SWR Interview on the Telekom Router Hack
aramido's security experts were interviewed by SWR last week regarding the hack of Telekom Speedport routers.
What Happened?
On the evening of Sunday, November 27, 2016, internet connectivity and other Internet Protocol (IP)-based services, such as telephony (VoIP) and television (IPTV), suddenly ceased to function for several Deutsche Telekom customers. Initially, an attack on port 7547, used for remote maintenance (called EasySupport by Telekom), was held responsible. A service using the TR-069 protocol could be reached on this port, which contained a security vulnerability. However, it later emerged that the devices were not actually susceptible to this specific vulnerability and were therefore not the target of the attack. The malware deployed was intended to aggregate hacked devices into a botnet, which could then be controlled remotely for further attacks.
The Telekom routers, however, possessed a different weakness: a high volume of requests on the aforementioned port led to a service failure of the router, resulting in more than 900,000 Telekom customers being forcibly disconnected from the internet. The actual target of the attack was routers from the manufacturer Zyxel, used among others by the Irish telecommunications company Eir. These were successfully infected and subsequently attacked other devices on the internet, including the Telekom routers.
Could the Incident Have Been Prevented?
The attack received significant attention from all media outlets. However, the fact that it was noticed at all is only due to its unplanned side effectsânamely, the failure of the Telekom routers. Following the incident, security experts agree that it should not have happened. For instance, the remote maintenance port should not have been accessible from the entire internet. Furthermore, the lack of updates and maintenance for router firmware is a systemic problem. It is noteworthy that a customer had already warned the company in the "Telekom Hilft" support forum two years prior about potential security vulnerabilities in the TR-069 remote maintenance protocol. The response from the Telekom employee in January 2014 to this warning sounds daring in hindsight: "You can assume that EasySupport is secure."

What Conclusions Can Be Drawn?
SWR4 reporter Thorsten Helber interviewed Andreas Sperber and Armin Harbrecht from aramido after the incident to learn how to effectively protect oneself from IT security risks. The following interview is an excerpt from the report broadcast on SWR radio on December 1, 2016.
Helber: It is likely every entrepreneur's nightmare: all business data suddenly gone, encrypted, spied upon, or maliciously altered. In such and similar cases, IT specialists from the Karlsruhe-based company aramido are called in. Usually, however, only after something has happened. For example, the attack on a corporate website, as one of the managing directors, Andreas Sperber, recalls.
Sperber: There was a website that was obviously infected with malware, which in turn infected other computers. Simply visiting this website was sufficient. It was a so-called drive-by download. Users could become infected through it.
Helber: Particularly critical about this: for months, the hacker attack remained unnoticed. The malware was able to spread undisturbed. In the case of the attacked Telekom routers, it is therefore positive that the security vulnerability has now come to light, explains Armin Harbrecht.
Harbrecht: We can be glad that the authors of this malware did such a poor job. Otherwise, perhaps 900,000 routers would have been infected without anyone noticing. A hacker's goal is actually to remain undetected, so that they can continue to exploit the security vulnerability.
Helber: The two IT specialists work as so-called White Hat hackers. The "good" hackers, symbolically wearing white hats. In contrast to Black Hat hackers, they use their knowledge only to protect IT systems, searching for vulnerabilities and bringing attention to them. Sometimes it is ignorance, but often cost pressures and convenience also lead to security risks.
Harbrecht: A very good example of this are internet-connected surveillance cameras available for purchase at Aldi. They simply had a default password preset. This makes it cheaper for the manufacturer and is convenient for the user. It is clear that this can be exploited.
Helber: General awareness of IT security is increasing, the experts believe, but there is often a too careless approach and the attitude "who cares about my personal data anyway". Yet, the current case of the Telekom routers shows once again:
Harbrecht: The hackers had no interest in hacking people's private holiday photos, but rather in the mass of routers, which could then be used for new attacks. That was the interest.
Helber: And what can be done to protect oneself and others? For Andreas Sperber, there are two decisive points.
Sperber: First, that default passwords are changedâto one's own, secure passwords, which should be long and contain complex characters. And the second important point is ensuring updates for one's devices. Just as you would typically take a car to a workshop for maintenance, you must ensure that your devices are also maintained.
Helber: This applies to everyone at home, but of course, especially for the protection of companies.
Sperber: A former FBI Director once said that there are two types of companies: companies that have already been hacked, and companies that will be.

What Needs to Be Done?
Several lessons can be drawn from the Telekom router hack.
- Telekom must be questioned as to why it did not resolve known security vulnerabilities for so long.
- The removal of the router mandate was a correct decision. Customers can now choose from a wider selection of routers and are not forced to use a potentially insecure router from their provider.
- Manufacturers of routers and other Internet of Things (IoT) devices must find a way to patch their devices immediately after a security vulnerability becomes known.
- It can be assumed that such attacks occur daily on the internet and are successful. Consequently, the risk of DDoS attacks via massive botnets continues to rise, as recent examples show.
- If you want to protect yourself, you must not blindly trust a provider. Security arises, according to the onion-peeling principle, from the combination of several layers of protection .
How can you make Internet of Things devices in your company more secure? An IoT penetration test will reveal where you are vulnerable.
On 09.12.2016 in the category Network Security published.

