Lemmings.world
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
thehatfox@lemmy.world to Technology@lemmy.worldEnglish · 2 years ago

Backdoored firmware lets China state hackers control routers with “magic packets”

arstechnica.com

external-link
message-square
21
link
fedilink
  • cross-posted to:
  • privacy@programming.dev
  • technology@lemmy.world
  • tech@pawb.social
362
external-link

Backdoored firmware lets China state hackers control routers with “magic packets”

arstechnica.com

thehatfox@lemmy.world to Technology@lemmy.worldEnglish · 2 years ago
message-square
21
link
fedilink
  • cross-posted to:
  • privacy@programming.dev
  • technology@lemmy.world
  • tech@pawb.social
The modified firmware used by BlackTech is hard to detect.
alert-triangle
You must log in or register to comment.
  • Bell@lemmy.world
    link
    fedilink
    English
    arrow-up
    59
    arrow-down
    6
    ·
    2 years ago

    Maybe we could have a comprehensive tariff on goods that floats with the number of state-sponsored cyber crimes, human rights violations, etc. Hack our routers? The rate just went up 5%.

    • xodoh74984@lemmy.world
      link
      fedilink
      English
      arrow-up
      52
      arrow-down
      3
      ·
      2 years ago

      I think this is fair, but man the retaliatory tariffs for NSA backdoors would be atrocious

      • SuckMyWang@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        ·
        2 years ago

        Working as it should be then

    • bdonvr@thelemmy.club
      link
      fedilink
      English
      arrow-up
      16
      ·
      2 years ago

      American tech is gonna get way more expensive dang

  • mvirts@lemmy.world
    link
    fedilink
    English
    arrow-up
    52
    arrow-down
    1
    ·
    2 years ago

    Lol. Ya don’t forget to monitor the router for unauthorized network access… in its logs, controlled by its firmware 😅

  • Buelldozer@lemmy.today
    link
    fedilink
    English
    arrow-up
    42
    arrow-down
    7
    ·
    2 years ago

    Not much different than what the NSA has been doing for a long time.

  • AutoTL;DRB
    link
    fedilink
    English
    arrow-up
    25
    arrow-down
    1
    ·
    2 years ago

    This is the best summary I could come up with:


    The threat actor is somehow gaining administrator credentials to network devices used by subsidiaries and using that control to install malicious firmware that can be triggered with “magic packets” to perform specific tasks.

    In an advisory of its own, Cisco said the threat actors are compromising the devices after acquiring administrative credentials and that there’s no indication they are exploiting vulnerabilities.

    Cisco also said that the hacker’s ability to install malicious firmware exists only for older company products.

    Newer ones are equipped with secure boot capabilities that prevent them from running unauthorized firmware, the company said.

    BlackTech members use the modified firmware to override code in the legitimate firmware to add the SSH backdoor, bypass logging, and monitor incoming traffic for “magic packets.” The term refers to small chunks of data the attackers send to the infected routers.

    While they appear random and innocuous in system logs, these packets allow the attackers to surreptitiously enable or disable the backdoor functionality.


    The original article contains 522 words, the summary contains 160 words. Saved 69%. I’m a bot and I’m open source!

    • Taleya@aussie.zone
      link
      fedilink
      English
      arrow-up
      9
      ·
      2 years ago

      The threat actor is somehow gaining administrator credentials

      …lemme guess. Default logins.

      • FaeDrifter@midwest.social
        link
        fedilink
        English
        arrow-up
        5
        ·
        2 years ago

        We might never know how they managed to somehow to obtain the secret password …1…2…3 …4

        • tslnox@reddthat.com
          link
          fedilink
          English
          arrow-up
          5
          ·
          2 years ago

          That’s the same code I have on my luggage!

        • Taleya@aussie.zone
          link
          fedilink
          English
          arrow-up
          3
          ·
          2 years ago

          No one will ever guess admin/admin, it’s so blatanly obvious!

  • ApeNo1@lemm.ee
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    4
    ·
    edit-2
    4 months ago

    deleted by creator

    • SzethFriendOfNimi@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 years ago

      Avad

      • ApeNo1@lemm.ee
        link
        fedilink
        English
        arrow-up
        6
        ·
        edit-2
        4 months ago

        deleted by creator

      • SzethFriendOfNimi@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        2 years ago

        Ke

        • SzethFriendOfNimi@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          2 years ago

          a

          • SzethFriendOfNimi@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 years ago

            ra

            • SzethFriendOfNimi@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              2 years ago

              dav

              • SzethFriendOfNimi@lemmy.world
                link
                fedilink
                English
                arrow-up
                6
                ·
                edit-2
                2 years ago
                # #################
                # Welcome to Hogwarts
                # #################
                
                root@licorice> 
                
                • Gsus4@feddit.nl
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  2 years ago

                  ls

  • RizzRustbolt@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    arrow-down
    1
    ·
    2 years ago

    From the Grassy Node?

  • HaggierRapscallier@feddit.nl
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    2
    ·
    edit-2
    2 years ago

    “Alohomora”

    – Li Dazhou

Technology@lemmy.world

technology@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@lemmy.world

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


  • @L4s@lemmy.world
  • @autotldr@lemmings.world
  • @PipedLinkBot@feddit.rocks
  • @wikibot@lemmy.world
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 3.4K users / day
  • 8.27K users / week
  • 14.4K users / month
  • 34.1K users / 6 months
  • 391 local subscribers
  • 76K subscribers
  • 16.6K Posts
  • 704K Comments
  • Modlog
  • mods:
  • L3s@lemmy.world
  • enu@lemmy.world
  • Technopagan@lemmy.world
  • L4sBot@lemmy.world
  • L3s@hackingne.ws
  • L4s@hackingne.ws
  • BE: 0.19.11
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org