McAfee Researchers Exploit Smart Plug to Attack Smart TV!
Researchers from McAfee have demonstrated how a flaw in a Belkin smart switch can be used to access other connected devices on the same network as the switch.
One of the recurrent themes of Internet of Things security might be summarized as “its not the THING, stupid!” In other words: the value of the individual endpoint is irrelevant. A webcam, a baby monitor, a connected TV – none of these, by themselves, hold much sensitive information or represent much computing power. Rather, it is the value of the things in aggregate, or their ability to open a path to other, more valuable things that matters.
Now new research from McAfee is putting that to the test, by demonstrating how a flaw in a Belkin smart switch can be used to access other connected devices on the same network as the switch.
In a recent blog post, McAfee said that it has uncovered a buffer overflow flaw in a component of the Wemo Insight Smart Plug that could allow an attacker to run his or her own code on the device and use it to access and attack other devices on the same network as the smart plug.
The vulnerability, CVE-2018-6692, is in a software library known as “libUPnPHndlr.so.” The process McAfee used to discover it is lengthy and complex, with researchers disassembling and reverse engineering the Wemo Insight Smart Plug. If you want a nice write up on how to do this, including tool talk and photos, check out their blog post.
For everyone else, what’s important to know is that Wemo Insight plugs are just tiny little Linux devices, running the OpenWRT embedded Linux OS – and not a very stripped down version of OpenWRT either. The researchers found two exploitable vectors on it: a write-what-where condition allows an attacker to write data to an arbitrary location in memory; by continuing to overwrite data on the stack, an attacker can overwrite the $RA register or return address for the calling function, providing the attacker control of the execution flow.
By using Linux commands left enabled on the smart plug, the researchers found they were able to download and execute any script, run NetCat, which could allow an attacker to write a script to create a reverse shell on the device. While attacks to the device itself are limited to turning the device on or off, the potential damage grows where the plug is networked with other devices. “The plug could now be an entry point to a larger attack. Later in this report, we will look at one possible attack,” the McAfee researchers concluded.
To prove that point, the McAfee researchers developed a proof of concept attack in which a compromised plug used a built-in UPnP library to poke a hole in the network router, creating a backdoor channel for an attacker to connect remotely, unnoticed on the network.
With that access, the researchers were able to use a remote shell to control a TCL smart TV connected to the same network as the Wemo plug by exploiting a Roku API implementation on the TV that accepts unencrypted and unauthenticated HTTP GET/POST requests. “Using the Wemo as a middleman, the attacker can power the TV on and off, install or uninstall applications, and access arbitrary online content,” the researchers found.
And smart TVs are just one visible example of how the Wemo plug could be used to pivot to other devices on a network. “With the attacker having established a foothold on the network and able to open arbitrary ports, any machine connected to the network is at risk. Because attacks can be conducted through the Wemo and the port mappings generated using this exploit are not visible from the router’s administration page, the attacker’s footprint remains small and hard to detect,” the researchers concluded.
This isn’t the first time that Wemo products have been the focus of security researchers. At the 2017 Security of Things Forum, Scott Tenaglia of the firm Invincea revealed a number of security flaws in Wemo home automation devices including vulnerability to a type of attack known as SQL injection. By sending purposely mis-formed updates to WeMo devices, Tenaglia found he could create his own malicious executable that was run by the WeMo smart device, allowing him to take control of those devices.
- Technical Pre Sales Consultant
- Greater London
- £65,000 Base + Bonus + Package
A Technical Pre Sales Consultant, with a focus on cybersecurity, is needed to join a specialist security services business in the Greater London area. This is a perfect opportunity for anyone looking to retain their technical hands-on skills and step into a presales position. CURRENT hands-on experience is essential as this role will be split between professional services and presales. The Technical Pre Sales Consultant must have current experience working within the cybersecurity industry and have experience engaging with clients face to face. Any experience with scoping, high-level design, proof of concept (hands-on), RFI, RFQ etc is highly desirable Must be commutable to West London. Current technology experience with any of the following vendors such as Check Point, Palo Alto, Varonis, Fortinet, F5, Bluecoat etc. Apply today for more information, all details kept in the strictest of confidence. Key skills: Presales, Pre Sales, Security Presales, Network Security, Managed Security Services Ref CH7538
- Data Centre Presales Engineer
- Up to £47,000 Base + Bonus
A Data Centre Presales Engineer is needed to join a leading Data Centre business in London. The Data Centre Presales Engineer will be responsible for; Sales Support, Stakeholder engagement (presentations etc.), RFI / RFQ, High-level technical architecture & support etc. This role is client-facing so expect some travel but only across London. Requirements Current presales experience within an IT managed services role. Current experience with Data Centre technology would be extremely beneficial but other experience in industries such as; telecommunications, cloud, unified communications etc. is required. MUST be commutable to London. Ref PG7543
- Senior Identity and Access Management Architect
- Up to €85,000 Base + Package
Senior Identity and Access Management Architect (IDAM) subject matter expert is needed to lead and drive technical and or business transformation projects in a client-facing position for a prestigious consultancy in Frankfurt, Germany. Broad technical knowledge across Identity and access management is essential. Technical hands-on experience with one or more of the following core areas; Privileged Access Management (PAM, CyberArk, Beyondtrust, Thycotic) Identity Governance Administration (IGA, Sailpoint, Omada, RSA) Customer Identity & Access Management (CIAM, Forgerock PSD2) Fluent German is a MUST (Written & Speaking) A successful individual will be client-facing and MUST have strong exposure in previous positions designing and implementing Identity and Access Management solutions, this will be a hands-on position, working directly with the functional consultant and support teams If you are passionate about your industry and specialise in the IDAM space and are looking for a new challenge to step up, apply today and speak with the Security team. Candidate must be Germany or EU based (must want to relocate to Germany) Ref: TC7153
- Functional Identity & Access Management Consultant
- Up to €100,000 Base + Package
My Client, a leading international consultancy firm are currently in the process of expanding their Identity & Access management practice across each of their 3 sectors. Working with Large FTSE 500 companies on interesting technical / Business Transformation projects. The Identity & Access Management Consultant will be the key head in deriving and understanding business cases, consulting with the client to truly understand the needs of the business and suggest a solution of best fit. A deep understanding of business protocols, risks, as well as a strong understanding of Identity & Access management is essential to be successful in this position. Working in one of the following three IAM practices, The Identity & Access Management Consultant will need to have strong knowledge in at least one of the following; Privileged Access Management (PAM, CyberArk, Beyondtrust, Thycotic) Identity Governance Administration (IGA, Sailpoint, Omada, RSA) Customer Identity & Access Management (CIAM, Forgerock PSD2) Fluent German (Speaking & Writing) Current experience within a client-facing role, working with Identity & Access Management solutions is essential, my client are one of the leading partners in the space, hence why I am looking to speak with the best of the best. If you are passionate about your industry and specialise in the IDAM space and are looking for a new challenge to step up, apply today and speak with the Security team. Candidate must be Germany or EU based (must want to relocate to Germany) Ref TC7542