Software fix for Mirai-infected IoT devices 'fails'

Update to stop DDoS malware can be circumvented, security researchers find

Efforts by an IoT manufacturer to prevent DVRs and other devices becoming infected by the Mirai bot have been largely in vain, according to a security researcher.

In fact, Chinese firm XiongMai did a "terrible job" of trying to patch bugs that opened devices up to the botnet malware, according to a blog post by Tony Gee, information security consultant at Pen Test Partners.

Mirai made waves last year when it brought down Dyn, a domain name system provider that helped users navigate to several huge sites including Twitter and Github. It was later open sourced, and variants sprang up, leading to a 54-hour DDoS storm against a US university that may have exploited open telnet (23) ports and TR-069 (7547) ports to hijack CCTV cameras, DVRs and routers to launch the attack.

Gee said Pen Test Partners had brought several of XiongMai's Floureon DVRs for its demo at the Infosecurity Europe Show last month. These devices didn't have telnet open on TCP/23, which was a security improvement, but it turned out that closing down telnet access wasn't enough.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

Gee simply used ncat to connect to port 9527 instead. He found that the passwords were the same as the web interface (defaults: usually admin/blank, admin/123456 or similar) and that a command shell could be opened.

From here, Gee then managed to open up a basic Linux shell that gave anyone accessing root permissions. This meant it was relatively straightforward to re-enable telnet.

"So for any new devices that have telnet now disabled, try the shell and then just start the telnet daemon. And we have Mirai all over again," said Gee.

Gee added that the version of embedded Linux tool Busybox installed in most XiongMai DVRs is very limited. "That's why we think BrickerBot didn't really work," he said. BrickerBot is the botnet that permanently disables poorly secured Internet of Things devices before they become part of the Mirai botnet. 

Metasploit and a BusyBox module were then used to jailbreak from a restricted shell to gain fuller access to the device. Gee could then use Metasploit to enumerate hosts on the network the device is attached to.

"The Metasploit module set also includes a basic wget and exec module to execute basic ASH shell scripts so there is no reason you couldn't write your own code and have it execute in a much more targeted way than Mirai did," said Gee.

Advertisement - Article continues below

He said that it wouldn't take much for hackers to re-enable the Mirai DDoS issue. All hackers would need to do was search for suitable DVRs using IoT device search engine Shodan, connect to these devices, re-enable telnet and use credentials from the Mirai source code to create a botnet.

"XiongMai needs to go back and start again with their software fix," he said.

Gee added that it wouldn't "take much to write self-propagating code to reverse the effect of BrickerBot - not that we think BrickerBot actually worked as intended on most of the DVRs we have seen."

Featured Resources

The IT Pro guide to Windows 10 migration

Everything you need to know for a successful transition

Download now

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Software-defined storage for dummies

Control storage costs, eliminate storage bottlenecks and solve storage management challenges

Download now

6 best practices for escaping ransomware

A complete guide to tackling ransomware attacks

Download now
Advertisement

Recommended

Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Visit/operating-systems/microsoft-windows/354297/this-exploit-could-give-users-free-windows-7-updates
Microsoft Windows

This exploit could give users free Windows 7 updates beyond 2020

9 Dec 2019
Visit/business/business-strategy/354304/ex-apple-cpu-architect-accuses-the-firm-of-invading-privacy
Business strategy

Ex-Apple CPU architect accuses the firm of invading privacy

10 Dec 2019
Visit/security/vulnerability/354309/patch-issued-for-critical-windows-bug
vulnerability

Patch issued for critical Windows bug

11 Dec 2019
Visit/cloud/microsoft-azure/354230/microsoft-not-amazon-is-going-to-win-the-cloud-wars
Microsoft Azure

Microsoft, not Amazon, is going to win the cloud wars

30 Nov 2019