{"id":1542,"date":"2020-09-03T12:06:31","date_gmt":"2020-09-03T10:06:31","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=365424"},"modified":"2020-09-03T12:06:31","modified_gmt":"2020-09-03T10:06:31","slug":"how-a-hacker-broke-telkom-adsl-routers-to-make-it-fix-security-flaws","status":"publish","type":"post","link":"https:\/\/interwebdev.co.za\/index.php\/2020\/09\/03\/how-a-hacker-broke-telkom-adsl-routers-to-make-it-fix-security-flaws\/","title":{"rendered":"How a hacker broke Telkom ADSL routers to make it fix security flaws"},"content":{"rendered":"<p>On the dark web and in the deeper corners of the public Internet, hackers tell stories of a vigilante who scoured the Internet for insecure devices, hacked into them, and disabled them so that other hackers couldn\u2019t use them to launch attacks from.<\/p>\n<p>One of those stories is of how this hacker exploited vulnerabilities in the Aztech and D-Link ADSL routers Telkom sold to its customers.<\/p>\n<p>The hacker went by the moniker \u201cDr Cyborkian a.k.a. janit0r\u201d and claimed to be the same hacker who created the infamous BrickerBot malware in 2017.<\/p>\n<p>Although the BrickerBot part of the story is <strong><a href=\"https:\/\/en.wikipedia.org\/wiki\/BrickerBot\" target=\"_blank\" rel=\"noopener noreferrer\">relatively well known<\/a><\/strong>, less well-known is the fact that Janit0r wrote detailed reports about what they did after the success of BrickerBot.<\/p>\n<p>Part memoir and part technical guide aimed at fellow hackers who would like to try their hand at cleaning up the Internet by euthanising insecure devices, Janit0r posted nine reports on the dark web over several months.<\/p>\n<p>In an interview with <strong><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/brickerbot-author-claims-he-bricked-two-million-devices\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bleeping Computer<\/a><\/strong> in April 2017, Janit0r described their work as \u201cInternet Chemotherapy\u201d.<\/p>\n<blockquote>\n<p>I consider my project a form of \u201cInternet Chemotherapy\u201d. I sometimes jokingly think of myself as The Doctor.<\/p>\n<p>Chemotherapy is a harsh treatment that nobody in their right mind would administer to a healthy patient, but the Internet was becoming seriously ill in Q3 and Q4\/2016 and the moderate remedies were ineffective. The side effects of the treatment were harmful but the alternative (DDoS botnet sizes numbering in the millions) would have been worse.<\/p>\n<p>I can only hope hope that when the IoT relapse comes we\u2019ll have better ways to deal with it. Besides getting the number of IoT DDoS bots to a manageable level, my other key goal has been to raise awareness.<\/p>\n<p>The IoT problem is much worse than most people think, and I have some alarming stories to tell.<\/p>\n<\/blockquote>\n<p>Janit0r\u2019s memoir is also titled \u201cInternet Chemotherapy\u201d. The first nine parts of the memoir were published between 10 December 2017 and 7 July 2018.<\/p>\n<p>After a long hiatus, Janit0r returned to the dark web and started posting updates again on 22 June 2020. The latest instalment was published on 31 July 2020.<\/p>\n<p>The hacker stated that the intention behind BrickerBot and their subsequent hacks on ISPs and telecommunications service providers was to make the Internet a safer place.<\/p>\n<p>With so many vulnerable Internet-of-Things devices online that could be turned into \u201cbots\u201d, Janit0r said that there was a serious risk should these devices continue to be left online in their insecure states.<\/p>\n<h3>The dirty case of Telkom South Africa<\/h3>\n<p>On 2 February 2018, Janit0r published the fourth instalment of \u201cInternet Chemotherapy\u201d which was subtitled \u201cThe dirty case of Telkom South Africa\u201d.<\/p>\n<p>In it, Janit0r explained how they used the TR069\/64 SOAP vulnerability (<strong><a href=\"https:\/\/www.cvedetails.com\/cve\/CVE-2016-10372\/\" target=\"_blank\" rel=\"noopener noreferrer\">CVE-2016-10372<\/a><\/strong>) to hack into insecure Telkom-branded Aztech routers and render them inoperable.