SlideShare a Scribd company logo
Device
inspection
To remoteroot
Uncovering the sekritz of proprietary software on a fixed
wireless terminal and weap0nizing them into a remote exploit
Where What Who
Ruxmon Melbourne
Device Inspection to remote
root
Tim Noise
tIMNOISE
• twitter/dnoiz1
• github/dnoiz1
• mIRC/dnz
• streetz/notorious D N Z
• tim@drkns.net
Internet subscriber and pirate impersonator
FixedWirelessTerminals
• Linux Based
• System on Chip
• Provide PoTS and ADSL
• 3G/LTE Backhaul
• Battery and Solar
• Remote Managed
• Deployed in Clusters
For people without copper or fiber
ExternalConnectors
• Ether over USB
(DHCP)
• Aerial socket
• SIM Card slot
• 2 RJ11 ports for
ADSL CPE and PoTS
Things we can probe
ExternalConnectors
• SIM Card slot
• 2 Management

Ethernet Ports (NO DHCP)
• 2 RJ11 power management ports
Things we can probe
WhatsInside?Rub the torx and the genie comes out
CPU
NAND0
NAND1
UART
Removable
CF Card for /
WhatsInside?Rub the torx and the genie comes out
Mini PCMCIA
3G Modem
BootProcessRedboot the buspirate, yarr
GND
RX
TX
VCC / NC
GainingROOTalways want that uid 0 - the usual tricks
• Removable root Media
• hashcat / jtr
• kernel paramaters
• init=/bin/sh
• single user mode
• Lucky for us, the root password is
printed on the PCB (not even joking)
MANAGEMENTInTERFACEthe dububdub
MANAGEMENTInTERFACEthe dububdub
LoggingINConnecting using the management USB interface
PortsANDProcessessWhats running on this thing?
PortsANDProcessessWhats running on this thing?
PortsANDProcessessWhats running on this thing?
BacktotheSourceWhere is this process stored and launched from
DECOMPYLEUsing multiline strings as comments is great!
Vulnerability1:UNPICKLESerializing objects its so convenient for passing them over a udp socket
Vulnerability1:UNPICKLESerializing objects its so convenient for passing them over a udp socket
PuttingitallTogethermaking use of our discovered vulnerabilities
PuttingitallTogethermaking use of our discovered vulnerabilities
PuttingitallTogethermaking use of our discovered vulnerabilities
PuttingitallTogethermaking use of our discovered vulnerabilities
DEMO
Device inspection to remote root
OneStepFURTHER
• Connect back payloads
• Dial 1900 numbers for profit
• UDP broadcast the attack
• Intercept data and telephony
• Insta-botnet / onion network
• Other bad things
For internet bad men
QUESTIONS?
tIMNOISE
• twitter/dnoiz1
• github/dnoiz1
• mIRC/dnz
• streetz/notorious D N Z
• tim@drkns.net
Internet subscriber and pirate impersonator

More Related Content

PDF
ifwt remote (sydney ruxmon edition)
PDF
Git Money
PDF
Practically DROWNing
PDF
Unifi'd Ownage
PDF
Bus Pirate Workshop Ruxcon Hardware Hacking 2017
PDF
Mototrbo
PPTX
Uncommon MiTM in uncommon conditions
PPT
[ENG] IPv6 shipworm + My little Windows domain pwnie
ifwt remote (sydney ruxmon edition)
Git Money
Practically DROWNing
Unifi'd Ownage
Bus Pirate Workshop Ruxcon Hardware Hacking 2017
Mototrbo
Uncommon MiTM in uncommon conditions
[ENG] IPv6 shipworm + My little Windows domain pwnie

What's hot (20)

