Walmart-exclusive Router and Others Sold on Amazon and eBay Contain Hidden Backdoors To Control Devices (cybernews.com) 94
Bernard Meyer, reporting for CyberNews: In a collaboration between CyberNews Sr. Information Security Researcher Mantas Sasnauskas and researchers James Clee and Roni Carta, suspicious backdoors have been discovered in a Chinese-made Jetstream router, sold exclusively at Walmart as their new line of "affordable" wifi routers. This backdoor would allow an attacker the ability to remotely control not only the routers, but also any devices connected to that network. CyberNews reached out to Walmart for comment and to understand whether they were aware of the Jetstream backdoor, and what they plan to do to protect their customers. After we sent information about the affected Jetstream device, a Walmart spokesperson informed CyberNews: "Thank you for bringing this to our attention. We are looking into the issue to learn more. The item in question is currently out of stock and we do not have plans to replenish it."
Besides the Walmart-exclusive Jetstream router, the cybersecurity research team also discovered that low-cost Wavlink routers, normally sold on Amazon or eBay, have similar backdoors. The Wavlink routers also contain a script that lists nearby wifi and has the capability to connect to those networks. We have also found evidence that these backdoors are being actively exploited, and there's been an attempt to add the devices to a Mirai botnet. Mirai is malware that infects devices connected to a network, turns them into remotely controlled bots as part of a botnet, and uses them in large-scale attacks. The most famous of these is the 2016 Dyn DNS cyberattack, which brought down major websites like Reddit, Netflix, CNN, GitHub, Twitter, Airbnb and more.
Besides the Walmart-exclusive Jetstream router, the cybersecurity research team also discovered that low-cost Wavlink routers, normally sold on Amazon or eBay, have similar backdoors. The Wavlink routers also contain a script that lists nearby wifi and has the capability to connect to those networks. We have also found evidence that these backdoors are being actively exploited, and there's been an attempt to add the devices to a Mirai botnet. Mirai is malware that infects devices connected to a network, turns them into remotely controlled bots as part of a botnet, and uses them in large-scale attacks. The most famous of these is the 2016 Dyn DNS cyberattack, which brought down major websites like Reddit, Netflix, CNN, GitHub, Twitter, Airbnb and more.
China-Mart is selling tech with Chinese backdoors! (Score:5, Informative)
China-Mart is selling tech with Chinese backdoor!
Well this what you get when you don't make stuff in the usa any more.
Re: (Score:1)
Re: (Score:1)
I don't care. The important thing is that we rid the country of fuckface Trump and his crooked, incestuous family.
Re:China-Mart is selling tech with Chinese backdoo (Score:4, Insightful)
No-one ever provided any proof when it came to Huawei, it was all "they could have . . .". Assuming these results are genuine, this is different. "They did".
Re: (Score:2)
Re: (Score:3, Insightful)
Re: (Score:1)
Oppressing independent thought...via the HUAC?
Bribing Countries...NATO?
Infiltrating Universities...Ronald Reagan
Enacting Social Credit Schemes...Trusted Flyer Program?
sorry, everything you just said started in Capitalist U.S.A.
Better luck winning at "Stupid" next round
Re: China-Mart is selling tech with Chinese backdo (Score:1)
No, that sounds like my 5 year old.
Re: (Score:1)
In the case of Huawei, there is evidence. You're essentially saying the U.S. Intelligence reports are not credible sources to be counted as evidence. Intelligence work, by definition, involves facts, techniques, tactics, and sources that cannot be publicly revealed - this is why information is 'classified.' These conclusions are what underlies the reports, and they count as evidence.
Barefaced lie, Evidence is submitted, not conclusions, and that is how you got Gulf of Tonkin.
If they cannot support the claim, the story is a lie.
WMD comes directly to mind
If you don't have the evidence, RIGHT NOW, shut the fuck up until you DO have the evidence.
Re:China-Mart is selling tech with Chinese backdoo (Score:4, Informative)
The USA makes loads of 'stuff'. Just not the kind of 'stuff' you find in Walmart.
Re: (Score:2)
Re: China-Mart is selling tech with Chinese backdo (Score:4, Funny)
American backdoors, fuck yeah!
Re: China-Mart is selling tech with Chinese backdo (Score:1)
Re: (Score:1)
We want 'merican stuff with 'merican back doors so ATT, NSA, etc. can monitor us!
Re: (Score:2)
Re: (Score:2)
China-Mart is selling tech with Chinese backdoor! Well this what you get when you don't make stuff in the usa any more.
So, lets see, A Chinese collaborator does not have to do his dirty deeds remotely. He could be an American, Britisher, Canadian, someone, who makes some $$$ to get the backdoor malware into the eprom software or other malleable storage devices. Furthermore, once installed, it will spread. The only way to have some security is to have source code delivered. We visibly scan the source code, sign it as "clean", and compile it to meet the instruction set of the host computer. We use certified compilers, not l
Yeah, it's out of stock (Score:3)
"Thank you for bringing this to our attention. We are looking into the issue to learn more. The item in question is currently out of stock and we do not have plans to replenish it."
After exfiltrating all the data they were interested in, they exfiltrated themselves. Standard operating procedure for spies. Or maybe they camouflaged themselves as toilet paper on sale and people bought them out.
Let's get it done (Score:5, Insightful)
Re: (Score:2)
Funny that.
Not "discovered", but rather "located" (Score:5, Insightful)
Let's be serious.
That a bulk market ChiCom router has back doors is a *given*.
