1 Senaste redigerad av hackerman1 (2013-03-16 17:34:59)

Tråd: Säkerhetsproblem med Huawei-modem

Hej !


Oroande nyheter från Black hat europe 2013:


"Huawei 3G/4G USB sticks put users' security at risk


Presentation title
The security presentation had a provocative title Zoom
Source: Uli Ries At the Black Hat Europe conference that is currently in progress, Russian security expert Nikita Tarakanov has presented the results of his analysis of the driver software that Huawei ships with its 3G/4G USB sticks. According to the researcher, the various components – drivers, configuration software, update mechanisms – are all of insufficient quality.

The central update server was identified as a massive attack vector by Tarakanov: the Huawei software installs an application and driver auto-update component on every computer. The researcher said that the service in question will contact a server in the Netherlands and query it for updates every 15 minutes. Apparently, the web server is still running on Microsoft's outdated Internet Information Server (IIS) version 6.0, which is part of Windows Server 2003. Tarakanov pointed out that whoever hacked that machine could infect millions of computers worldwide with malicious software.

After the presentation, three Huawei representatives who had listened eagerly in the first row of the auditorium, written everything down and frantically taken pictures of every presentation slide with a tablet PC told The H's associates at heise Security that they had assumed the update server's security was adequate. Tarakanov didn't give the manufacturer any advance notice of his discoveries.

According to the Russian hacker, another issue with the update component is that the relevant service contains a vulnerability that makes it easy for potential attackers to escalate their privileges under Windows. Whether the service is vulnerable to remote attacks remains unclear. A further problem was discovered accidentally by iOS and PHP expert Stefan Esser just before the presentation: the researcher tweeted that installing the update component (ouc.app) gives unrestricted write access to the /usr/local directory under Mac OS X, which potentially allows malware to be injected into the system directory. His discovery became a last minute addition to the presentation.

The Huawei representatives told heise Security that their company would work to provide updates to solve the disclosed problems as soon as possible; they added that they didn't know long this would take or how the new software versions would reach customers.
"

http://www.h-online.com/security/news/i … 23894.html

http://www.blackhat.com/eu-13/briefings.html#Tarakanov


Ytterligare ett bra bevis på att alla dessa (j-la) automatiska uppdateringar innebär inte bara systembelastningar utan även säkerhetsproblem !


Starta taskmanager, stäng ner ouc.exe
Men, den startar återigen nästa gång man startar om datorn...

Det finns 2 enkla sätt att stänga ner ouc.exe-processen permanent:

1. gå till mobile partner-mappen, (C:\program files\....), döp om filen till t.ex. ouc.ex, så den inte är körbar

2. starta "services", leta reda på "Mobile Partner. OUC", sätt startup type till "disabled"
jag kör engelsk version O/S-version så jag har ingen aning om vad alternativen heter i svensk version,
"avaktivera "kanske ?
borde vara nedersta alternativet under "manuell"....

2

Sv: Säkerhetsproblem med Huawei-modem

haha :-)

tog ett tag innan det kom upp till ytan !
varför en usb router är en fördel....

3

Sv: Säkerhetsproblem med Huawei-modem

G-Man skrev:

haha :-)

tog ett tag innan det kom upp till ytan !
varför en usb router är en fördel....

que ?
vad menar du ?

4

Sv: Säkerhetsproblem med Huawei-modem

Den kör väl inte automatiska uppgraderingar av modemet.

LTE testare på 4G 2600, 1800, 900, 800 med Fritzbox AVM 6890, AVM6840, AVM6842, AVM 6820 och AVM 7590/7490/7390 samt diverse mifis från ZTE och Netgear. Några huaweimodem på hyllan.

5

Sv: Säkerhetsproblem med Huawei-modem

Slipper exponera datorn till hoaweeei's programuppdateringar...

6 Senaste redigerad av plun (2013-03-17 15:23:47)

Sv: Säkerhetsproblem med Huawei-modem

Jo jag kan inte erinra mig att jag nånsin fått en automagisk uppdatering för ett Huawei-modem. Har kört ett antal.

Däremot så hämtas det ju filer när man manuellt uppdaterar ett firmware och det måste ju vara från någon server någonstans.

Fiber 250/100 Mbits, Ubiquiti Edgemax Lite, Telenor 4G 80 Mbits (Dec 2011) , Huawei E392 samt E398, Poynting panelantenn, 14 dbi 2600 Mhz, ASUS RT-N66U/AC68U,  1 st IP kamera D-link DCS-932L.  TP-Link 3420v2/WR703N, kör ROOter såklart  smile

7

Sv: Säkerhetsproblem med Huawei-modem

It depends if OTA is enabled in firmware.