csrf change dns

13
DNSchanger 2014 DNSchanger 2014 Alfons Tanujaya

Upload: alfons-tanujaya

Post on 30-Jun-2015

114 views

Category:

Internet


0 download

DESCRIPTION

DNSChanger 2 exploiting your routers

TRANSCRIPT

Page 1: Csrf change dns

DNSchanger 2014DNSchanger 2014

Alfons Tanujaya

Page 2: Csrf change dns

DNSchanger 2007

• Aktif 2007 - 2011

• Infeksi lebih dari 4 juta komputer PC dan Mac

• Online adv, spam, scam

• Keuntungan 140 milyar

• 8 Maret 2012, server bring down, kiamat kecil internet ?

Page 3: Csrf change dns

DNSchanger 1

Page 4: Csrf change dns

DNSChanger 2014 Symptom

Page 5: Csrf change dns

What is this ?

• Antivirus merek apapun tidak bisa mengatasi malware ini.

• Tidak hanya berdampak pada Windows tetapi pada Linux, Mac dan Android phone.

• Sekalipun komputer di format, akan kembali lagi terjadi.

Sea-surf = CSRF

Page 6: Csrf change dns

CSRF Cross Site Request Forgery

• A type of malicious exploit of a website whereby unauthorized commands are transmitted from a user that the website trusts. Unlike cross-site scripting (XSS), which exploits the trust a user has for a particular site, CSRF exploits the trust that a site has in a user's browser.

• Attack is blind. Not good for credential stealing.

• But ordinary weapon in a smart criminal can be deadly.

Page 7: Csrf change dns

DNSChanger 2014

• Changing DNS of vulnerable routers.

• Log all traffic proxy, credential leak.→• Lead to install malware.

• Lead to forgery website, can lead to leak of credential.

• Improper advertisement, porn, malware etc.

• How many victims ? 300.000 routers x 5 users = 1,5 million computers.

Page 8: Csrf change dns

How it happen

http://192.168.1.1/userRpm/LanDhcpServerRpm.htm?dhcpserver=1&ip1=192.168.1.100&ip2=192.168.1.199&Lease=120&gateway=0.0.0.0&domain=&dnsserver=162.248.99.162&dnsserver2=199.85.127.10&Save=%B1%A3+%B4%E6

Page 9: Csrf change dns

List of vulnerable routers

• TP Link

• D-Link

• Micronet

• Tenda

Page 10: Csrf change dns

Solution

Sea SurfSEA MONKEY

Page 11: Csrf change dns

SOLUSI

• Upgrade firmware Tidak selalu sukses←• → OpenWRT

• Solusi, set dns di client dgn DNS isp / google, local DNS overpower router, kecuali dipaksa router

• T-FA Challenge token

• Tidak gunakan web based administration

• Gunakan https

• Gunakan browser berbeda khusus untuk administrasi router berbeda dengan browsing

Page 12: Csrf change dns

get

Login form

Session Cookie

UNPS

Post Cookie

get

Auto submit form

Post Cookie

Page 13: Csrf change dns

Resource

• http://cxsecurity.com/issue/WLB-2012100027