<\/p>\n<p>While going through the device pool on the Telkom network, Janit0r said they noticed a large number of D-Link devices that you could log into with default passwords and reconfigure over the Internet.<\/p>\n<p><a href=\"https:\/\/mybroadband.co.za\/news\/security\/78873-adsl-router-security-concern-in-sa.html\"><strong>MyBroadband reported about vulnerabilities in Telkom-deployed D-Link routers<\/strong><\/a> as early as May 2013, but the problem was never fully addressed.<\/p>\n<p>In addition to hacking and \u201csoft bricking\u201d the exposed Aztech routers on Telkom\u2019s network, Janit0r said that they also targeted some D-Link and Huawei routers.<\/p>\n<p>Janit0r\u2019s hope was that the disruption would cause Telkom to realise that there was a significant security problem on its network and fix it. However, that is not what happened.<\/p>\n<p>Since Janit0r did not leave the routers in a state where they were permanently destroyed, Telkom simply advised customers to restore them to factory default settings.<\/p>\n<p>Janit0r executed his attacks against the vulnerable routers frequently, which means that even if Telkom subscribers factory reset their routers, they would soon find themselves disconnected from the Internet again.<\/p>\n<p>If subscribers complained about the repeated problems with their router, Telkom\u2019s support staff would advise that customers buy a new router.<\/p>\n<p>The hacker broke down the effect of their attacks on a daily and monthly basis. The following table shows how, according to Janit0r, the number of vulnerable devices on Telkom\u2019s network declined between July 2017 and January 2018:<\/p>\n<div class=\"mybb_table\">\n<table cellpadding=\"7\">\n<thead>\n<tr>\n<th>Month<\/th>\n<th>Aztech (TR069 exploit)<\/th>\n<th>D-Link (default password)<\/th>\n<th>Huawei (MediaTek RPC exploit)<\/th>\n<th>Other<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>July 2017<\/td>\n<td>246<\/td>\n<td>0<\/td>\n<td>0<\/td>\n<td>783<\/td>\n<\/tr>\n<tr>\n<td>August 2017<\/td>\n<td>159411<\/td>\n<td>1771<\/td>\n<td>0<\/td>\n<td>31519<\/td>\n<\/tr>\n<tr>\n<td>September 2017<\/td>\n<td>11203<\/td>\n<td>4249<\/td>\n<td>3180<\/td>\n<td>20394<\/td>\n<\/tr>\n<tr>\n<td>October 2017<\/td>\n<td>8196<\/td>\n<td>2145<\/td>\n<td>2577<\/td>\n<td>14997<\/td>\n<\/tr>\n<tr>\n<td>November 2017<\/td>\n<td>9225<\/td>\n<td>2303<\/td>\n<td>2077<\/td>\n<td>15492<\/td>\n<\/tr>\n<tr>\n<td>December 2017<\/td>\n<td>4278<\/td>\n<td>765<\/td>\n<td>604<\/td>\n<td>8925<\/td>\n<\/tr>\n<tr>\n<td>January 2018<\/td>\n<td>3716<\/td>\n<td>670<\/td>\n<td>268<\/td>\n<td>7245<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><a href=\"https:\/\/interwebsa.com\/blog\/wp-content\/uploads\/2020\/09\/how-a-hacker-broke-telkom-adsl-routers-to-make-it-fix-security-flaws.jpg\" data-slb-active=\"1\" data-slb-asset=\"1695347999\" data-slb-internal=\"0\" data-slb-group=\"365424\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/interwebsa.com\/blog\/wp-content\/uploads\/2020\/09\/how-a-hacker-broke-telkom-adsl-routers-to-make-it-fix-security-flaws.jpg\" class=\"aligncenter size-full wp-image-365504 lazyload\" alt data-aspectratio=\"640\/480\" width=\"640\" height=\"480\" sizes=\"(max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" srcset=\"https:\/\/interwebsa.com\/blog\/wp-content\/uploads\/2020\/09\/how-a-hacker-broke-telkom-adsl-routers-to-make-it-fix-security-flaws.jpg 640w, https:\/\/interwebsa.com\/blog\/wp-content\/uploads\/2020\/09\/how-a-hacker-broke-telkom-adsl-routers-to-make-it-fix-security-flaws-1.jpg 533w, https:\/\/interwebsa.com\/blog\/wp-content\/uploads\/2020\/09\/how-a-hacker-broke-telkom-adsl-routers-to-make-it-fix-security-flaws-2.jpg 573w\"><\/a><\/p>\n<p><noscript><img decoding=\"async\" class=\"aligncenter size-full wp-image-365504\" src=\"https:\/\/interwebsa.com\/blog\/wp-content\/uploads\/2020\/09\/how-a-hacker-broke-telkom-adsl-routers-to-make-it-fix-security-flaws.jpg\" alt width=\"640\" height=\"480\" srcset=\"https:\/\/interwebsa.com\/blog\/wp-content\/uploads\/2020\/09\/how-a-hacker-broke-telkom-adsl-routers-to-make-it-fix-security-flaws.jpg 640w, https:\/\/interwebsa.com\/blog\/wp-content\/uploads\/2020\/09\/how-a-hacker-broke-telkom-adsl-routers-to-make-it-fix-security-flaws-1.jpg 533w, https:\/\/interwebsa.com\/blog\/wp-content\/uploads\/2020\/09\/how-a-hacker-broke-telkom-adsl-routers-to-make-it-fix-security-flaws-2.jpg 573w\" sizes=\"(max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\"><\/noscript>\n<\/div>\n<p>\u201cAlthough you might call the 94% reduction in vulnerable devices between August and January a big improvement, it should be noted that it took 6 months to realize this result,\u201d Janit0r stated.