PPTX
Hacking routers as Web Hacker
PPTX
PDF
Solnik secure enclaveprocessor-pacsec
PPTX
A Science Project: Swift Serial Chat
PPTX
Making and breaking security in embedded devices
PPTX
Hardware Hacking Primer
PDF
Kasza smashing the_jars
PDF
Уязвимости программного обеспечения телекоммуникационного оборудования Yota
PDF
IoT mit Rust programmieren
PDF
BSD Sockets API in Zephyr RTOS - SFO17-108
PDF
Arpwall - protect from ARP spoofing
PDF
Operating System fo IoT
PDF
MOVED: RDK/WPE Port on DB410C - SFO17-206
PDF
Secrets of a linux ninja Software Freedom Day 2013 Johannesburg, South Africa
PDF
Is Rust Programming ready for embedded development?
PDF
PLNOG 21: Ron Broersma - Historical_Perspectives_on_Computing, Networking, Se...
PDF
Fedora 12 Introduction
PPTX
Kali linux summarised
PPTX
Wiznet Ethernet library for ARM mbed
PDF
FOSDEM2015: Porting Tizen:Common to open source hardware devices
Hacking routers as Web Hacker
Solnik secure enclaveprocessor-pacsec
A Science Project: Swift Serial Chat
Making and breaking security in embedded devices
Hardware Hacking Primer
Kasza smashing the_jars
Уязвимости программного обеспечения телекоммуникационного оборудования Yota
IoT mit Rust programmieren
BSD Sockets API in Zephyr RTOS - SFO17-108
Arpwall - protect from ARP spoofing
Operating System fo IoT
MOVED: RDK/WPE Port on DB410C - SFO17-206
Secrets of a linux ninja Software Freedom Day 2013 Johannesburg, South Africa
Is Rust Programming ready for embedded development?
PLNOG 21: Ron Broersma - Historical_Perspectives_on_Computing, Networking, Se...
Fedora 12 Introduction
Kali linux summarised
Wiznet Ethernet library for ARM mbed
FOSDEM2015: Porting Tizen:Common to open source hardware devices
Ad

Viewers also liked (17)

PDF
Catalogo Inspiraflor
PPTX
медиаобразование
DOCX
Отчет. приложение 2.
PDF
Benefits and struggles of Lean Game Development
PPTX
PDF
UX, ethnography and possibilities: for Libraries, Museums and Archives
PDF
Designing Teams for Emerging Challenges
PDF
Visual Design with Data
PDF
3 Things Every Sales Team Needs to Be Thinking About in 2017
PDF
How to Become a Thought Leader in Your Niche
PPTX
SOMETHING INTANGIBLE, BUT REAL ABOUT CYBERSECURITY
PDF
Espcinvestmentgradeaudit
PPTX
Makanan Tradisional
PPTX
Mapping the NHS - Liverpool, for NHS Citizen NW, 29th of May
PDF
Portfolio
DOCX
Articolo
PPTX
Bubble Narratives - Preston Teeter - Confirmation Speech
Catalogo Inspiraflor
медиаобразование
Отчет. приложение 2.
Benefits and struggles of Lean Game Development
UX, ethnography and possibilities: for Libraries, Museums and Archives
Designing Teams for Emerging Challenges
Visual Design with Data
3 Things Every Sales Team Needs to Be Thinking About in 2017
How to Become a Thought Leader in Your Niche
SOMETHING INTANGIBLE, BUT REAL ABOUT CYBERSECURITY
Espcinvestmentgradeaudit
Makanan Tradisional
Mapping the NHS - Liverpool, for NHS Citizen NW, 29th of May
Portfolio
Articolo
Bubble Narratives - Preston Teeter - Confirmation Speech
Ad

Similar to Device inspection to remote root (20)

