Главная
Study mode:
on
1
Introduction
2
Who am I
3
Landside DSL
4
CWMP
5
Heros Explore
6
Heroesx Security
7
Must Implementation
8
Posture Protect
9
Outcome
10
Deutsche Telekom
11
Ireland
12
Who did it
13
Bonus Win
14
Ida Pro
15
Miss Fortune Cookie
16
Exploit
17
DSL Forum Certification
18
SSL TLS
19
XML
20
Threat Model
21
Hacking
22
Audit
23
Disclosure Timeline
24
FreeACS
25
Postit
26
Postit screenshots
27
We want preoff
28
Attack Surf
29
Test Fuzzing
30
XML NEX
31
BaseField
32
XSS
33
Payload Limitations
34
Remote Script
35
Admin User
36
Stack Overflow
37
Stack Overflow exploit
38
Game over
39
Script kiddie
40
OpenACS
41
JBoss
42
Misc Configuration Server
43
CSP
44
CSP in the wild
45
CSP in Java
46
CSP in PHP
47
Laravel Autoloading
48
Exploitable
49
Solutions
50
Defenses
51
Ongoing research
52
Thanks
Description:
Explore the critical security vulnerabilities in CPE devices and their widespread impact in this conference talk from Security BSides London. Dive into the TR-064 misconfiguration disclosed in late 2016 that allowed remote device takeovers and led to significant internet outages. Examine the exploitation of these vulnerabilities by botnets and investigate related TR-069 protocol implementation issues. Learn about the technical details of these attacks, including command injection, XML vulnerabilities, and stack overflows. Discover the implications for ISPs and their customers, with specific examples from Deutsche Telekom and Irish networks. Gain insights into the disclosure timeline, exploitation techniques, and potential defenses against these threats. Understand the importance of proper CPE configuration, SSL/TLS implementation, and XML security in preventing large-scale router takeovers. Analyze various attack surfaces, fuzzing techniques, and payload limitations in exploiting these vulnerabilities. Explore ongoing research in this field and learn about potential solutions to mitigate these risks in CPE devices and network management protocols. Read more

A Look at TR-06FAIL and Other CPE Configuration Disasters

Security BSides London
Add to list