Are public Wi-Fi networks a threat to our privacy? Tech insiders know the answer. What they don't know is that an Israeli hacker has demonstrated how easily he could take over an entire city's free Wi-Fi network.
One day, on his way home from work, Amihai Neiderman, head of the research team at Israeli company Equus Technologies, spotted a wireless hotspot he had never seen before. It was unusual because it was in an area without buildings.
It turned out that the Wi-Fi hotspot was called “FREE_TLV” and was part of the city’s free wireless network and had been set up by the Tel Aviv local administration.
Neiderman wondered: How safe is it?
Over the next few weeks, he tried to hack the network in his free time. He first connected to the network through one of the access points located throughout the city to check what the IP (Internet Protocol) address was. This is usually a public address assigned to the router through which anyone who wants to use Wi-Fi can and does access the internet.
He then disconnected and started scanning the IP address for open ports. He discovered that the web-based login interface was on port 443 (HTTPS).
When he tried to connect from his browser, he was presented with the name of the device manufacturer (Peplink) without any other information regarding the device type or model. An analysis of the web interface did not reveal any vulnerabilities that could grant him access via SQL injection.
The researcher realized that a more in-depth analysis was necessary to discover the actual firmware of the device.
Identifying the device to find the correct firmware was not an easy task. Peplink manufactures and sells many types of devices for various network services. However, he thought of downloading the version 5 firmware for the Peplink Balance 380 high-end load balancing router.
The firmware used basic XOR encryption to make it harder for third parties to reverse-engineer the firmware's file system. But bypassing it was relatively easy. Neiderman then loaded the unpacked components into an emulator and was able to access the CGI (Common Gateway Interface) scripts that were present in the router's web interface.
As you can imagine, it didn't take long for the researcher to discover a buffer overflow vulnerability in the CGI script that handles the log-out process. The flaw could be exploited by sending a long session cookie to the script, granting it full control of the device.
Neiderman presented his findings Thursday at the DefCamp security conference in Bucharest. He declined to say whether he actually hacked into Peplink's Balance routers used for Tel Aviv's free Wi-Fi network, citing legal concerns.
However, when he reported the flaw to Peplink, the company confirmed the vulnerability and immediately, albeit somewhat haphazardly, updated the firmware.
Router vulnerabilities are not uncommon, but this particular case stands out because it shows that a skilled hacker could attack thousands or tens of thousands of users connected to large public Wi-Fi networks.