<\/p>\n<p>In contrast, Janit0r reported that they saw Rogers in Canada respond decisively to similar attacks within 48 hours, while Infostrada Italy had a five-day turnaround.<\/p>\n<p>\u201cBased on the social media record Telkom simply took a \u2018not our problem, buy a new modem\u2019 approach to any Telkom-supplied device that was out of warranty, and the mitigations were left to the user community to figure out on their own,\u201d Janit0r reported.<\/p>\n<h3>Complaints on social media<\/h3>\n<p>Many of the social media posts from 2017 which Janit0r refers to in the original dark web post are still online to serve as proof of the Telkom hack.<\/p>\n<p>\u201cIt seems that we have been picking up some issues with the Aztech routers that we have in the field. We are busy investigating the cause of the problem, but in the meantime it seems that resetting your router to the Factory Defaults and then reconfiguring it will solve most, if not all the issues,\u201d a <strong><a href=\"https:\/\/community.telkom.co.za\/t5\/Routers-Devices\/Aztech-Router-How-to-Reset\/td-p\/11087\" target=\"_blank\" rel=\"noopener noreferrer\">Telkom community manager<\/a><\/strong> said on the company\u2019s support forum.<\/p>\n<p>In response, several users continued to complain. One reported: \u201cI\u2019ve done the factory reset as per the instructions a few times already. It only lasts for an hour or two, and then the same problem rears its ugly head\u2026no internet.\u201d<\/p>\n<p>In a different thread on the same forum, another user <strong><a href=\"https:\/\/community.telkom.co.za\/t5\/Routers-Devices\/Aztec\/td-p\/11071\" target=\"_blank\" rel=\"noopener noreferrer\">posted<\/a><\/strong> that a support desk agent informed them that 80% of the complaints Telkom was getting related to Aztech routers, and 20% to Huawei routers.<\/p>\n<p>On MyBroadband, one of the forum members posted about <a href=\"https:\/\/mybroadband.co.za\/forum\/threads\/telkom-dlink-2750u-hacked.908697\/\"><strong>how they solved a problem with a D-Link router during the attacks<\/strong><\/a>:<\/p>\n<blockquote>\n<p>Client complained about no internet. Went to site to find SSID changed to TELKOMHACKED, password still the same, and the Internet Connection (pppoe under WAN connection) completely gone.<\/p>\n<p>Router\u2019s admin password wasn\u2019t on default. Support user\u2019s password however was still on TelkomDlink12345. Suppose that\u2019s how they got in. Telkom as ISP.<\/p>\n<p>Just FYI to change support password as well when configuring these modems.<\/p>\n<\/blockquote>\n<h3>Telkom, Aztech, D-Link, Huawei router vulnerabilities not unique<\/h3>\n<p>Janit0r noted that the situation on Telkom\u2019s network was, unfortunately, not isolated or unusual.<\/p>\n<p>\u201cAdmittedly the case of Telkom of South Africa isn\u2019t that unique or even interesting, but it\u2019s a story that has to be told in order to give you a better perspective of the complexities involved in forcing negligent ISPs to correct their security problems,\u201d stated Janit0r.<\/p>\n<p>\u201cThe problems involving Telkom are representative of the issues with many large ISPs outside the US and RIPE network space.\u201d<\/p>\n<p>Last year South African ISPs faced multiple waves of devastating distributed denial of service (DDoS) attacks. <a href=\"https:\/\/mybroadband.co.za\/news\/internet\/333082-cool-ideas-hit-by-another-big-ddos-attack.html\"><strong>Cool Ideas was especially hard hit<\/strong><\/a>, with subscribers left unable to connect to the Internet for days at a time.