You don't "discover" that it has them; you either succeed or fail at finding them . . .
hawk
Re: (Score:1)
not really backdoor (Score:2)
Re: (Score:1)
So the intent is different, but the result is the same?
Granted only if malicious hackers are aware of it.
Re: (Score:2)
Lots of media were warning us about the possibility over the last few years. Then the 2020 general election polls came along, and almost all of them changed their tunes.
https://www.nbcnews.com/news/a... [nbcnews.com]
https://www.cbsnews.com/news/r... [cbsnews.com]
https://news.engin.umich.edu/2... [umich.edu]
Re: (Score:1)
Re: (Score:2)
The count is over. F* off
Actually.. The whole discussion before was about the NEXT count, for which there are no ballots cast yet. You need to F'n learn to read.
The whole process needs to be tightened up a bit for the next election so we don't go through this mess again. Like what happened in FL after Bush squeaked by Gore and the hanging chad thing. They tossed those old punch card system pretty fast after that.
Re: (Score:2, Insightful)
haven't your kind been beating liberals over the head for the past four years by repeating "Trump won, get over it."
Well, eat your own dog food, trumptards. Trump lost. Get over it.
Re: (Score:1)
Walmart Means "Chinese Made" (Score:3)
Re:Walmart Means "Chinese Made" (Score:5, Insightful)
Hilary hasn't been anything at all since 2013.
In the 20 years since Bill finished being president the republicans have controlled 2/3 of your government most of time and changed exactly nothing about China's trade status.
Stop pretending to yourself this is some sort of democrat plot, or that the Clintons have any power.
Re:Walmart Means "Chinese Made" (Score:5, Insightful)
Really? Let's remember the Republican brain trust who told us "opening" China would make them a model nation: Nixon and Kissinger.
Re: Walmart Means "Chinese Made" (Score:2)
... and they were largely correct.
Re: (Score:2)
Re: (Score:1)
Did we forget that Bill Clinton took illegal campaign contributions from the Chinese in the 1996 presidential campaign? He wouldn't have won a second term without their help. He then took the lead in admitting them to WTO, the death knell for the American working class. He had to, it was a quid pro quo payback for their help.
Nixon and Kissinger's idea was a good one. And it worked, until 1989 when anyone could clearly see that China had gone as far as it was going to go. After Tianenmen China should
Re: (Score:3)
Or is this related to that pizza shop I keep hearing about?
Re: (Score:1)
Uhm, the office of President was held by Obama for 8 of those 20 years, and by my math, that's almost half of the past 20 years.
Also, in America we have a President, Senate and Congress - it takes all three to do anything, and if an opposing party controls only one of them (House, for example), they can block passage of anything, and while a President can veto a bill passed by the house and senate (to a point), the President can not overcome a rejection by either the House or Senate.
Re: (Score:2)
OP above is trying to argue the Clintons are somehow still able to exercise power, which is nonsense.
Re: (Score:1)
If there is no OpenWRT support, don't buy. (Score:3)
Re: (Score:2)
A router works with OpenWRT or it might just as well not exist.
So do these?
Re: (Score:2)
OpenWRT (Score:3)
Anyone know if OpenWRT supports these routers? At these prices, I might pick one up and overwrite the Chinese firmware.
Re: (Score:2)
Don't forget, your dsl modem is also a vulnerability.
Re: (Score:2)
dsl modem
DSL. How quaint. At any rate, the ONT is on the wrong side of a firewall.
Re: (Score:2)
Making it a vulnerability you can't control. Thanks for your insightful contribution. /s
Re: (Score:2)
Making it a vulnerability you can't control.
The entire Internet beyond a firewall is full of vulnerabilities we can't control. Deal with it.
shocked picachu face (Score:1)
ONN crapola (Score:1)
I bought a cheap wireless mouse of their store brand. It frequently froze for several seconds for no reason I could tell. It is sitting on a bookshelf now unused. I went to a computer store and paid about the same for a wired gaming mouse that works.
how (Score:3)
Re: (Score:2)
unless I also do something stupid or have a vulnerability in the device I am using.
Those do not sound like particularly high bars, especially considering we are talking about average consumers who bought a Chinese router.
Re: (Score:2)
yes but those issues exist with or without a compromised router
Exactly: that is why a compromised router is a such problem.
What users need to understand is that a breach usually requires multiple points of failure. A malicious email + a vulnerable email client; a phishing email + a foolish user who downloads and runs executables; a hacked router + a vulnerable browser, for example. So one cannot simply say "a hacked router is not a problem because it will only matter if the browser has a vulnerability" then also say "vulnerable browsers are not a problem unless you h
Re: (Score:1)
Agreed. A back door in a router doesn't suddenly breach security on every connected device.
"affordable" (Score:2)
Why the quotes? It can be affordable AND allow the Chinese state to surveil your activities. Those goals are independent.
Oh, oh, do Apple next! (Score:1)
Re: (Score:3)
Indeed. For a company that loves vertical integration, it was kind of a WTF moment when they announced EOL for their AirPort routers.
Re: (Score:2)
And how it's "news"?! (Score:1)
This kind of post generates so many FUD (Score:1)
Re: This kind of post generates so many FUD (Score:1)
Much FUD. Many confusion.
China bot spotted.
Re: This kind of post generates so many FUD (Score:1)
OpenWrt or PFSense (Score:2)
Never Trust (Score:2)
China-Part routers now as good as Cisco's (Score:2)
Yeah breaking news, but it's just disgusting and is an important argument that you need to have full access on a device.
And btw. "exclusive", what a joke, more true: "exclusive plastic outer shell and images for the webinterface".