DEF CON 32 - Detecting persistent threats on Draytek  devices - Octavio Gianatiempo,  Gastón Aznarez

DEF CON 32 - Detecting persistent threats on Draytek devices - Octavio Gianatiempo, Gastón Aznarez

Source: YouTube · DEFCONConference · published Oct 16, 2024 · 35:40

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The presentation focuses on security vulnerabilities discovered in DrayTek edge routers running RTOS, demonstrating how attackers could exploit dynamic kernel modules 0:14.

Key Takeaways:
• Researchers reverse engineered DrayTek's firmware format and created "Router Arsenal" to extract and analyze components 4:00
• Multiple vulnerabilities were discovered including plaintext password storage and predictable 2FA codes using time-based seeds 13:02
• Attackers can install malicious modules through several vectors including unauthenticated endpoints and supply chain compromises 18:52
• Demonstrated a persistent SSH backdoor that survives firmware updates by residing in separate file system 25:32
• Created proof-of-concept defensive module to verify integrity of other modules in memory 28:08

The researchers emphasize that closed-source firmware represents security through obscurity and advocate for vendor implementation of proper detection solutions 33:39.

Sources:

  • 0:14 Introduction to security research on DrayTek routers
  • 4:00 Firmware reverse engineering process
  • 13:02 Vulnerabilities discovered in routers
  • 18:52 Module installation attack vectors
  • 25:32 SSH backdoor demonstration
  • 28:08 Defensive module explanation

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

hi everyone there is more people that I expect at 10: a.m. thank you very much for being here um you are the ones who survived until the last day in Defcon awesome welcome to taking off the blindfold detecting persistent threats on uh drch Edge devices we are part of the farad research team my partner here is octav kmo I am as Nares and uh we have some experience uh we working with firmware we have foundation on computer science and we like to play CDF as a resum we we like to break things to and do research so what we are going to see today first we are going to see a motivation for This research and this talk uh we are going to see some reverse engineer on trch fmw we are going to talk about vulnerabilities and attack vectors we are going to see mitigation strategies and at least we're g…