopes to restore full service.

A MasterCard spokeswoman confirmed the disruptions to the SecureCode service, but insisted that online transactions had not been affected. Instead, there were "isolated reports" of SecureCode service slowdowns reported, she said, adding that SecureCode service has been restored to normal.

Meanwhile MasterCard rival Visa, which has also been under a DDoS attack, was finally knocked offline this afternoon. Visa's main corporate site appears to have been hit by two separate attacks according to Sean-Paul Correll, a researcher with PandaLabs. Correll has been maintaining a regularly updated blog on the unfolding attacks.

The first attacks against the site started last night after midnight ET and resulted in intermittent service disruptions for several hours. No group has so far claimed responsibility for those attacks, Correll said.

Then at about 4 p.m. ET today, the company was hit with another DDoS attack -- this time by Anonymous, the group of loosely affiliated hackers that has vowed to attack organizations seen as attempting to censor WikiLeaks.

In a statement, Visa said that its corporate Web site Visa.com was "currently experiencing heavier than normal traffic" and said it hoped to restore full site operations in the next few hours. "Visa's processing network, which handles cardholder transactions, is functioning normally and cardholders can continue to use their cards as they routinely would. Account data is not at risk."

Anonymous, which has also been attacking entertainment industry sites over copyright enforcement issues, this week launched Operation: Avenge Assange. It is targeted at "entities involved in censoring [WikiLeaks'] information."

So far, the group is believed to have been behind the attacks on MasterCard, Visa, Swiss payment transaction firm PostFinance, PayPal, EveryDNS and others. All of the targets recently announced plans to terminate service for WikiLeaks after the site began releasing confidential U.S. State Department cables.

In addition to these attacks, Anonymous has also launched attackes on the Web sites of Sen. Joseph Lieberman (I-Conn.), former Alaska Gov. Sarah Palin and the Web sites of the Swedish prosecutors who are pursuing rape charges against WikiLeaks founder Julian Assange.

Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for  Computerworld. Follow Jaikumar on Twitter at Twitter @jaivijayan or subscribe to Jaikumar's RSS feed Vijayan RSS. His e-mail address is jvijayan@computerworld.com.


- wong chee tat :)