<\/p>\n<p>These attacks were enabled by <a href=\"https:\/\/mybroadband.co.za\/news\/internet\/320911-ddos-attacks-can-wipe-south-african-isps-off-the-internet.html\"><strong>poorly configured MiktoTiK routers<\/strong><\/a> on entirely different networks than the ISPs who were targeted.<\/p>\n<p>In an unrelated matter, <a href=\"https:\/\/mybroadband.co.za\/news\/security\/303442-international-investigation-into-cryptojacking-in-south-africa.html\"><strong>the Hawks also investigated cryptojacking attacks<\/strong><\/a> last year that were perpetrated through MikroTik routers that were not properly secured.<\/p>\n<p>The DDoS and cryptojacking attacks in South Africa happened despite the fact that MikroTik offers excellent support and timely security patches for its devices, unlike some other Internet router manufacturers.<\/p>\n<p>The issue was therefore not the MikroTik devices themselves, but the fact that Internet service providers and network operators had not configured them correctly or kept them properly updated.<\/p>\n<h3>The retirement of Janit0r<\/h3>\n<p>Janit0r announced their <strong><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/brickerbot-author-retires-claiming-to-have-bricked-over-10-million-iot-devices\/\" target=\"_blank\" rel=\"noopener noreferrer\">retirement<\/a><\/strong> from hacking and bricking IoT devices at the end of 2017. The final instalment of \u201cInternet Chemotherapy\u201d was posted to the dark web on 7 July 2018.<\/p>\n<p>MyBroadband asked Telkom how it has secured its network against hacks such as the one Janit0r launched on vulnerable routers, but the company did not respond by the time of publication.<\/p>\n<p><em>Thanks to <strong><a href=\"https:\/\/defplex.wordpress.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Defplex<\/a><\/strong> for the tip.<\/em><\/p>\n<h3>Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/security\/364734-how-to-protect-yourself-after-the-experian-data-breach.html\">How to protect yourself after the Experian data breach<\/a><\/h3>\n<p><a href=\"https:\/\/mybroadband.co.za\/news\/internet-of-things\/365424-how-a-hacker-broke-telkom-adsl-routers-to-make-it-fix-security-flaws.html\">Source: MyBroadband<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>On the dark web and in the deeper corners of the public Internet, hackers tell stories of a vigilante who scoured the Internet for insecure devices, hacked into them, and disabled them so that other hackers couldn\u2019t use them to launch attacks from. One of those stories is of how this hacker exploited vulnerabilities in [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":1543,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[77],"tags":[52,53,54,55,56,8,57,59,72,60,61,62,63,64,65,66],"class_list":["post-1542","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-co-za","tag-com","tag-affordable","tag-cheap","tag-cpanel","tag-development","tag-domain","tag-hosting","tag-interweb","tag-joomla","tag-registration","tag-reseller","tag-shared","tag-south-africa","tag-website","tag-wordpress"],"acf":[],"_links":{"self":[{"href":"https:\/\/interwebdev.co.za\/index.php\/wp-json\/wp\/v2\/posts\/1542","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/interwebdev.co.za\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/interwebdev.co.za\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/interwebdev.co.za\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/interwebdev.co.za\/index.php\/wp-json\/wp\/v2\/comments?post=1542"}],"version-history":[{"count":0,"href":"https:\/\/interwebdev.co.za\/index.php\/wp-json\/wp\/v2\/posts\/1542\/revisions"}],"wp:attachment":[{"href":"https:\/\/interwebdev.co.za\/index.php\/wp-json\/wp\/v2\/media?parent=1542"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/interwebdev.co.za\/index.php\/wp-json\/wp\/v2\/categories?post=1542"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/interwebdev.co.za\/index.php\/wp-json\/wp\/v2\/tags?post=1542"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}