PDF
Docking stations andy_davis_ncc_group_slides
PDF
D1 t1 t. yunusov k. nesterov - bootkit via sms
PPTX
OWASP Appsec USA 2014 Talk "Pwning the Pawns with Wihawk" Santhosh Kumar
PDF
When DevOps and Networking Intersect by Brent Salisbury of socketplane.io
PDF
Republic of IoT 2018 - ESPectro32 and NB-IoT Workshop
PPTX
2017 - LISA - LinkedIn's Distributed Firewall (DFW)
PDF
Bh fed-03-kaminsky
PDF
PDF
Introduction to SDN
PPTX
28c3 in 15
PDF
DEFCON 22: Bypass firewalls, application white lists, secure remote desktops ...
PDF
DefCon 2012 - Gaining Access to User Android Data
PPTX
Security Onion
PDF
Root via SMS: 4G access level security assessment, Sergey Gordeychik, Alexand...
PPTX
Steelcon 2015 - 0wning the internet of trash
PDF
Keeping your rack cool with one "/IP route rule"
PDF
Keeping your rack cool
PDF
Insecure Obsolete and Trivial - The Real IOT
PDF
What is SDN and how to approach it with Python
PPSX
2018 all lens bag of tricks v1.2
Docking stations andy_davis_ncc_group_slides
D1 t1 t. yunusov k. nesterov - bootkit via sms
OWASP Appsec USA 2014 Talk "Pwning the Pawns with Wihawk" Santhosh Kumar
When DevOps and Networking Intersect by Brent Salisbury of socketplane.io
Republic of IoT 2018 - ESPectro32 and NB-IoT Workshop
2017 - LISA - LinkedIn's Distributed Firewall (DFW)
Bh fed-03-kaminsky
Introduction to SDN
28c3 in 15
DEFCON 22: Bypass firewalls, application white lists, secure remote desktops ...
DefCon 2012 - Gaining Access to User Android Data
Security Onion
Root via SMS: 4G access level security assessment, Sergey Gordeychik, Alexand...
Steelcon 2015 - 0wning the internet of trash
Keeping your rack cool with one "/IP route rule"
Keeping your rack cool
Insecure Obsolete and Trivial - The Real IOT
What is SDN and how to approach it with Python
2018 all lens bag of tricks v1.2

Recently uploaded (20)

PDF
FINAL CALL-6th International Conference on Networks & IOT (NeTIOT 2025)
PPTX
Funds Management Learning Material for Beg
PPTX
Digital Literacy And Online Safety on internet
PDF
Vigrab.top – Online Tool for Downloading and Converting Social Media Videos a...
PDF
Slides PDF The World Game (s) Eco Economic Epochs.pdf
PPTX
introduction about ICD -10 & ICD-11 ppt.pptx
PPTX
522797556-Unit-2-Temperature-measurement-1-1.pptx
PPTX
Module 1 - Cyber Law and Ethics 101.pptx
PDF
APNIC Update, presented at PHNOG 2025 by Shane Hermoso
PDF
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...
PPTX
PptxGenJS_Demo_Chart_20250317130215833.pptx
PPTX
international classification of diseases ICD-10 review PPT.pptx
PPT
tcp ip networks nd ip layering assotred slides
PPTX
Internet___Basics___Styled_ presentation
PDF
RPKI Status Update, presented by Makito Lay at IDNOG 10
PPTX
presentation_pfe-universite-molay-seltan.pptx
PDF
Paper PDF World Game (s) Great Redesign.pdf
PPTX
Power Point - Lesson 3_2.pptx grad school presentation
PPTX
Introuction about WHO-FIC in ICD-10.pptx
PDF
Tenda Login Guide: Access Your Router in 5 Easy Steps
FINAL CALL-6th International Conference on Networks & IOT (NeTIOT 2025)
Funds Management Learning Material for Beg
Digital Literacy And Online Safety on internet
Vigrab.top – Online Tool for Downloading and Converting Social Media Videos a...
Slides PDF The World Game (s) Eco Economic Epochs.pdf
introduction about ICD -10 & ICD-11 ppt.pptx
522797556-Unit-2-Temperature-measurement-1-1.pptx
Module 1 - Cyber Law and Ethics 101.pptx
APNIC Update, presented at PHNOG 2025 by Shane Hermoso
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...
PptxGenJS_Demo_Chart_20250317130215833.pptx
international classification of diseases ICD-10 review PPT.pptx
tcp ip networks nd ip layering assotred slides
Internet___Basics___Styled_ presentation
RPKI Status Update, presented by Makito Lay at IDNOG 10
presentation_pfe-universite-molay-seltan.pptx
Paper PDF World Game (s) Great Redesign.pdf
Power Point - Lesson 3_2.pptx grad school presentation
Introuction about WHO-FIC in ICD-10.pptx
Tenda Login Guide: Access Your Router in 5 Easy Steps

Device inspection to remote root